
23.09.2026 containmentmsp-securityransomwaresupply-chainincident-response
In September 2025, the operators behind Qilin didn’t need 32 separate break-ins to take down 32 South Korean financial firms. They needed exactly one: South Korean managed service provider GJTec. On September 23, 2025, the Korea JoongAng Daily reported that more than 20 asset management companies in the country were infected with ransomware following the compromise of GJTec. By the end of the campaign, dubbed “Korean Leaks,” between 28 and 32 organizations had been hit. By gaining access to a single managed service provider, GJTec, Qilin used its standing privileged credentials to move laterally into 32 South Korean financial institutions without breaching each independently. Over a million files and more than two terabytes of data were exfiltrated.
For IR teams, this isn’t an exotic edge case — it’s a stress test for a containment model most organizations still build around single-victim incidents.
Traditional containment playbooks assume an attacker moving inside a network you monitor and control. In Korean Leaks, that control point didn’t sit with the victims — it sat with the service provider. To pull off these attacks, the Qilin affiliate is said to have breached a single upstream managed service provider (MSP), leveraging the access to compromise several victims at once. Bitdefender called this a critical blind spot: “Exploiting a vendor, contractor, or MSP that has access to other businesses is a more prevalent and practical route that RaaS groups seeking clustered victims can take.”
What makes this particularly bitter is that none of the victims had a realistic chance to catch it before impact. The GJTec compromise was not detected by any of the 28 victim financial institutions before ransomware payloads detonated — it was detected only after data appeared on Qilin’s leak site. A containment playbook built on your own telemetry is powerless when the point of compromise sits outside your visibility entirely.
The latest Unit 42 report confirms this is no longer a niche pattern: software supply chain risk has expanded beyond vulnerable code to the misuse of trusted connectivity, with attackers exploiting SaaS integrations, vendor tools and application dependencies to bypass perimeters at scale.
Three structural gaps explain why standard playbooks fail here — and where IR teams should focus now:
No segmentation of standing access. MSP standing privileged access needs to be treated as its own high-criticality attack surface, with just-in-time elevation replacing permanent administrative rights that can be revoked in bulk during an incident.
No shared kill switch. A containment playbook for MSP relationships needs contractually defined, technically pre-built emergency mechanisms: who has the authority to cut MSP access to all client networks simultaneously, and how fast can that actually be executed?
No rehearsed communication chain. When an attack routes through a shared provider, notification obligations don’t stop at your own organization — they potentially involve dozens of simultaneously affected peers with no established channel between them. Tabletop exercises should explicitly rehearse this scenario: not “how do we respond to an incident,” but “how do we respond when twenty other organizations hit the same wall at the same moment, through a provider none of us controls.”
Frameworks like NIS2 and sector-specific rules increasingly demand credible third-party risk management. In practice, that often amounts to nothing: these controls are frequently implemented as checkbox exercises: a vendor questionnaire submitted once during onboarding, with no mechanism to verify the vendor’s actual security posture or detect a breach on the vendor’s side.
Korean Leaks shows exactly where that leads: a security architecture built on self-attestation instead of continuous monitoring and pre-built containment mechanisms is useless the moment it’s tested. IR teams that have only addressed MSP relationships contractually — not operationally, inside their containment playbooks — should treat this as a wake-up call, not a regional anomaly.
← Back to overview