UK and Republic of Korea Issue Warning about DPRK State-Linked Cyber Actors
Time 2 Minute Read

On November 23, 2023, the UK government’s National Cyber Security Centre (“NCSC”) and the Republic of Korea’s National Intelligence Service (“NIS”) issued a joint advisory detailing techniques and tactics used by cyber actors linked to the Democratic People’s Republic of Korea (“DPRK”) that are carrying out software supply chain attacks. The publication follows the recent announcement of a new Strategic Cyber Partnership between the UK and the Republic of Korea where the two nations have committed to work together to tackle common cyber threats.

In the statement by the NCSC, it notes that DPRK state-linked cyber actors have been using increasingly sophisticated techniques to gain access to victims’ systems. Particularly, the cyber actors have been observed leveraging zero-day vulnerabilities in third-party software to gain access to specific targets or indiscriminate organizations via their supply chains. The NCSC and the NIS consider these supply chain attacks to “help fulfil wider DPRK-state priorities, including revenue generation, espionage and the theft of advanced technologies.” In addition to providing technical details about the malicious activity and tactics of the cyber actors, the joint statement also includes case studies of recent attacks emanating from the DPRK and advice on how organizations can seek to mitigate supply chain compromises. The NCSC and NIS believe these attacks are likely to increase and therefore encourage organizations to follow the recommended actions in the joint advisory.

You May Also Be Interested In

Time 2 Minute Read

On March 25, 2026, the UK Information Commissioner’s Office and the UK Office of Communications released a joint statement addressing the intersection of online safety and data protection in relation to age assurance.

Time 2 Minute Read

On March 23, 2026, the UK Information Commissioner's Office released new guidance clarifying the use of the new recognized legitimate interest lawful basis for processing personal information under UK data protection law.

Time 3 Minute Read

On February 27, 2026, the UK ICO announced a public consultation on proposed updates to its guidance concerning research, archiving and statistics to reflect the changes introduced by the Data (Use and Access) Act 2025.

Time 2 Minute Read

On February 24, 2026, the UK ICO announced that it had fined Reddit, Inc. £14.47 million following an investigation into the company’s handling of children’s personal information.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page