Skip to main content
Back to overview
High

South Korean Domain Registrar Gabia Hacked, Exposing 350,000 User Records

South Korean domain registrar Gabia experienced a cyberattack on Saturday, July 26, 2026, which impacted the online connectivity of approximately 100,000 registered domains.

Key points

  • Gabia, a South Korean domain registrar, was hacked on July 26, 2026.
  • The attack affected the online connection of 100,000 registered domains.
  • Data of 350,000 users was exposed, including names, user IDs, passwords, and registration numbers.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Internal actor · Malware · Confidentiality impact

Malware, Hacking activity

03

Potential impact

Potential extortion or operational risk

Confidentiality

Published
Jul 26, 2026
Updated
Jul 28, 2026
Confidence
High
Evidence
2 sources

Structured assessment

Signal analysis

It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Malware, Hacking activity

Watch ransomware, endpoint compromise and business interruption exposure.

  • Source type: possible insider or internal misuse

Business impact

Potential extortion or operational risk
Impact area
Confidentiality
Likely asset
User or customer data

Mentioned entities

GabiaData DisclosureSouth Korean Domain Registrar GabiaHackedExposingGabiaSaturdayIDsCombolistAdditionally

Quick context

Questions about this signal

What happened in this signal?

South Korean domain registrar Gabia experienced a cyberattack on Saturday, July 26, 2026, which impacted the online connectivity of approximately 100,000 registered domains. The incident led to the exposure of data belonging to 350,000 users. The compromised information included names, user IDs, passwords, and registration numbers. This breach highlights the significant risks associated with compromised credential reuse, as a large portion of the exposure originated from "Combolist sources." Additionally, active infostealer activity, linked to malware families such as LummaC2, Redline, and Rhadamanthys, was identified, further indicating a focus on credential theft impacting both clients and employees. The incident also revealed 245 compromised employee accounts, posing an infrastructure risk, and 30,782 leaked client credentials, creating regulatory liability. The timeline of related events showed an increase in client-related incidents from August 2025 through April 2026, with a peak in March 2026, and spikes in employee-related events in January, April, and May 2026. Remediation efforts should prioritize credential hygiene, multi-factor authentication enforcement, and enhanced monitoring for suspicious login activity, particularly targeting login forms and account management services. The incident was reported by the Korea Herald on Monday, July 28, 2026.

When was this signal reported?

Shadow Tier lists Jul 26, 2026 as the signal date.

Which organization is connected to this signal?

Gabia is the organization connected to this public signal.

Explore Gabia