Korea's cyber crisis alert levels — normal to serious, and what 'caution' changes
South Korea grades cyber threats on a five-step scale: normal, attention (gwansim), caution (juui), alert (gyeonggye) and serious (simgak). Attention means warning signs with little chance of a national crisis; caution means real damage at some organisations with a risk of spreading; alert means damage spreading across several sectors; serious means nationwide network paralysis. The national alert is issued with the National Intelligence Service at the centre, while the Ministry of Science and ICT and the Korea Internet and Security Agency (KISA) cover the private sector. On October 4, 2026, after AI-assisted hacks leaked data from seven financial firms, the ministry raised KISA monitoring to caution and told financial firms to check web and API flaws and exposed credentials
The three lines
- Five levels — normal, attention, caution, alert, serious; caution is where real damage plus spread risk begins
- Who — national level centred on the NIS; private sector on the science ministry and KISA; finance on its regulators
- October 4 — KISA monitoring raised to caution after the bank hacks; 24-hour response; web, API and credential checks
Key questions
- South Korea cyber alert levels
- **Graded by whether damage is real and how far it has spread.** | Level | Situation | |---|---| | Normal | No warning signs | | Attention | Signs of threat, low chance of national crisis | | Caution | Damage at some organisations, may spread | | Alert | Damage spreading across sectors | | Serious | Nationwide network paralysis |
- What happens at cyber alert caution level
- **Monitoring goes round-the-clock and the whole sector is told to check itself.** | Change | Detail | |---|---| | Monitoring | 24-hour emergency watch | | Sharing | Attacker IPs and methods pushed to related bodies at once | | Checks | Sector-wide emergency vulnerability reviews | | Reporting | Faster incident reporting |
- Who issues Korea cyber crisis alerts
- **Different bodies for different domains.** | Domain | Responsible | |---|---| | National, public | National Intelligence Service | | Private sector | Ministry of Science and ICT, KISA | | Finance | Financial Services Commission, FSS, Financial Security Institute | | Defence | Ministry of National Defense |
When Korean headlines say a cyber alert was "raised to caution," what actually changes? On October 4, 2026, after seven financial firms lost customer data to attacks linked to an AI penetration-testing tool, South Korea's science ministry raised the monitoring level at the Korea Internet and Security Agency (KISA) to "caution" (juui). Korea's cyber alerts work like weather warnings: fixed levels, each with set government actions.
1. Five levels
| Level | Situation | Weather analogy |
|---|---|---|
| Normal | Peacetime, no signs | Clear |
| Attention | Signs of threat, low activity, unlikely national crisis | Cloudy |
| Caution | Actual damage at some organisations, could spread | Advisory |
| Alert | Damage spreading across several sectors | Warning |
| Serious | Nationwide paralysis or massive damage | Disaster |
The key line is between attention and caution: up to attention, it is about signs; from caution, damage has been confirmed. The bank hacks crossed exactly that line.
2. Who raises and lowers it — there is more than one alert
| Domain | Body | Role in October 2026 |
|---|---|---|
| National, public | National Intelligence Service (National Cyber Security Center) | Public-sector alert |
| Private | Ministry of Science and ICT, KISA | Monitoring raised to caution Oct 4; 24-hour response |
| Finance | FSC, FSS, Financial Security Institute | Attacker IPs sent to ~500 firms; checks due Oct 8 |
| Defence | Ministry of National Defense | Military networks |
So the national alert can sit at attention while private-sector monitoring is at caution. When you see "alert raised," check who raised which domain. This time it was KISA's private-sector monitoring.
3. What caution changes
| Item | Attention | Caution |
|---|---|---|
| Monitoring | Strengthened | 24-hour emergency watch |
| Information sharing | Regular | Attacker IPs and methods pushed immediately |
| Checks | Voluntary | Sector-wide emergency reviews recommended |
| Scope | Key institutions | Affected sector plus those at risk |
Alongside the October 4 move, financial firms were told to review web and API vulnerabilities and exposed credentials — the very weaknesses the attackers used in back-office systems.
4. Raised even without damage
Levels also go up pre-emptively at high-risk times.
| When | Action | Reason |
|---|---|---|
| Before 2012 general election | Attention | Election and North Korean missile launch |
| March 2022 | Attention → caution | More hacking attempts; joint drills with the U.S. |
| June 3, 2025 presidential election | Temporary caution, back to attention after | Election-period threats |
| October 4, 2026 | KISA private monitoring to caution | Confirmed AI-assisted damage in finance |
The October move matters because it responds to confirmed damage from automated, AI-assisted scanning — attacks that hit many targets at once and can shrink the time between "some organisations" and "several sectors."
5. What remains unconfirmed
- The national alert level as of October 7 was not confirmed from the NIS.
- The prior KISA level of attention is from some reports.
- Detailed criteria for alert and serious levels are not public.
Sources
- News1 — Science ministry raises KISA monitoring to 'caution' after financial AI hacking
- Korea Policy Briefing — National cyber crisis alert raised to 'caution'
- KISA KrCERT — Cyber crisis alert raised from 'attention' to 'caution'
- Boan News — After the election, NIS lowers cyber alert from 'caution' to 'attention'
- Korea Policy Briefing — Government issues cyber crisis 'attention' alert