More than twenty South Korean asset management companies were infected with Qilin ransomware following the compromise of a managed service provider identified in reporting as GJTec, in a campaign researchers named Korean Leaks. Reporting places the eventual victim count at 28.
The Downstream Victims Are The Sector, Not A Sample Of It
Twenty-plus asset management firms in one national market is not a random selection. It is a substantial share of an industry, reached because they shared an IT provider.
This desk filed at 25-0909 that two of France’s four major carriers disclosing within a month approaches population-scale coverage, and at 25-1130 that a single platform breach in a national market approaches the population.
Sector concentration behind one provider is a third version of the same structure, and it is the one a customer can least easily discover — you can see who your competitors bank with more readily than who runs their servers.
Financial Firms Outsourcing IT Is The Normal Case
An asset manager is a small organisation by headcount with regulatory obligations designed for large ones. Outsourcing IT is the standard response, and it is encouraged.
DORA at 25-0117 is the one instrument in this corpus that reaches critical ICT providers for financial entities, and it applies in the EU. The corpus filed at 25-0713 that Gulf banking incidents lacked the supervisory reporting that makes EU and US financial data usable; the same asymmetry applies here.
On The State-Actor Suggestion
Some reporting raises possible involvement of North Korean state-affiliated actors alongside the ransomware-as-a-service operation.
This desk records that as raised and not established. The corpus filed at 25-0731 that a state-linked group running ransomware collapses the distinction the database is organised around, and at 26-0217 that tradecraft resemblance is not identification. Graded medium accordingly.
Compiled from published research reporting, listed below. Victim counts vary between accounts. The suggestion of state-affiliated involvement is reported and not established. Corrections: corrections@forensicpost.com.