North Korea was responsible for a cyber attack that shut down tens of thousands of computers and servers at South Korean broadcasters and banks last month, officials in Seoul say, noting that an initial investigation pointed to a military-run spy agency as the culprit.
The accusation comes as tensions run high on the Korean Peninsula, with North Korea delivering increasingly belligerent rhetoric as it stews over UN sanctions and US-South Korean military drills.
Investigators detected similarities between the March cyber attack and past hacking attributed to the North Korean spy agency, including the recycling of 30 previously used malware programs – out of a total of 76 used in the attack, said Chun Kil-soo, an official at South Korea's internet security agency.
Investigators believe six computers in North Korea were used to access South Korean servers using more than 1000 IP addresses in 40 countries overseas, Chun said. Thirteen of those IP addresses were traced back to North Korea.
He said the attack appeared to have been planned for about eight months.
"We saw evidence that the attack was extremely carefully prepared," Chun said.
The March 20 cyber attack struck 48,000 computers and servers, hampering banks for two to five days, although Financial Services Commission official Lim Wang-sub said no bank records or personal data were compromised. Staffers at TV broadcasters KBS, MBC and YTN were unable to log on to news systems for several days, although programming continued during that period. No government, military or infrastructure targets were affected.
It was not the first time Seoul has blamed Pyongyang for such online assaults.
South Korea's National Intelligence Service said North Korea was behind a denial of service attack in 2009 that crippled dozens of websites, including that of the presidential office. Seoul also believes the North was responsible for cyber attacks on servers of Nonghyup bank in 2011 and Joongang Ilbo, a national daily newspaper, in 2012.
North Korea blamed South Korea and the US for cyber attacks in March that temporarily disabled internet access and websites in North Korea, where a small number of people can go online.
Though Wednesday's findings were from an interim investigation report, the final conclusions were not likely to change much, said Lim Chae-ho, a professor of network security at the Korea Advanced Institute of Science and Technology.
"Future evidence will strengthen the case rather than reverse it," Lim said. "It is worrisome that the North's cyber attacks are getting increasingly severe."
Experts believe North Korea trains large teams of cyber warriors and that the South and its allies should be prepared against possible attacks on key infrastructure and military systems. If the inter-Korean conflict were to move into cyberspace, South Korea's deeply wired society would have more to lose than North Korea's, which remains largely offline.