Cyberwarfare

South Korea Says Presumed North Korean Hackers Breached Personal Emails of Presidential Staffer

South Korean President Yoon Suk Yeol’s office said presumed North Korean hackers breached the personal emails of one of his staff members.

South Korean President Yoon Suk Yeol’s office said presumed North Korean hackers breached the personal emails of one of his staff members.

South Korean President Yoon Suk Yeol’s office said Wednesday that presumed North Korean hackers breached the personal emails of one of his staff members ahead of Yoon’s trip to Europe in November.

Yoon’s office said the cyberattack only affected the personal account of the unidentified employee, who violated security protocols by partially using commercial email services to handle official duties. Officials did not specify what type of information was stolen from the staff member’s personal emails but stressed that the office’s overall security system was not affected.

“We detected the case in advance of (Yoon’s) visit and took necessary measures,” Yoon’s office said in a statement to reporters. The office said it has been monitoring and defending against “constant” hacking attempts presumed to be related to North Korea but “it’s not that the presidential office’s security system got hacked.”

Yoon in November made a three-day visit to Britain, where he met King Charles III and Prime Minister Rishi Sunak, and followed it with a trip to France.

North Korea runs a huge, government-backed hacking program that has been accused of stealing large sums of money, often in cryptocurrency, to finance its illicit nuclear weapons and missile program in defiance of U.S.-led international sanctions. North Korea-backed hackers have also been accused of stealing information from outside governments, businesses and think tanks.

According to a report obtained by The Associated Press last week, a U.N. panel of experts said they are investigating 58 suspected North Korean cyberattacks between 2017 and 2023 valued at approximately $3 billion, with the money reportedly being used to help fund its development of weapons of mass destruction.

Advertisement. Scroll to continue reading.

While the country has denied involvement, North Korea has been linked to major cyberattacks in past years, including a 2013 campaign that paralyzed the servers of South Korean financial institutions, the 2014 hacking of Sony Pictures, and the WannaCry malware attack of 2017.

Related: New ‘SpectralBlur’ macOS Backdoor Linked to North Korea

Related: New MacOS Malware Linked to North Korean Hackers

Related: North Korean APT Hacks Internet Infrastructure Provider via ManageEngine Flaw

Related Content

Vulnerabilities

The bug allowed attackers to gain full control of the victims’ systems and deploy the ForestTiger backdoor.

Supply Chain Security

The PolinRider campaign has compromised more than 100 legitimate open source packages and repositories to deliver a backdoor and information stealer to developers.

Supply Chain Security

A malicious dependency the attackers added to over 140 Mastra packages fetches a payload targeting cryptocurrency extensions.

Nation-State

The campaigns focus on financial organizations, including cryptocurrency, venture capital, and blockchain entities.

Cybercrime

The hackers targeted LayerZero’s DVN, compromising certain RPCs and DDoSing others to trigger failover to the poisoned infrastructure.  

Cybercrime

Kejia Wang and Zhenxing Wang compromised the identities of dozens of US persons to help land jobs at over 100 companies.

Artificial Intelligence

The AI giant is taking action after determining that a macOS code signing certificate may have been compromised.

Supply Chain Security

The threat actor behind the Axios supply chain attack has been aiming at other maintainers in its social engineering campaign.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version