Hacking attacks through ransomware call taxis 'eaten' all over the country

Hacking attacks through ransomware call taxis 'eaten' all over the country


Issue Date: 2022-07-18 18:04
A company operating a 'call taxi system' in most cities and counties in Gangwon-do was attacked by a hacking attack, and call taxi calls through smartphone apps were blocked. It was found that the call system was paralyzed in parts of Busan, Gyeonggi, Gyeongbuk, and Jeonnam in addition to Gangwon due to the hacking damage.

According to Yonhap News, as of 5 pm on the 18th, call systems in Chuncheon, Donghae, Yanggu, Jeongseon, Inje, Goseong, and Yangyang in Gangwon are not operating normally. In the case of Chuncheon, 1362 Smile Call taxis are not receiving calls through the app. Therefore, they are using other apps or dispatching by phone.

As in the past, other affected cities and counties are also responding by receiving calls from landlines and dispatching them.

A company operating a call taxi system in most cities and counties in Gangwon-do was attacked by a hacking attack, and call taxi calls through smartphone apps were blocked.

A taxi worker in the Chuncheon area said, "In the case of Chuncheon, dispatches are made using other programs, but in other cities and counties, the store will be closed."

In the case of Busan, the dispatch of 'Duribal', a special means of transportation for the disabled, which is consigned by the Busan Facilities Corporation, is manually switched and operated, so dispatching is significantly delayed. The call system of 'Zabicall', a call taxi for the transportation vulnerable, is also paralyzed.

Accordingly, the city of Busan is instructing the disabled to pay only 35% of the deductible while using a call taxi using the phone number of the self-call driver owned by the disabled in consultation with the disabled group.

A developer operating a call system said to the city and county, “Our call system operating across the country was infected by hacking (ransomware) by an overseas hacking organization around 2 am on the 17th, and all centers and backup servers in service were infected. stopped,” he said.

Ransomware is a malicious program used by hackers to encrypt a victim's system or data so that it cannot be used and then take it hostage and demand money.

The company explained, "In this regard, immediately after infection, we confirmed that it was a new type of ransomware through the Korean Ransomware Recovery Center, and contacted the hacker in the early morning of the 18th for an urgent solution and contacted the hacker to restore the backup server."

He added, “I paid the coin required by the hacker to restore the backup server, and now I have requested the data recovery key.”

According to the company, emergency recovery is carried out after receiving the recovery key within the same day, and recovery is expected to take two to three days.

The company said, “We are sorry for the inconvenience caused to the service due to the first new ransomware attack.

By Ahn Ho-cheon, staff reporter [email protected]