Internet

The Misconception of 'Sophisticated Hacking'… What Brought Down Major Corporations Was 'Trivial Basics'

[The Age of Massive Hacking—Security Experts’ Analysis] (1) 1,236 Cyber Incident Reports… 19.5% Increase in One Year SKT, Coupang, and TVING Hit by a Series of Incidents; Cause: ‘Minor Security Loopholes’ Six Security Experts: “Internal Visibility and Fundamentals Are More Important Than Security Products” “Even if a breach occurs, contain the spread; close it immediately upon detection”… Defense is also a “race against time”

Yun Junghoon
2026-09-15 05:21:02
[Edaily Yun Junghoon·An Yu-ri Reporter] According to the Ministry of Science and ICT and the Korea Internet & Security Agency (KISA), reports of domestic cyber incidents in the first half of this year totaled 1,236, a 19.5% increase compared to the previous year (1,034 cases).

A string of breaches occurred across both private companies and public institutions, including SKTelecom, Lotte Card, Coupang, KTCorporation, TVING, YES24 Co.,Ltd, Duo, Gangnam Unnie, the National Diplomatic Academy, and the Institute for Information & Communications Technology Planning & Evaluation. A closer look at the investigation results of this series of hacking incidents reveals a common thread: the breaches did not stem from sophisticated attacks orchestrated by AI, but rather from “minor breaches of basic security protocols” that even the responsible staff had forgotten about.

The person who breached Coupang was a former employee who had personally developed the alternative authentication system. The root of the problem was that the signature key was never renewed or revoked after he left the company. SKT stored usernames and passwords in plain text—without encryption—on a server connected to the public internet, ultimately leading to a breach that compromised its core network. TVING had a developer’s access key stolen; the problem was that the key had been left embedded in the source code to begin with.

Kim Hyuk-jun, CEO of Naru Security; Kang Byung-tak, CEO of AI Spera; Park Kwan-soon, CISO of Tori; Park Tae-hwan, Head of the ACSC Division at AHNLAB,INC.; Kim Dong-min, Team Leader of the White Hat Center at RaonSecure Co., Ltd.; and Cho Seong-min, Director (Head of Information Security) at NHN (from left to right in the photo) (Photo courtesy of respective companies)


This is truly the “era of massive hacking.” With the advancement of sophisticated AI, no company can guarantee that its security measures are completely safe. This is why Jensen Huang, CEO of NVIDIA, stated at the Goldman Sachs Technology Conference on the 10th that “cybersecurity will be the next major application area for AI.”

E-Daily interviewed six experts who examine security from various perspectives to gather advice on what companies—both those already excelling at security and those aspiring to do so—need to prepare for and implement.

The six experts included Park Tae-hwan, Director of the AHNLAB,INC.(053800) Cybersecurity Center (ACSC), which investigates actual security breaches and tracks threats; Kim Hyuk-jun, CEO of Naru Security, a security firm that tracks attackers’ traces through network traffic; Kim Dong-min, Team Leader at the White Hat Center ( RaonSecure Co., Ltd.(042510) ), which leads a team of white-hat hackers to conduct simulated penetration tests on companies; Kang Byung-tak, CEO of AI Spera, a company specializing in attack surface management (ASM) that monitors what corporate systems are exposed to the internet; Cho Seong-min, Director (Head of Information Security Policy) at NHN(181710), who oversees internal information security policies and development security while directly operating large-scale services such as cloud and gaming platforms; Park Kwan-soon, Chief Information Security Officer (CISO) at Tori, a corporate security consulting firm.

They unanimously emphasized that “it’s not about the number of security products, but how accurately you assess your internal environment and how quickly you patch vulnerabilities.”

Attacks Accelerated by AI... “All IT Assets, Including Servers, Must Be Protected”

CISO Park Kwan-soon attributed the root cause of recent major personal data breaches to “not sophisticated hacking techniques, but minor violations of basic security rules and accumulated security debt.”

As an example of the advancement of AI, he noted that the analysis of high-risk vulnerabilities at the Linux kernel level—which used to take several weeks—has now been reduced to a matter of hours or a single day thanks to AI.

CEO Kang Byung-tak offered a similar assessment. “Attackers don’t come through the front door; if even a single back window is open, they’ll come in that way,” he explained. “What makes AI so frightening is that it can find these small loopholes—ones that even the people in charge have forgotten about—much faster.”

Experts identified Attack Surface Management (ASM) as the first step.

CEO Kang pointed out, “Many companies don’t know exactly what they have exposed on the internet.” Interestingly, this isn’t just a challenge for large corporations.

He advised, “If you’re a small or medium-sized enterprise (SME) facing budget constraints, start by utilizing the ASM-based inspection support program provided free of charge by the Korea Internet & Security Agency (KISA).”

CISO Park Kwan-soon also noted, “The initial point of entry usually begins with neglected assets that even the responsible personnel have forgotten exist.”

There was also consensus that credential management must move beyond the goal of “never letting them leak” to “detecting leaks the moment they occur.”

Director Cho Seong-min revealed that NHN is building a source code repository entirely in-house to block external access at the source and is establishing controls to automatically filter out any code that contains embedded authentication keys before it is uploaded. In particular, as “Vibe Coding”—where AI writes code on behalf of developers—becomes more prevalent, the company has created and distributed its own development security guidelines instructing AI not to directly embed authentication credentials.

Team Leader Kim Dong-min also emphasized, “Keys must have a recorded history from issuance to disposal, be rotated at short intervals, and be immediately revoked if a leak is suspected.”

Six security experts interviewed by Edaily emphasized the fundamentals, such as “it’s not about the number of security products, but how accurately you assess your internal systems and how quickly you patch vulnerabilities” (Photo: ChatGPT)


Preventing Hackers from Moving to Adjacent Areas Even If They Break In

Experts also agreed that assets, such as servers, must be isolated to prevent hackers from moving to other areas even after an intrusion.

CISO Park Kwan-soon refers to this as “guardrails,” stating, “Based on the premise that people can make mistakes at any time, companies equipped with technical controls that prevent employee errors from escalating into system-wide incidents are the most challenging for attackers.”

Team Leader Kim Dong-min cited a real-world penetration testing experience as the most difficult case to breach: “Companies that have only a main page and no actual services are the hardest to breach. Since there are no functional features, there’s no entry point to penetrate.”

Team Leader Kim continued, “The next most difficult target is a company where, even if one point is breached, it’s hard to advance to the next stage, and where the organization reacts quickly to even minor anomalies.” Critical systems require access via managed terminals and multi-factor authentication, and the structure ensures that development and operations environments are separated, with external data transfers restricted.

CEO Kim Hyuk-jun advised, “The moment an attacker’s understanding of the internal environment surpasses the defender’s visibility, the attack disappears completely from the defender’s radar,” adding, “To prevent this, define the scope of normal business operations as data in advance.”

He explained that having established criteria for which servers typically communicate with which destinations allows the system to immediately flag as anomalous behavior instances such as communication with unfamiliar external addresses or bulk queries of customer information without a legitimate business reason.

Park Tae-hwan, a division head at AHNLAB,INC., added, “Do not store all customer information on a single server; it should be segregated based on purpose and importance,” noting, “For companies that have implemented a multi-factor authentication system, it is not easy for an attacker to gain access using only information obtained online.”

“The ‘golden time’ for response after an intrusion is critical… intruders won’t wait.”

As most hacking cases demonstrate, government security certifications—such as the Information Security Management System (ISMS)—can be viewed as a minimum requirement.

CISO Park Kwan-soon stated, “Certification is merely a benchmark for compliance; it is not a practical firewall capable of blocking intrusions that evolve in real time,” adding, “Regular audits conducted once or twice a year only assess the status at a specific point in time, whereas today’s attacks move at the ‘speed of machines’—measured in seconds.”

Director Cho Seong-min remarked, “The trend in government information security disclosure figures is a far more objective indicator than incident history,” adding, “Management must first verify whether there is a system in place to regularly report these figures to them, and whether the security organization is in a position to raise issues without having to worry about how business departments will react.”

CEO Kang identified time as the key factor that truly distinguishes defensive capabilities.

He said, “While some companies let weeks slip by just verifying with the responsible department and coordinating schedules even after a vulnerability is discovered, top-performing companies block the threat immediately and take action right away,” adding, “Attackers won’t wait those few weeks.”

Team Leader Kim also noted, “Speed metrics—such as how quickly risks are detected and mitigated—are more important than the number of products or the total budget,” adding, “Senior management must personally monitor the time taken from detection to resolution and the number of cases that exceed deadlines.”

Although the experts reached the same conclusion, their key points of focus differed slightly.

Based on his experience responding to actual incidents, Division Head Park Tae-hwan emphasized “fundamentals” such as multi-factor authentication and distributed data storage; CEO Kim Hyuk-jun, drawing on his field experience tracking traces of breaches, highlighted the importance of securing “visibility” that extends beyond the attacker’s scope; and Team Leader Kim Dong-min, from the perspective of a white-hat hacker who has conducted penetration tests, stressed “internal controls” to prevent the spread of a breach once it occurs.

CEO Kang Byung-tak, true to his expertise in attack surface management, consistently emphasized “identifying exposed assets” and “response speed,” while Director Cho Seong-min, speaking as an insider at a company operating actual services, prioritized institutional metrics such as “proactive prevention” during the development phase and “information security disclosures” visible to executive management. CISO Park Kwan-soon, drawing on his experience in both security consulting and public-interest vulnerability reporting, most strongly advocated for the concept of “security debt” and the design of “guardrails” based on the assumption of human error.

Economy

Corporation

IT·Science

Economy

Escaping the Brink of Closure, a 23.5 Billion Windfall… The Secret to Outback’s Resurgence [Market In]

In the domestic market, private equity funds have become firmly associated with corporate restructuring and job insecurity. Although a series of negative incidents has led to a more skeptical view, th…
2026-09-15 03:34:06

Corporation

Searching for the Next APR… K-Home Beauty Devices Heating Up the Investment Market

As beauty company APR(278470)has achieved success by pioneering the global home beauty device market, investments are pouring into startups following a similar growth model. With growing demand for co…
2026-09-14 15:29:06

IT·Science

The Misconception of 'Sophisticated Hacking'… What Brought Down Major Corporations Was 'Trivial Basics'

According to the Ministry of Science and ICT and the Korea Internet & Security Agency (KISA), reports of domestic cyber incidents in the first half of this year totaled 1,236, a 19.5% increase compare…
2026-09-15 05:21:02