/ 10 April 2013

Seoul: North Korea behind March hacking

North Korea was behind the cyberattack that wiped hard drives on more than 30 000 computers in South Korea
The compromised data includes personal information and medication dispensed to patients (AFP)

North Korea was behind the cyberattack in March that wiped hard drives on more than 30 000 computers at TV stations and disrupted banks in South Korea, a spokesperson for its internet security agency said on Wednesday, ratcheting up the growing tension between the two sides another notch.

The agency said six computers in the North accessed computer servers in the South using more than a thousand access points on the internet, called IP addresses, based overseas. Those were then used to set up the attack.

A spokesperson told the Associated Press that the attack, planned up to eight months earlier, had similarities to past North Korean hacking attempts, which he said were carried out by an espionage agency run by the military there.

That will raise concerns that even a minor conflict between the two nations could be presaged by a cyberattack aimed at critical infrastructure in the South, which is one of the most networked nations in the world – in stark contrast to the North, which is one of the least networked.

Aggressive language
North Korea has been using increasingly aggressive language in public statements: on Tuesday it warned foreigners to leave the South for "safe places", implying a nuclear war was imminent. The two nations have never signed a peace treaty; the three-year-long Korean war ended in a ceasefire, but not a peace treaty. They have remained at war despite the peace that has reigned since July 1953.

The online realm has become the most active frontier in what is so far a phoney war between the two nations. North Korea's Twitter feed was hacked last week, apparently by hackers from the Anonymous collective.

The cyberattack in March was quickly linked to IP addresses in China by authorities in Seoul, who were already suspicious that the North was behind the attacks. Personal computers in broadcasters YTN, MBC and KBS had their hard drives wiped, while cash machines across the country were disabled and about 32 000 computers at two major commercial banks, Shinhan Bank and NongHyup Bank, were affected, according to the South's state-run Korea Internet Security.

Soon after the attack security companies pointed to North Korea as the likely culprit, saying that the tools used for the incursion were outdated by modern hacking standards, and that the targets were not the kind that unaffiliated "hacktivists" would target. – © Guardian News and Media 2013