Qilin ransomware gang claims 1TB theft from SK Group's U.S. arm

Organization
SK Group
Exploit
Ransomware
Industry
Conglomerate

On April 10, 2025 the Qilin ransomware operation, also tracked as Agenda, listed South Korean conglomerate SK Group on its dark web leak site and claimed to have downloaded more than one terabyte of files from the company's servers. The post gave SK Group 48 hours to make contact before the data would be published and included no sample files as proof.

SK Group is South Korea's second-largest chaebol after Samsung, with more than 260 affiliates spanning semiconductors, energy, telecommunications, batteries and biopharmaceuticals. It employs over 80,000 people worldwide and reported roughly $91bn in revenue in 2024.

Korean reporting later established that the intrusion, which took place in late March, hit SK Americas, the group's North American coordination unit set up in 2024, and servers at its New York office rather than the wider group. SK Group said it reported the threat to U.S. authorities immediately and completed containment measures, and that the affected servers held no technology or customer information, so no critical data was leaked.

The 48-hour deadline passed without Qilin publishing any files, and no follow-on attack or further extortion demand was reported. The gang did add an image to its blog that appeared to show a video conference between SK executives and a U.S. official, which was never verified. Korean outlets reported that no connection had been established between the SK Americas attack and the separate SK Telecom USIM data breach disclosed around the same period.

Sources