4,778 Cyberattacks in 5 Years... 35% of Ministry of Land, Infrastructure and Transport Affiliates in Security Blind Spot
Assemblyman Jo Incheol Analyzes Ministry Data
800 to 1,000 Attack Attempts Detected Annually
11 Out of 31 Affiliated Institutions Not Connected to Security Monitoring System
Nearly 5,000 attempted cyberattacks targeting the land, infrastructure, and transport sector have been detected over the past five years. However, one out of every three public institutions under the Ministry of Land, Infrastructure, and Transport (MOLIT) still remains unconnected to the National Cyber Security Monitoring System. Concerns are being raised about gaps in the cybersecurity of institutions operating systems closely tied to daily life, including railways, roads, airports, and housing and spatial information.
According to an analysis by Assemblyman Incheol Jo of data submitted by the Ministry of Land, Infrastructure, and Transport to the National Assembly's Land, Infrastructure, and Transport Committee on October 6, a total of 4,778 attempted cyberattacks were detected from 2021 to last year at the ministry and its affiliated organizations that have implemented the National Cyber Security Monitoring System.
By year, there were 1,021 cases in 2021, 989 in 2022, 812 in 2023, 1,019 in 2024, and 937 last year. Attempts have consistently hovered between 800 and 1,000 each year over the past five years. The most common type was “web vulnerability,” such as website defacement or manipulation, accounting for 2,609 cases or 54.6% of the total.
There were also 1,902 cases of "simple intrusion attempts," making up 39.8%. Combined, these two categories accounted for 94.4% of all detected attempts. However, it should be noted that these numbers reflect detected attempts classified by type, not actual incidents where websites were compromised or systems were breached.
By institution, the Ministry of Land, Infrastructure, and Transport topped the list with 766 cases. Among affiliated agencies, Korea Real Estate Board recorded the most with 655 cases, followed by Korea Railroad Corporation with 579, Korea Agency for Infrastructure Technology Advancement with 557, and Korea Expressway Corporation with 461. These organizations, which are responsible for areas such as housing and real estate information, railways and roads, and land, infrastructure and transport R&D—closely connected to daily life and national infrastructure—were among the most targeted.
In particular, SR, which merged with the Korea Railroad Corporation last September, saw the number of detected attack attempts surge from 23 in 2021 to 175 last year—an increase of approximately 7.6 times. The attacks rose from 44 in 2022, to 29 in 2023, to 97 in 2024, and ultimately to 175 last year.
The core issue is that, despite these repeated cyberattack attempts, some affiliated agencies still are not connected to the national-level security monitoring network. As of September this year, 11 out of 31 public institutions under MOLIT, equivalent to 35.5%, remained unconnected to the National Cyber Security Monitoring System.
The unconnected agencies include Gadukdo New Airport Construction Authority, Construction Technology Training Institute, Spatial Information Industry Promotion Institute, Spatial Information Quality Management Agency, National Aviation Museum of Korea, Automotive Insurance Claims Adjustment Promotion Agency, KORAIL Tourism Development, KORAIL Logistics, KORAIL Tech, Korea Expressway Corporation Service, and Korea Overseas Infrastructure & Urban Development Corporation.
The MOLIT Information Security Work Regulations stipulate that agencies required to establish and operate sectoral or unit security monitoring centers, according to the National Intelligence Service's cybersecurity regulations, must connect their monitoring centers to the National Cyber Security Monitoring System. Security monitoring involves the continuous detection, analysis, and response to external cyberattacks.
It was found that all 11 unconnected institutions have established plans to connect to the national system. However, actual integration has been delayed. This delay has sparked criticism that the ministry needs to go beyond simply setting plans by actually checking the budget, personnel, and system readiness of each agency, and managing integration with the monitoring network.
Assemblyman Jo remarked, "From railways and roads used for commuting to airports, housing, and spatial information, the systems in the land, infrastructure and transport sector are embedded in the routines of daily life," and added, "With around 1,000 cyberattack attempts detected every year, it is unacceptable for one in three affiliated institutions to remain unconnected to national security monitoring for an extended period."
Hot Picks Today
[Exclusive] "Forecasts of Over 10 Billion, but Only 100 Million Earned"... 95% Followed This Pattern: Why Are KOSDAQ Special Exception IPOs Inflated? [KOSDAQ Inflated IPOs]①
- Korean Language Proficiency Rises Again in the AI Era... Sales of "Korean Language" Books Up 11.2%
- "My Debt Is 73 Million Won"... Sharing Every Repayment Led to an Unexpected Turn
- "Drinking This in the Morning Is Like Drinking Alcohol"..."Doctors Warn: Never Consume It"
- Is 'KOGUMA' Coming Too?... "Japan in Serious Trouble" - Archipelago on High Alert Ahead of Holidays
He further emphasized, "The ministry must thoroughly assess the budget, personnel, and system readiness at each of the 11 unconnected agencies and provide support where necessary," adding, "No vulnerabilities should be left in the cybersecurity of any sector, whether railways, roads, airports, housing, or spatial information."
© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.