
Security company Oasis Security discovered large amounts of data on foreign attackers' servers
AI-generated summary
While analyzing the server of an overseas attacker, security company Oasis Security discovered leaked data related to two large domestic churches.
(Seoul = Yonhap News) Reporter Kwon Ha-young = A security company analysis confirmed that two large domestic churches suffered cyber attacks and member personal information, donations, accounting data, and internal documents were leaked.
According to Oasis Security, a cyber threat intelligence company, on the 6th, as a result of analyzing attack tools, records, data, and account information obtained from overseas attacker servers, large-scale church member information related to two large domestic religious institutions was discovered.
Oasis Security announced that the analysis showed that the scope of the attack had expanded to other internal systems through systems accessed from the outside of both churches.
In particular, the company explained that actual data related to a domestic church was found on the overseas attacker's server, and that the data appears to have been transmitted to an external server.
According to Oasis Security, in the case of Church A, an attacker used a web shell, a malicious program, to infiltrate the enterprise resource planning (ERP) system server and secured administrator rights for the database used by the system.
The company announced that it had confirmed that the attacker had accessed services connected to other internal systems using the privileges obtained in this way.
The company explained that about 330,000 records of member donations believed to be related to Church A and about 960,000 pieces of member information updated over the past two years were discovered on the overseas attacker's server.
It was also revealed that approximately 47.3 GB of data, including approximately 68,000 electronic payment documents and 14,706 internal messenger conversation records, were also discovered.
In the case of another church, Church B, Oasis Security analyzed that the attacker accessed the groupware server using account information believed to have been obtained in advance.
According to the company, the attacker later expanded the scope of access by exploiting system vulnerabilities to access other user information and secure administrator-level accounts.
The company also said that ERP was also accessed through the integrated login function, which allows access to multiple systems with a single login, and that employee information and photos were obtained in the process.
Oasis Security announced that it had confirmed information on 89,000 church members and 286 cases of employee information believed to be related to Church B on the overseas attacker's server.
According to Oasis Security, during this analysis, it was discovered that the administrator account of an external storage server related to a violation of a religious content and streaming service in the United States was also used to store and transmit data related to domestic churches.
Based on this, the company analyzed that there is a possibility that accounts and related infrastructure secured during the breach of American religious content and streaming services were later used in attacks targeting domestic churches.
However, based on these circumstances alone, it is difficult to conclude that the subject of each attack is the same.
Oasis Security said, “There is a need to check how core business systems such as personnel and accounting systems, groupware, and databases are connected to each other and what the authentication and authorization systems are.”

Over the past five years, the share of major overseas telecommunications carriers, such as Google and Netflix, in domestic Internet traffic has increased to 47%. As foreign operators took the top 1 to 3 positions, the debate over network usage fees reignited.

Minister of Science and ICT Bae Kyung-hoon announced during the National Assembly audit that the AI model applied to the government business AI platform will be replaced with the second model of the independent foundation model (Dokpamo). This is a measure taken in response to criticism that the government-wide AI platform included Chinese AI models.

The passwords of over 75,000 Google Workspace accounts used by schools and educational institutions in the Daejeon area were changed without permission, and the Daejeon Metropolitan Office of Education took measures to suspend use and change them again.

DigitalX announced that it has launched a new app equipped with a generative artificial intelligence chatbot, the first domestic virtual asset exchange. Users can obtain market information and place orders by asking questions in natural language, and there is also a function to switch between Lite and Pro modes and a reward event when missions are achieved.

It was confirmed that the attacker IP used in the recent hacking incident at a major financial company also attempted to access Kakao Bank, K Bank, and Toss Bank servers several times, but it was detected and blocked by the security system, so no actual damage occurred, the financial industry announced.

LG will launch five components made by three affiliates aboard South Korea's Nuri rocket on Wednesday to test their performance in space, marking the conglomerate's first groupwide space technology demonstration using a CubeSat developed with Unmanned Exploration Laboratory.