S. Korean Military Hit by Record Number of Cyberattack Attempts
South Korea’s military registered a record number of cyberattack attempts in 2025, with 18,951 incidents targeting its networks and websites, Yonhap News Agency reported.
The data continues an overall upward trend from 14,419 in 2024, 13,599 in 2023, and over 9,000 in 2022.
Nearly all the incidents recorded last year, 18,792 cases, involved efforts to obtain administrator access to military websites, potentially allowing attackers to take control of affected systems.
The military’s Cyber Operations Command said identifying those behind the attacks remains difficult, as hackers routinely obscure their identities.
It nevertheless pointed to the growing sophistication of North Korea’s cyber capabilities.
South Korean authorities have long accused Pyongyang of conducting cyber operations through its General Reconnaissance Bureau, the country’s primary military intelligence agency responsible for cyber activities.
Cyber Cooperation
To strengthen its defenses against North Korean cyber operations, the country has expanded cooperation with the US and other Western partners.
Seoul and Washington have developed bilateral mechanisms for sharing threat intelligence, coordinating responses, and improving joint cyber capabilities.
South Korean personnel have also participated in US-led Cyber Flag exercises, which test how allied teams detect, contain, and respond to simulated attacks.
This cooperation extends to joint investigations and public advisories.
In 2024, the US, UK, and South Korean authorities identified North Korea’s intelligence apparatus as being behind the Andariel hacking group.
According to the three governments, the group targeted defense, aerospace, nuclear, and engineering organizations to steal technology and intellectual property for Pyongyang’s military and nuclear programs.
Seoul has also deepened cooperation with Germany.
In a 2024 joint advisory, the two countries warned that North Korean hackers were targeting the defense sector through social engineering and supply chain attacks.
In one documented case, attackers first compromised a contractor responsible for maintaining the maritime research center’s web servers before using that access to infiltrate the facility.









