Skip to content
TEN Brief Ten verified stories a day 2026.10.07 KO

이 기사는 한국어로도 읽을 수 있습니다 →

Tech · 2 min read · Explainer

Korea's cyber crisis alert levels — normal to serious, and what 'caution' changes

South Korea grades cyber threats on a five-step scale: normal, attention (gwansim), caution (juui), alert (gyeonggye) and serious (simgak). Attention means warning signs with little chance of a national crisis; caution means real damage at some organisations with a risk of spreading; alert means damage spreading across several sectors; serious means nationwide network paralysis. The national alert is issued with the National Intelligence Service at the centre, while the Ministry of Science and ICT and the Korea Internet and Security Agency (KISA) cover the private sector. On October 4, 2026, after AI-assisted hacks leaked data from seven financial firms, the ministry raised KISA monitoring to caution and told financial firms to check web and API flaws and exposed credentials

Staff seen from behind watching a wall of world-map screens in a sunlit cyber monitoring center

The three lines

  • Five levels — normal, attention, caution, alert, serious; caution is where real damage plus spread risk begins
  • Who — national level centred on the NIS; private sector on the science ministry and KISA; finance on its regulators
  • October 4 — KISA monitoring raised to caution after the bank hacks; 24-hour response; web, API and credential checks

Key questions

South Korea cyber alert levels
**Graded by whether damage is real and how far it has spread.** | Level | Situation | |---|---| | Normal | No warning signs | | Attention | Signs of threat, low chance of national crisis | | Caution | Damage at some organisations, may spread | | Alert | Damage spreading across sectors | | Serious | Nationwide network paralysis |
What happens at cyber alert caution level
**Monitoring goes round-the-clock and the whole sector is told to check itself.** | Change | Detail | |---|---| | Monitoring | 24-hour emergency watch | | Sharing | Attacker IPs and methods pushed to related bodies at once | | Checks | Sector-wide emergency vulnerability reviews | | Reporting | Faster incident reporting |
Who issues Korea cyber crisis alerts
**Different bodies for different domains.** | Domain | Responsible | |---|---| | National, public | National Intelligence Service | | Private sector | Ministry of Science and ICT, KISA | | Finance | Financial Services Commission, FSS, Financial Security Institute | | Defence | Ministry of National Defense |

When Korean headlines say a cyber alert was "raised to caution," what actually changes? On October 4, 2026, after seven financial firms lost customer data to attacks linked to an AI penetration-testing tool, South Korea's science ministry raised the monitoring level at the Korea Internet and Security Agency (KISA) to "caution" (juui). Korea's cyber alerts work like weather warnings: fixed levels, each with set government actions.

1. Five levels

LevelSituationWeather analogy
NormalPeacetime, no signsClear
AttentionSigns of threat, low activity, unlikely national crisisCloudy
CautionActual damage at some organisations, could spreadAdvisory
AlertDamage spreading across several sectorsWarning
SeriousNationwide paralysis or massive damageDisaster

The key line is between attention and caution: up to attention, it is about signs; from caution, damage has been confirmed. The bank hacks crossed exactly that line.

2. Who raises and lowers it — there is more than one alert

DomainBodyRole in October 2026
National, publicNational Intelligence Service (National Cyber Security Center)Public-sector alert
PrivateMinistry of Science and ICT, KISAMonitoring raised to caution Oct 4; 24-hour response
FinanceFSC, FSS, Financial Security InstituteAttacker IPs sent to ~500 firms; checks due Oct 8
DefenceMinistry of National DefenseMilitary networks

So the national alert can sit at attention while private-sector monitoring is at caution. When you see "alert raised," check who raised which domain. This time it was KISA's private-sector monitoring.

3. What caution changes

ItemAttentionCaution
MonitoringStrengthened24-hour emergency watch
Information sharingRegularAttacker IPs and methods pushed immediately
ChecksVoluntarySector-wide emergency reviews recommended
ScopeKey institutionsAffected sector plus those at risk

Alongside the October 4 move, financial firms were told to review web and API vulnerabilities and exposed credentials — the very weaknesses the attackers used in back-office systems.

4. Raised even without damage

Levels also go up pre-emptively at high-risk times.

WhenActionReason
Before 2012 general electionAttentionElection and North Korean missile launch
March 2022Attention → cautionMore hacking attempts; joint drills with the U.S.
June 3, 2025 presidential electionTemporary caution, back to attention afterElection-period threats
October 4, 2026KISA private monitoring to cautionConfirmed AI-assisted damage in finance

The October move matters because it responds to confirmed damage from automated, AI-assisted scanning — attacks that hit many targets at once and can shrink the time between "some organisations" and "several sectors."

5. What remains unconfirmed

  • The national alert level as of October 7 was not confirmed from the NIS.
  • The prior KISA level of attention is from some reports.
  • Detailed criteria for alert and serious levels are not public.

Sources

  1. News1 — Science ministry raises KISA monitoring to 'caution' after financial AI hacking
  2. Korea Policy Briefing — National cyber crisis alert raised to 'caution'
  3. KISA KrCERT — Cyber crisis alert raised from 'attention' to 'caution'
  4. Boan News — After the election, NIS lowers cyber alert from 'caution' to 'attention'
  5. Korea Policy Briefing — Government issues cyber crisis 'attention' alert

Verification

Published
Last modified
Cross-check
Checked against 5 independent sources.
Unverified
  • The national cyber crisis alert level as of October 7, 2026 was not confirmed from an NIS announcement.
  • That KISA monitoring stood at 'attention' before October 4 is based on some reports.
  • Detailed criteria for alert and serious levels are internal guidelines not confirmed from public text.
Authoring
Reviewed by a person before publication. The full process is described in the Editorial.

Ten stories, once each morning

We send the three-line summaries only; the full pieces stay on the site. One-click unsubscribe, any time.

Related