Seoul Semiconductor Co., Ltd. Ransomware Attack: A Cybersecurity Threat

Incident Date: May 07, 2024

Attack Overview
VICTIM
Seoul Semiconductor Co., Ltd.
INDUSTRY
Manufacturing
LOCATION
South Korea
ATTACKER
MetaEncryptor
FIRST REPORTED
May 7, 2024

Ransomware Attack on Seoul Semiconductor Co., Ltd.

Victim Profile

Seoul Semiconductor Co., Ltd. is a South Korean company specializing in manufacturing and distributing light emitting diode (LED) products. Founded in 1987, the company is headquartered in Ansan-si, South Korea. Seoul Semiconductor's product range includes z-power LED, top view LED, through hole, side view LED, customized module, chip on board LED, chip, and sensor. The company operates manufacturing factories in Korea, the US, China, and Vietnam, with a presence in 30 offices across about 70 countries.

Industry Standing

Seoul Semiconductor is a key player in the LED industry, known for converting electric energy into light using eco-friendly and energy-efficient technologies. The company is listed on the Korea Exchange and ranks among the world's top 3 LED manufacturers, with annual revenues exceeding $1 billion based on IFRS consolidated financial reporting.

Attack and Vulnerabilities

During the ransomware attack the ransomware group stole 23GB of sensitive data from the company's systems. As a prominent player in the LED manufacturing sector, Seoul Semiconductor's global presence and innovative technologies make it an attractive target for threat actors. The company's extensive network of manufacturing facilities and international offices may pose challenges in maintaining fortified cybersecurity measures across all locations, potentially exposing vulnerabilities that ransomware groups like MetaEncryptor could exploit.

Ransomware Group Tactics

MetaEncryptor, the ransomware group behind the attack on Seoul Semiconductor, is known for its sophisticated encryption techniques and data leak site operations. The group has been linked to similar ransomware operations like LostTrust, indicating a pattern of rebranding to evade detection. MetaEncryptor's use of a data leak site and encryption methods similar to other ransomware groups suggest a high level of coordination and expertise in cyber attacks.

Sources:

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.