Desk live·
ForensicPost
Ransomware/Third party/File 25-1110b

One Provider, Twenty Asset Managers

Qilin ransomware reached more than twenty South Korean asset management companies through the compromise of a single managed service provider, in a campaign dubbed Korean Leaks.

Constructed geometry · not a chart of case data
JurisdictionSouth Koreathe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetSouth Korean asset managers
ActorQilin
D. Kennedy12 min readConfidence: medium2 sources reviewed

More than twenty South Korean asset management companies were infected with Qilin ransomware following the compromise of a managed service provider identified in reporting as GJTec, in a campaign researchers named Korean Leaks. Reporting places the eventual victim count at 28.

The Downstream Victims Are The Sector, Not A Sample Of It

Twenty-plus asset management firms in one national market is not a random selection. It is a substantial share of an industry, reached because they shared an IT provider.

This desk filed at 25-0909 that two of France’s four major carriers disclosing within a month approaches population-scale coverage, and at 25-1130 that a single platform breach in a national market approaches the population.

Sector concentration behind one provider is a third version of the same structure, and it is the one a customer can least easily discover — you can see who your competitors bank with more readily than who runs their servers.

Financial Firms Outsourcing IT Is The Normal Case

An asset manager is a small organisation by headcount with regulatory obligations designed for large ones. Outsourcing IT is the standard response, and it is encouraged.

DORA at 25-0117 is the one instrument in this corpus that reaches critical ICT providers for financial entities, and it applies in the EU. The corpus filed at 25-0713 that Gulf banking incidents lacked the supervisory reporting that makes EU and US financial data usable; the same asymmetry applies here.

On The State-Actor Suggestion

Some reporting raises possible involvement of North Korean state-affiliated actors alongside the ransomware-as-a-service operation.

This desk records that as raised and not established. The corpus filed at 25-0731 that a state-linked group running ransomware collapses the distinction the database is organised around, and at 26-0217 that tradecraft resemblance is not identification. Graded medium accordingly.

How we reported this

Compiled from published research reporting, listed below. Victim counts vary between accounts. The suggestion of state-affiliated involvement is reported and not established. Corrections: corrections@forensicpost.com.

Sources
  1. Qilin ransomware turns South Korean MSP breach into 28-victim Korean Leaks data heistThe Hacker News
  2. Most notable supply-chain attacks of 2025Kaspersky
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary