주메뉴바로가기본문바로가기
비즈한국 비즈한국

Emergency Check
The Current State of Security at 4 Major Online Bookstores Amidst Successive Hacking Attacks

This article was automatically translated by AI. There may be errors compared to the original Korean article.  Read original in Korean →

[비즈한국] The recent paralysis of Yes24053280 and a string of hacking incidents across major domestic bookstores and e-book platforms have heightened concerns regarding the industry's security capabilities. The vulnerability of security systems and the urgent need for improvements were already pointed out during the Aladin e-book leak incident in 2023.

Unlike the past, which was centered on offline services, the industry's reliance on digital systems has increased significantly due to the expansion of e-book distribution and online sales. At the same time, as cyber threats become more sophisticated and cloud/server environments grow more complex, coupled with blind spots in internal security, information security has emerged as both a foundation for technological operations and a key risk in corporate management. We examine the current state of information security systems in the bookstore industry.

As the nation’s largest online bookstore, Yes24, suffered a 'system paralysis' due to a ransomware attack, the security capabilities of the relevant industry have come under scrutiny. The photo shows the Yes24 headquarters in Yeongdeungpo-gu, Seoul, on the morning of the 16th. Photo=Reporter Park Jung-hoon
As the nation’s largest online bookstore, Yes24, suffered a 'system paralysis' due to a ransomware attack, the security capabilities of the relevant industry have come under scrutiny. The photo shows the Yes24 headquarters in Yeongdeungpo-gu, Seoul, on the morning of the 16th. Photo=Reporter Park Jung-hoon

Yes24 recently experienced a five-day service outage due to a ransomware attack. With online services—including website and app access, e-book downloads, and ticket reservations—shut down, and disruptions even affecting book searches and payments at offline stores, the company's technical infrastructure and security response capabilities have been called into question. While the situation has entered a resolution phase as the company announced primary and secondary compensation plans, including 5,000 won vouchers for all members, this incident—coming just two years after Aladin’s massive e-book leak—has raised fundamental questions about the security systems within the industry.

BizHankook queried four major domestic bookstore and e-book platform companies regarding their information protection status, based on criteria such as revenue, corporate size, and market share. While Kyobo Book Centre, Yes24, Aladin, and Ridibooks all stated that they are increasing investments in information protection to bolster security, they exhibited different approaches to the structure of their security organizations and the management of their CISOs (Chief Information Security Officers).

Dedicated Information Protection Organizations: Only Kyobo Book Centre and Yes24

Among the four companies—Kyobo Book Centre, Yes24, Aladin, and Ridibooks—only Kyobo Book Centre and Yes24 maintain separate departments for information protection. Kyobo Book Centre formed an information security team in 2015 and has since expanded it into an Information Security Office. Yes24 stated that it has a dedicated information protection department separate from system operations, but the exact organizational structure could not be verified. Conversely, it was found that neither Aladin nor Ridibooks operate independent information security departments.

Key indicators for gauging information security capability include the status of dedicated personnel, the scale of investment, the designation and operation of a CISO, and relevant certifications. These serve as essential indicators that objectively demonstrate information security management and operational capabilities, and are also required for companies subject to information security disclosure laws.

While all four companies have designated a CISO to oversee information protection, the practice of concurrent job holding varies. Ridibooks operates its CISO directly under the Chief Technology Officer (CTO) to handle security tasks. Although they appear not to have a separate organizational department, the company explains that it operates an information protection system, including the establishment and execution of internal security policies, centered on a dedicated security professional who does not hold other concurrent roles. Ridibooks stated, "We have deployed specialized personnel to handle related tasks and, when necessary, collaborate with external professional organizations."

Considering the information security organization and CISO operations as a whole, Kyobo Book Centre appears to have the most systematic structure in terms of security and personnel. Kyobo Book Centre's CISO is held by the head of the Information Security Office, a system that relatively secures the independence and professionalism of security policies.

According to the Korea Internet & Security Agency (KISA) information protection disclosure portal, Yes24’s CISO also serves as the CPO (Chief Privacy Officer). As a listed company meeting revenue requirements, Yes24 is the only one among the four with a legal obligation to disclose information protection status. While the integration of CISO and CPO roles is common even in large corporations due to the perceived similarity of the functions, it is also criticized as a strategy prioritized for efficiency, which can lead to side effects such as unclear lines of responsibility.

Whether a CISO holds concurrent roles is one of the practical indicators of a company's security competence. It is generally believed that if the role is held concurrently with other positions, it may limit the ability to allocate sufficient resources to information protection, thereby creating limitations in establishing security policies, managing risks, and implementing controls. This is why some information and communication companies above a certain size (e.g., total assets of 5 trillion won) are prohibited from having internal CISOs hold concurrent roles. However, Yes24 does not fall under this prohibition.

Aladin stated that it carries out security tasks through a shared structure involving a development team responsible for web infrastructure and an internal audit organization. The development team handles technical operations, while the audit organization manages security policies, regulations, and internal controls. The CISO role is held concurrently by an internal director.

Among the four companies, Kyobo Book Centre and Ridibooks have obtained the Information Security Management System (ISMS-P) certification, while Yes24 holds the ISMS-P certification (which integrates information security and personal information protection). For Aladin, the only certification status visible on the KISA website expired in November 2023, indicating it has not yet been renewed. ISMS is a comprehensive certification system that integrates personal information protection requirements into the ISMS framework established and operated by organizations to securely protect their information assets.

Proposal for a Consultative Body Fails… Lack of Cooperation Increases Cyber Risk

All four companies emphasized that they are expanding their investments in information protection. However, only Kyobo Book Centre and Yes24 provided specific figures for their annual information protection investment proportions or actual amounts. According to Kyobo Book Centre, the ratio of information protection investment to total IT investment is 6.7% this year, a 1.7 percentage point increase from the previous year (5.0%). According to Yes24's information protection disclosure, the investment amount for information protection last year was approximately 1.269 billion won, which was 9.2% of its total IT investment. The three-year trend for their information protection investment was: 1.103 billion won in 2022 (9.2% of IT investment) and 947 million won in 2023 (5.1%).

An Aladin official stated, "It is difficult to disclose specific investment amounts or proportions, but we have been fully committed to security investment over the past three years and have been allocating a large budget." A Ridibooks official also said, "As the importance and sense of responsibility for information security grow, we are continuously expanding the scale of our investment. A budget for strengthening our security systems has also been allocated for the second half of this year."

There was also an opinion from an industry insider that "it is difficult to disclose related figures because it is not always clear whether the budget is for information protection or general IT infrastructure costs." Given that disclosure is legally required for companies subject to information protection reporting, this reveals that the maturity of information security response systems in the publishing and bookstore industry varies significantly by company and has yet to be standardized.

The bookstore industry is carrying out various security activities, such as technical measures and raising internal awareness. Photo=Pixabay
The bookstore industry is carrying out various security activities, such as technical measures and raising internal awareness. Photo=Pixabay
This article was automatically translated by AI. There may be errors compared to the original Korean article.
긴급점검
  • [Emergency Check] The Current State of Security at 4 Major Online Bookstores Amidst Successive Hacking Attacks
    [Emergency Check] The Current State of Security at 4 Major Online Bookstores Amidst Successive Hacking Attacks
강은경 기자

기술과 산업을 취재하고 씁니다.

gong@bizhankook.com
저작권자 ⓒ 비즈한국 무단전재 및 재배포 금지