Skip to content
safemode.space
All incidents
2021-06-15 (approximate)
cyber espionage
supply chain

North Korea-linked intrusion at Korea Aerospace Industries, the KSLV-2 stage developer (2021)

Confidence in this reading:
low

What happened

South Korea's National Intelligence Service briefed the parliamentary intelligence committee on 8 July 2021 that hackers linked to North Korea had accessed the network of Korea Aerospace Industries in mid-June 2021. The disclosure was made publicly by Rep. Ha Tae-keung of the People Power Party, a member of that committee. KAI's relevance to the space segment is specific: it built the propellant tank for the first stage of KSLV-2, South Korea's first indigenous space launch vehicle, and was responsible for assembling that stage, which was due for a demonstration launch from the Naro Space Center in October 2021. Independent reporting places the KAI breach in a sequence with the Korea Atomic Energy Research Institute in May and Daewoo Shipbuilding, traces attacker addresses to servers associated with the Kimsuky group, and lists KF-21 fighter, FA-50, unmanned aircraft and radar material among what was at risk. The NIS is reported to have warned KAI of possible breaches beforehand and urged precautions that the company did not take.

The evidentiary chain here is long and thin: a spy agency briefed a closed parliamentary committee, a member of that committee described the briefing publicly, and the press reported the description. No technical artefact and no vendor analysis is public, and both company statements the cited sources carry are brief: a KAI spokesperson confirmed the hack to SpaceNews and declined to elaborate, citing the ongoing investigation, and a KAI statement quoted by the Korea Times said only that the company had requested a police investigation into suspected cyberattacks and would fully cooperate with investigators. The Kimsuky attribution comes from a separate outlet, not from the NIS on the record. The record's overall confidence is low for that reason and not because the event is doubted. A second note on sourcing: the SpaceNews article SPARTA's bibliography cites was retrieved at its stored URL and read in full on 2026-08-21, and the Korea Times piece, which was read in full, carries the corroboration.

Attack vector

Not stated in any source read for this record.

Operational impact

None reported. No source states that the KSLV-2 programme, its schedule or its hardware was affected; the October 2021 demonstration launch proceeded.

Data compromised

Not established. The reporting states that the network holding confidential rocket propulsion technology was accessed, not that specific material was taken.

Affected segments

supply_chain, launch

Disclosed

2021-07-08

SPARTA techniques evidenced

Each row is a technique this record evidences, with the reasoning and the source that attests to it.

What relationship, confidence, and evidence mean on the rows below
Relationship

What kind of link this is between the technique and the target.

Mitigates: the target actively prevents, detects, or recovers from the technique.

Addresses: the target governs the technique or is relevant to it, without interdicting it. Most governance and policy obligations sit here.

Triggers obligation: the technique occurring is what triggers the duty the target imposes.

Relates to: related to the technique, but the target neither interdicts nor governs it. Used sparingly.

Confidence

How strongly the source supports this mapping, not how severe the technique is.

High: the source supports the mapping squarely.

Moderate: supported, with a qualification such as a cross-tactic reading that stays operationally sound.

Low: the source reaches the technique only in part.

Evidence

How close to the source text the mapping was made.

Direct: a verbatim excerpt of the cited source was read against the technique, and the rationale argues from that excerpt.

Derived: the mapping follows from the source's scope or structure, with no on-point excerpt addressing the technique.

Inferred: reached by composition through another framework, or by domain reasoning the source does not support on its face.

  • The reported objective is access to a network holding confidential propulsion technology for a launch vehicle whose first-stage propellant tank and stage assembly the victim owned. REC-0001 covers collection of the design picture including propulsion and the artefacts integrators hold, so the objective matches the technique. Two things hold the edge to low and derived: no source states that anything was taken, only that the network was accessed; and KSLV-2 is a launch vehicle, whereas REC-0001's subject is a spacecraft. REC-0004 (Gather Launch Information) is the launch-scoped technique, but its subject is launch windows, range operators and vehicle configuration, none of which any source describes being sought here. The gap is an editorial question, not a mapping this record settles.

    https://spacenews.com/north-korea-linked-hackers-accessed-souths-rocket-developer-spy-agency/

Considered and not mapped

These techniques were considered for this record because a source, a related record or SPARTA's own catalogue pointed at them. Each was read against what the sources say and not mapped. The reason is given in full.

  • No source states data was taken, and IMP-0006 in any case covers data a spacecraft gathers and sends, not ground-held design material.

  • SPARTA cites it. But REC-0008 is the adversary mapping manufacturers, lots, custody handoffs, signing services and promotion gates to find choke points. The sources describe an intrusion at one integrator, not reconnaissance of a chain. Being a supplier is not the same as being the object of supply-chain reconnaissance.

Sources

The published accounts this record rests on. The tier is SafeMode Space's own assessment of the source, and the reason for it is given beside it. What the tiers mean and how they are assigned: the source tiers.

A source is listed when a mapped technique rests on it, or when it disputes the account. One the curators read but neither cited nor recorded as disputing the record is not listed, so an absence here means neither is true rather than that nobody looked.

  • SpaceNews · Park Si-soo

    Tier 3: Space trade outlet with a named correspondent, relaying a parliamentary disclosure of a National Intelligence Service briefing. The underlying claim is a spy agency's, delivered through a legislator, and no technical artefact is published.

  • The Korea Times · Kang Seung-woo · 2021-07-01

    Tier 3: National English-language daily with a named reporter, covering the same parliamentary disclosure. Independent outlet, same underlying claim.

Every source SafeMode Space reproduces, and on what terms: sources and attribution.

Corpus 2026.08.24-1, built 2026-08-24 from 226 techniques, 308 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.