South Korea
KOR
KYOWON detected abnormal activity on 10/01/2026 and isolated internal networks after determining that the incident involved ransomware. Reporting based on the incident investigation described ransomware propagation across interconnected affiliate systems, with most of the group's IT network, including its KSS internal authentication and management platform, becoming unavailable. Websites, key services and internal database access were disrupted across affiliates involved in education, travel, funeral services, healthcare-related products and warehousing. Website access began returning from 12/01/2026 and most websites and key functions were operating normally by 14/01/2026. Kyowon also confirmed indications of external data exfiltration, while incident reporting documented extortion activity.
Estimated severity
82 / 100
Source reliability
92 / 100
Approximate Date
10/01/2026
Targeted Company
KYOWON
Distribution & Fulfillment
Procurement & Sourcing
Production & Manufacturing
Sales (Retail & Ecommerce)
Warehousing
Service Delivery
Unrecognized Impact
Supply Chain Relations
No information
South Korea
KOR
No other affected countries reported
Target country
South Korea
Affected countries
Impacted regions
No information
Duration
No information
Financial impact (USD M)
No information
Impact types
Affected sectors
Affected departments
Attack types
Attributed threat actors
No information
Incident Sources
Please rotate your phone