A significant ransomware attack by the Qilin group has compromised 28 financial institutions in South Korea, resulting in the leakage of 2TB of data. The attack targeted GJTec, a South Korean IT service provider, in a supply chain breach dubbed "Korean Leaks." Over 1 million files were exposed in the incident. Bitdefender's investigation links the operation to the North Korean-backed APT "Moonstone Sleet," suggesting collaboration with the Russian-speaking Qilin group. The attack appears to be an effort to exert pressure on the South Korean financial market.