Yes24 admits to ransomware hack with book, ticket platform down for 2 days

2025. 6. 10. 21:19
자동요약 기사 제목과 주요 문장을 기반으로 자동요약한 결과입니다.
전체 맥락을 이해하기 위해서는 본문 보기를 권장합니다.

Addressing concerns about potential data leaks, Yes24 said, "We have confirmed that no personal data has been leaked or lost. All order and transaction data remains intact."

However, on its website, it merely cited "system maintenance" or "system failure" until it issued a full statement later. Responding to criticism that it did not consent to technical support from KISA, a Yes24 representative said, "To our understanding, companies with in-house security teams are not required to do so."

음성재생 설정 이동 통신망에서 음성 재생 시 데이터 요금이 발생할 수 있습니다. 글자 수 10,000자 초과 시 일부만 음성으로 제공합니다.
글자크기 설정 파란원을 좌우로 움직이시면 글자크기가 변경 됩니다.

이 글자크기로 변경됩니다.

(예시) 가장 빠른 뉴스가 있고 다양한 정보, 쌍방향 소통이 숨쉬는 다음뉴스를 만나보세요. 다음뉴스는 국내외 주요이슈와 실시간 속보, 문화생활 및 다양한 분야의 뉴스를 입체적으로 전달하고 있습니다.

Yes24, one of Korea’s largest online bookstores and ticketing platforms, has been offline for two consecutive days following a ransomware attack, which is having a particularly severe impact on events with tickets bookable through the company.

Yes24, one of Korea’s largest online bookstores and ticketing platforms, has been offline for two consecutive days following a ransomware attack. While the company promptly reported the incident to authorities, it did not inform users about the breach until 36 hours later.

Ransomware refers to a type of cyberattack in which hackers encrypt the victim's data and demand payment in exchange for its release.

In a statement issued at 4 p.m. on Tuesday, Yes24 acknowledged that the disruption was due to a ransomware attack that began around 4 a.m. on Monday. According to the company, all of its services — including book sales, ticketing, e-books, digital library services and the Sarak content platform — have been rendered inaccessible.

Addressing concerns about potential data leaks, Yes24 said, “We have confirmed that no personal data has been leaked or lost. All order and transaction data remains intact.”

According to Rep. Choi Su-jin of the People Power Party, who sits on the National Assembly’s Science, ICT, Broadcasting and Communications Committee, Yes24 initially informed the Korea Internet and Security Agency (KISA) immediately after the attack.

However, on its website, it merely cited “system maintenance” or “system failure” until it issued a full statement later. Responding to criticism that it did not consent to technical support from KISA, a Yes24 representative said, “To our understanding, companies with in-house security teams are not required to do so.”

A concept depicting a data leak [GETTY IMAGES]

The incident has already affected several live events. Producers of musicals such as "Bare the Musical," "Gutenberg" and "The Bridges of Madison County" — which use Yes24’s ticketing platform — posted on social media Tuesday evening asking attendees to bring booking confirmation emails or printed tickets.

They added, “Entry will proceed as normal if seat information can be confirmed. Otherwise, entry may be restricted depending on the situation at the venue.”

K-pop boy band Enhypen canceled applications for its fan signing event, originally scheduled to remain open through Yes24 from June 7 to 9.

Yes24 said it is preparing compensation plans for affected users and partners. “We will notify everyone of detailed compensation according to the scope of the damage, once services are restored,” the company said.

The Korean publishing industry faced a similar cyber incident in 2023, when rival online bookstore Aladin was hacked. That breach resulted in the leak of approximately 720,000 e-books, with 5,000 of them illegally circulated. Compensation for copyright damages followed.

Translated from the JoongAng Ilbo using generative AI and edited by Korea JoongAng Daily staff. BY LEE HOO-NAM [yoon.soyeon@joongang.co.kr]

Copyright © 코리아중앙데일리. 무단전재 및 재배포 금지.