Ransomware attack takes South Korean ticketing platform Yes24 offline

Organization
Yes24
Exploit
Ransomware
Industry
E-commerce & Ticketing

Yes24, the South Korean online bookseller and event ticketing platform, was taken offline by a ransomware attack that began in the early hours of Monday, June 9, 2025. The company serves more than 20 million registered users and reported 2024 revenue of about 671.4 billion won, roughly $494 million.

The lockout disabled ticketing, e-book access and community forums for several days. Concert presales, fan meetings and stage performances were postponed or cancelled, affecting events tied to the actor Park Bo-gum and the acts Enhypen, Ateez and B.I. Producers of musicals including The Bridges of Madison County and Aladdin asked audiences to bring printed or emailed reservation confirmations, and some ticket holders were turned away earlier in the week.

Yes24 said it had regained control of an administrator account by midweek and aimed to restore full service no later than Sunday, June 15. It initially said no external leak of personal information had been confirmed, then said it would notify individuals if further investigation established otherwise, and reported suspicious activity involving customer data to authorities.

South Korea's Personal Information Protection Commission opened an investigation into whether customer data was exposed and whether Yes24 met its obligations under national privacy law. The National Police Agency made preliminary inquiries. No ransomware group was publicly identified.

Sources