KR Auction.co.kr Feb 2008 Hacking (Q13071)
From Open Risk Manual
A data breach risk event
Language | Label | Description | Also known as |
---|---|---|---|
English | KR Auction.co.kr Feb 2008 Hacking |
A data breach risk event |
Statements
DF83DDE3-BBCE-4498-9256-2D6C128646C9
February 2008
0 references
South Koreas largest online shopping site earlier this month was attacked by a Chinese hacker who made off with the user information on 18 million members and a large amount of financial data. The attack was launched from Chinas internet. After the incident, Auction.co.kr received a phone call offering to exchange the user information for money, the reports said. According to a report on Dark Visitor, a security blog site, the Chinese hacker did not directly attack the server. The hacker sent out bulk emailings to the auction staff containing hacker procedures that may have contained malware. When the staff members confirmed the emails, the hacker was able to gain their IDs. The hacker was then able to log into the Auction server using the staffers ID. The WASC report categorizes the expl (English)