Skip to content
Cyber intrusions surge in South Korea, hit SMEs hardest

Cyber intrusions surge in South Korea, hit SMEs hardest

Biz.Chosun September 13, 2026

More than 8,500 cyber intrusion incidents have been reported by corporations and others to authorities over the past six years.

According to data submitted by the office of Hwang Jeong-a, a lawmaker with the Democratic Party of Korea on the National Assembly's Science. ICT. Broadcasting. and Communications Committee, from 2021 through June this year a total of 8,565 cyber intrusion incidents were reported. The number of reports by year rose annually: 640 in 2021, 1,142 in 2022, 1,277 in 2023, 1,887 in 2024, and 2,383 in 2025. This year alone, 1,236 were reported in the first half.

Small and midsize enterprises, which relatively lack security capabilities, were found to be vulnerable to cyber intrusions. Of all reports, incidents at small and midsize enterprises were the most at 6,991, or 81.6%. Mid-sized corporations recorded 760, and large corporations 310. The nonprofit institutional sector also accounted for 504. Reports of cyber intrusions at small and midsize enterprises jumped from 518 in 2021 to 1,913 in 2025. This year, 997 were reported through June, already exceeding half of last year's annual total.

Cyberattacks are spreading across industries rather than being confined to specific sectors. As of last year, information and communications recorded the most reports by industry with 977, followed by manufacturing (364), wholesale and retail (288), and professional, scientific and technical services (128). This year, information and communications had 553 reports, manufacturing 191, and wholesale and retail 170.

Notably, 468 corporations reported system hacking two or more times. Ninety-eight corporations reported it three times, and 42 corporations also reported it four or more times, it was found.

Hwang Jeong-a said, "For acts that downplay or conceal cyber intrusion incidents, corporations must be held strictly accountable, while for corporations that promptly report and actively respond to incidents, we should build an effective cybersecurity ecosystem by expanding security investment and technical support," adding, "In the AI era, cybersecurity issues will escalate into matters of national security. We need to support the security industry at a level comparable to the defense industry and foster the ecosystem."