The number of cyber incidents in the first half of 2026 reached 1,236, marking a 19.5% increase compared to the same period last year. This rise is attributed to security threats stemming from the expansion of generative artificial intelligence (AI) and the sophistication of software supply chains.
The Ministry of Science and ICT (MSIT) and the Korea Internet & Security Agency (KISA) announced the findings on July 30, 2026, in their report titled '2026 Cyber Threat Trends in South Korea.'
According to the report, KISA received 1,236 incident reports in the first half of this year, a 19.5% increase from the previous year, although this figure represents an 8.4% decrease from the second half of last year.
Among the types of incidents, distributed denial-of-service (DDoS) attacks and ransomware infections saw significant increases. DDoS attacks totaled 373 in the first half of the year, a 56.7% rise compared to the previous year, making it the most significant increase among major cyber threats. Ransomware reports reached 145, an increase of 82 incidents from the first half of last year. Server hacking accounted for the largest share (39.4%) of all incidents, with 487 cases reported in the first half of 2026.
The MSIT identified several key cyber threats, including: the sophistication of attacks due to the proliferation of generative AI, open-source supply chain attacks, DDoS attacks targeting domestic entities by international hacktivists, ransomware combined with data breaches, and personal information leaks through API and account theft. The ministry noted that as generative AI and AI agents become integrated into work systems, new security risks such as prompt injection, privilege misuse, and sensitive information leaks are increasing. It also warned that the theft of developer accounts and supply chain attacks could spread across businesses.
Additionally, the report highlighted ongoing threats from international hacktivist DDoS attacks, double-extortion ransomware, and personal information leaks exploiting API vulnerabilities and reused account information. The MSIT urged the implementation of multi-factor authentication (MFA) for APIs and accounts, enhanced software supply chain management, access controls for AI services, immutable backup operations, and regular incident response and recovery training.
Choi Woo-hyuk, head of the MSIT's Information Security Network Policy Division, stated, "AI-based cyber threats are becoming a reality, and intelligent attacks targeting cloud vulnerabilities continue to emerge. The government will establish and operate a prevention and response system based on AI and take proactive measures to identify vulnerabilities."
In response to the growing AI threats, the MSIT plans to develop a 'Cybersecurity AI Foundation Model.' Applications will be accepted until August 21, and selected development teams will receive support of 256 NVIDIA GPUs for ten months.
* This article has been translated by AI.
Copyright ⓒ Aju Press All rights reserved.