Qilin Ransomware Turns South Korean MSP Breach Into 28-Victim ‘Korean Leaks’ Data Heist
What has been described as a sophisticated supply chain operation that resulted in the deployment of Qilin ransomware targeted South Korea's financial industry.
According to a report shared with The Hacker News by Bitdefender, this operation used Managed Service Provider (MSP) compromise as the initial access vector, combining the capabilities of a significant Ransomware-as-a-Service (RaaS) group, Qilin, with possible involvement from North Korean state-affiliated actors (Moonstone Sleet).
The RaaS team demonstrated "explosive growth" in October 2025, claiming over 180 victims, making Qilin one of the most active ransomware operations this year. According to data from NCC Group, the group is accountable for 29% of all ransomware outbreaks.
In September 2025, South Korea became th...

