
A fire occurred at the National Information Resource Center of South Korea in Daejeon, the main government data center, almost two weeks ago, on September 26. As a result, many government digital services stopped working, from the South Korean analogue of “Gosuslug” and identification cards to websites and emails of government departments.
The fire destroyed the storage of electronic documents and work files of civil servants - 858 terabytes of data were lost . Moreover, there are no backup copies of this data, so a significant part of it is lost forever. Some things can be recovered from local copies, email and paper archives.
Officials explain that the database was too large and low-performance, and it was technically impossible to back it up. They were criticized for using a system with such a blatant vulnerability.
The work of several departments was paralyzed - for example, the Ministry of Civil Service, which is responsible for hiring, salaries, insurance and pensions of officials (this is about 2% of the South Korean population).
The fire occurred during maintenance work due to the explosion of a lithium-ion battery that powered the server equipment. They extinguished the fire for about a day. One person was seriously injured.
South Korean President Lee Jae-myung criticized the officials responsible for the operation of the data center. “This was a predictable incident,” he said, “but nothing was done to prevent it. It’s not that the measures didn’t work, there were simply no measures.”
The main version of the reasons for the incident is negligence. Police arrested four people. An official from the South Korean government's Digital Innovation Office committed suicide by jumping from the 15th floor. His name is not mentioned, but it is known that he oversaw the restoration of the center’s network infrastructure. The Ministry of Internal Affairs emphasized that no police investigation was carried out against him in connection with the fire.

Meanwhile, the National Cyber Security Center, subordinate to South Korean intelligence, raised its alert level from “attention” to “caution.” The reason was the fear that hackers could take advantage of the vulnerability of the systems during restoration after the fire.
The fire occurred at the height of the hacking scandal. On September 24, the Committee on Science, Technology, Information, Broadcasting and Communications of the South Korean Parliament held a hearing in connection with hacks in the country's largest companies, most notably the KT telecommunications corporation. At the hearing, Korea University Graduate School of Security professor Kim Seung-joo said that not only KT and other private companies had recently been hacked, but also several government departments, including the Ministry of Foreign Affairs and counterintelligence, as well as the government's electronic document management system.
At the same time, Kim Seung-ju referred to an article in the hacker publication Phrack, from which it follows that the hacker group Kimsuky was behind the hacks. She works for North Korea and most likely has the support of China. The article claims that white-hat hackers, after gaining access to the computer of one of the Kimsuky members, confidentially notified South Korean agencies (including military counterintelligence) during June and July 2025 that they had been hacked.
Following parliamentary hearings, it was announced that an inspection of the Daejeon National Information Resource Center would take place on September 26. It is there that the servers of government departments are located, which, according to Phrack, were hacked by Kimsuky. The inspection was scheduled to begin at 8 p.m. The fire department was notified of a battery explosion and fire in the data center at 20:20. The servers - presumably showing signs of hacking - were lost.
"Jellyfish"