Yes24
Incident posture
Timeline
Summary
Yes24 suffered a ransomware attack that disrupted its website and mobile app, preventing users from accessing books, e‑books, tickets and other services until the platform was brought back online later that day. The company said the intrusion began early in the morning and was resolved after several hours, noting that users saw messages about heavy traffic or technical errors during the outage. This incident followed a previous ransomware event that had crippled the system for several days, prompting the firm’s leadership to apologize and promise a comprehensive security overhaul, increased investment and external expert assistance.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
Early Monday morning at approximately 4:40 a.m., a ransomware attack disabled user access to Yes24’s website and mobile application. A Yes24 official confirmed the incident and issued an apology for the inconvenience caused by the external ransomware attack. The official stated that the company had been working to restore the service. By 11:30 a.m., all services were reported to be fully accessible and functioning normally. Users had been unable to access the website, e‑books, and other services from the early morning hours. The site and app remained down until around 11:00 a.m., displaying notices that cited heavy traffic or technical errors as the cause of the disruption.
In June of the same year, Yes24’s systems had been paralyzed by a separate ransomware attack. During that incident, services gradually resumed over a period of five days. The company delayed informing users and authorities about the June attack until media reports brought the issue to public attention. Yes24 reports having 20 million registered users and offers a diverse inventory that includes books, music, stationery, and tickets for concerts and theater performances. The outage resulting from the June attack caused prolonged and widespread disruptions for its user base. Following the June incident, the company’s co‑CEOs, Kim Seok‑hwan and Choi Se‑ra, issued a public apology and pledged to overhaul security measures, increase funding, and engage outside experts to strengthen cybersecurity.
The August attack was resolved by the afternoon, with service restoration completed by 11:30 a.m. as stated by the official. Yes24’s response included ongoing efforts to restore service and communication of the apology to affected users. No further details about attacker identity, ransom demands, or specific technical mitigations were provided in the source material.
Sources
Sources available to members: 1 source.