Co-authored by Asia Business Daily reporters Sim Nayoung, Jeon Youngjoo, and Park Yoojin
Tracking Victim Companies, Negotiators, and White-Hat Hackers
Uncovering ‘Korean-Style Silence’ After Hacking Incidents
Jury: “Highlights Meokkosanism,

The hacker demanded 500 million won. It was a small semiconductor parts maker located in the provinces, employing only 10 people. The amount extorted by the hacker was equivalent to the annual salary of all 10 employees combined. Yet the CEO, rather than reporting the incident to the authorities, paid the ransom. The company was about to launch an investment project that had been three years in the making. To him, the prospect of the hacking incident becoming public was more frightening than losing 500 million won. He told the reporter, "I can't risk the fate of a company I've dedicated my entire life to over five hundred million won."

A Nation That Remains Silent After Being Hacked... 'Korea Has Been Hacked' Selected for Sejong Book List View original image

It's a strange situation: a crime is committed, but the victim has to hide. There’s something even stranger, too. Companies targeted by hackers often reach out for help not from the government, but from someone else first: the “negotiator.” If the hacker demands 15 bitcoins as ransom, the negotiator might bargain it down to 9. Part of the saved amount becomes the negotiator’s fee. It’s like a hostage negotiation, except the hostages are servers, not people. This is the current reality for companies in Korea.


'Korea Has Been Hacked' (published by Sideway), written by The Asia Business Daily reporters Sim Nayoung, Jeon Youngju, and Park Yujin, has been selected for the Sejong Books program in the general knowledge category by the Publication Industry Promotion Agency of Korea. The book was published in December of last year. At first glance, the title suggests a technical manual on cybersecurity. But after reading it, you’re left with a very different impression. What lingers most from this book isn’t the hackers’ techniques—it's the people who, after being attacked, are unable to speak out.


The three reporters sought out victimized companies, white-hat hackers, security experts, and negotiators working out ransom deals with hackers. What they discovered was a paradox. While digital crime has become frighteningly sophisticated, the culture enabling it has deep roots. When an incident is made public, someone is expected to take responsibility. Bad news is rarely reported upwards. Security doesn’t immediately translate into revenue. If a problem arises, it is often easier for organizations to quietly sweep it under the rug than to deal with it openly.


According to the government's "2024 Information Security Status Survey," the hacking incident reporting rate was just 4.1% for small and medium-sized businesses and 6.5% for larger companies. Even though companies can face fines for failing to report to the relevant authorities, most remain silent. This is because they judge that the potential loss of trust and the administrative burden caused by reporting outweigh any benefits from doing so. In effect, victims fear revealing their plight more than they fear the perpetrators themselves.


This is what makes the book’s title so peculiar. It doesn’t say "Your company has been hacked," or "Your personal data has been compromised." Instead, it declares, "Korea Has Been Hacked."


While hackers attack servers, what the authors ultimately examine is Korean society itself. According to the summary submitted to the Publication Industry Promotion Agency of Korea, the book identifies "meokgosanism (the prioritization of making a living), convenience-driven attitudes, complacent collectivism, and hierarchical organizational culture" as the background factors. Combined with the government’s inadequate data collection systems, which can't even properly track the scope of the damage, this has led to growing "security gaps," according to the authors.


“Meokgosanism” especially stands out as a term, because it's so unrelated at first glance to hacking. But on second thought, it may be the closest concept to hacking in the context of this book. Unless an incident happens, investments in security don't generate visible results, so they get placed on the back burner when more urgent business needs arise. The same reasoning applies even after incidents occur. From a business owner’s perspective, quietly paying off the ransom can seem like a rational option compared to risking the company's reputation and business relationships by reporting the incident. But the sum of these individual, rational choices results in the most dangerous outcome for society as a whole.


This is where hacking ceases to be merely an IT issue. If those who report problems within an organization are treated as troublemakers, real risks may never get communicated upward. If the companies that reveal their incidents suffer losses and those that cover them up survive, statistics will never reflect the truth. Without statistics, the nation has no way to gauge the extent of risks or respond to prevent similar incidents in the future.


Disasters that go unrecorded are disasters we cannot learn from. The selection committee for the Sejong Books program focused on this point as well. Judge Choi Jeongwon commented, "The hacking incidents that have come to light are only a fraction of the whole; the majority have been concealed.” The judges went on to note that the authors highlighted "meokgosanism, hierarchical culture, and the government's neglect—even the lack of statistics—as key factors in the problem." They concluded, "This book is recommended for readers who want to face the reality of hacking as a disaster."


The book argues that punishing companies more severely for not reporting incidents won’t solve the problem. Instead, it proposes providing incentives such as tax credits to encourage companies to view security spending as preventive investment, as well as setting up mechanisms like cyber insurance so companies can share the risk with society when incidents do occur. Before punishing those who keep quiet, it asks why people feel the need to hide in the first place.


'Korea Has Been Hacked' was also selected by the Korean Publishers Association in January for its "Noteworthy New Books" list. These selections are introduced as recommended reads to more than 3,000 library staff members nationwide. Now, the book has also been recognized in the general knowledge category of the Sejong Books program. Being selected twice shows that this book is not just for people in the security industry. Although it deals with hacking, in reality, the book asks: How do organizations in Korea handle bad news? How does the nation manage invisible risks?


After hackers break in, they erase their traces. But in Korea, sometimes the evidence is erased again: the victimized company does not speak up, the incident is not recorded, and so it disappears from the statistics as well.



The hack happens once, but the incident disappears twice. First by the hacker, and a second time by ourselves.


This content was produced with the assistance of AI translation services.

© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.

Today’s Briefing