South Korea’s E-Government System Faces Major Cybersecurity Breach

Seoul: The e-government system that South Korea has long taken pride in is facing significant challenges following the discovery of substantial security breaches. A battery fire at the National Information Resources Service in September revealed serious vulnerabilities in the government's computer network, severely disrupting electronic government services.

According to Yonhap News Agency, the Onnara System, an online platform utilized by civil servants, was hacked, leading to a data leak that persisted for approximately three years. This marks the first known infiltration of the system managed by the Interior Ministry. The breach resulted in the leak of around 650 electronic signatures, known as government public key infrastructure certificates, which are crucial for logging into the system. Additionally, passwords of 12 users were stolen.

In August, Phrack magazine, a US publication focused on online cybersecurity, raised concerns about possible hacking incidents involving South Korean government agencies and private companies. This was later confirmed by the Interior Ministry and the National Intelligence Service. An inspection by the intelligence agency uncovered hacking traces within the Onnara system, mail servers, email accounts, and the Government-Virtual Private Network used for remote access through user authentication. In the private sector, mobile carriers KT and LG Uplus were also subjected to hacking attacks.

Authorities discovered that hackers had accessed the Onnara system's data from September 2022 to July this year by exploiting the remote VPN with public key infrastructure certificates. The Onnara platform is integral to the daily operations of civil servants, who rely on it to send and receive numerous documents and memos essential for government functions.

Despite numerous login failure records indicating hacking attempts, no alerts were triggered. This failure to detect abnormal activity highlights the government's lack of awareness regarding the hacking and subsequent data leak from a critical system over an extended period. The incident underscores the government's indifference to the security of its computer networks.

Following the discovery of the hack, the government implemented emergency measures requiring users to undertake additional authentication steps. However, the identity of the hackers and the extent of the data leak remain unclear. The government's assurance that the damage is minimal is unconvincing, given the hackers' access to internal government data and the lack of information on what was compromised.

The incident reflects the government's chronic neglect of cybersecurity risks. Previous calls for an overhaul of government information systems, following network equipment failures in November 2023, have not led to significant changes. Although the magazine report identified a suspect referred to as "KIM," it remains uncertain whether this refers to Kimsuky, a North Korean state-backed hacker group. The Korean government currently assumes that unidentified hackers may have infiltrated the administration network by obtaining passwords and authentication certificates.

The recent leakage of customer data from SK Telecom, KT, and Lotte Card has prompted the government to consider punitive measures for security failures. However, the government now finds itself in a similar predicament, having been lax in managing its computer systems. Any disruptions to the government's online networks could severely impact everyday life and national security.

The fire at the state data center, alongside the delayed exposure of the Onnara network hack, has exposed significant weaknesses within the electronic government system. Comprehensive examinations of all government computer systems are imperative. A mere quick fix could lead to even greater calamities in the future.