South Korea’s National Intelligence Service is investigating a report that email accounts belonging to old boys from Korea University Graduate School of Information Security were compromised by external hackers, possibly North Korean.
Describing the scenario, an official with the school explained on Tuesday, “Early this month the email accounts of a portion of our old boys received a piece of spam mail carrying malicious code ostensibly sent by the Korea University Center for Information Security Technologies. The investigation revealed that all of those who received it graduated in the same year. It appears that the hackers obtained the directory with all their email addresses and planted the malicious code.”
The NIS and the police’s Cyber Terror Response Center are now working together to ascertain whether any important documents were stolen in the attack. A source involved with the investigation told The Daily NK, “We have seized the email server and are trying to trace the origin of the spam email (used to infiltrate the accounts).”
While North Korea is bound to fall under suspicion, the source inside the investigation was careful to avoid apportioning blame at this stage, saying, “We have not determined whether it was the work of North Korea. We are investigating what if any role they played in the event and at the moment are considering all options.”
The kind of malignant code used in the incident is apparently not uncommon, and as such the attack could have been the work of any number of parties; however, the technique has been used by North Korean hackers in previous incidents.
In the meantime, because the code allowed the sender to view all material stored in the hacked email accounts, concerns are growing that important information may have been stolen. This is especially problematic since a large number of the graduate students from the school work for security organizations such as the NIS or the Ministry of National Defense.
Regardless, it is certain to be a wake-up call for South Korea’s intelligence community, which has long been criticized for its generally lax approach to information security.
“The email server was quite old, so as a result of this incident we have shut it down. We have merged the accounts with the rest of Korea University’s high security servers,” the school source revealed, adding that the university is reviewing the idea of deleting all such directories from next year.










