OAK — OnChain Attack Knowledge

Worked example · 2017-06

Bithumb employee-laptop compromise + downstream phishing wave — multi-asset / Korean exchange — 2017-06 to 2017-09

Loss
approximately $1M+ across the chained operation, with the bulk of attributable user loss occurring in the downstream targeted-phishing / customer-account-drain wave that followed the upstream customer-data exfiltration. Bithumb publicly disclosed the breach 2017-06-29 / 2017-06-30 and acknowledged that personal data — names, mobile-phone numbers, and email addresses — for an estimated ~31,800 customers (~3% of the user base, per the South Korean regulator's later finding) had been exfiltrated. Subsequent customer reports and Korean press coverage attributed direct user losses across multiple verified incidents — high-value individual victims included one user reporting ~₩1.2B (~$1M+ at the time) lost from their Bithumb account through a chained social-engineering / SMS-spoofing / two-factor bypass operation. Korea's Personal Information Protection Commission (PIPC) ultimately fined Bithumb ₩60M (~$55,000 at the time) for the data-protection failure underneath the breach.
OAK Techniques observed
OAK-T11.002 broadly construed (custody-adjacent host compromise — employee endpoint with access to customer-data systems) for the upstream exfiltration, plus T4-class downstream techniques (targeted phishing → customer-account drain) for the second-stage operation that monetised the exfiltrated data. OAK-T15.003 (Operator-Endpoint Compromise) — the canonical pre-2020 anchor for the employee-laptop-with-non-signing-data sub-shape: the load-bearing endpoint state was a Bithumb employee laptop whose privileged access reached the customer-data database; the case anchors the earliest documented T15.003 sub-shape in OAK at v0.1 and is the active-since marker for T15 (Bithumb 2017-06).
Attribution
inferred-strong — South Korean intelligence (NIS) and subsequent US Treasury / Justice attributions to North Korean state-aligned actors covered the post-2017 wave of South Korean exchange compromises (Bithumb 2017, Coinrail 2018, Bithumb 2018, Upbit 2019), and the cohort is consistently attributed in industry reporting (Chainalysis, Recorded Future, FireEye / Mandiant) to OAK-G01 / Lazarus and its sub-clusters. No DOJ indictment names the Bithumb 2017 case specifically at the OAK v0.1 cutoff.
OAK-Gnn
OAK-G01 Lazarus Group / DPRK-attributed.
Key teaching point
customer-data breach + downstream targeted-phishing-driven account drain is a chain pattern, not two independent events. The T4-class extraction depended on the T11-class custodial-data exfiltration upstream — the phishing was effective precisely because the actor had names, phone numbers, and email addresses for the targeted Bithumb customers, with knowledge of which addresses were active Bithumb users. Defenders who classify customer-data breaches as "data-protection events" rather than "pre-positioning for targeted phishing" mis-price the operational risk.

Summary

Bithumb, headquartered in Seoul, was at the time of the event one of the largest cryptocurrency exchanges in South Korea and globally — at peak handling on the order of ~10% of global bitcoin trading volume in mid-2017. On 2017-06-29 / 2017-06-30 Bithumb publicly disclosed that an employee's personal computer had been compromised, that the compromise had produced unauthorised access to a customer-information database held on the affected machine, and that personally-identifying information for an estimated ~31,800 Bithumb customers had been exfiltrated. The compromised data included names, mobile-phone numbers, and email addresses; per Bithumb's contemporaneous statement, it did not include passwords, private keys, or direct withdrawal-authority credentials.

In the weeks that followed the disclosure, Bithumb customers began reporting a coordinated wave of targeted phishing operations: phone calls and SMS messages from actors who possessed the victims' names and Bithumb-account-related contact information, who could pass plausibility checks ("you have this account on Bithumb, your name is X, your phone number is Y") and who walked victims through chained credential-elicitation, SMS-spoofing-driven two-factor bypass, and account drains. The largest publicly-reported individual loss was approximately ₩1.2B (~$1M+ at the time) from a single Bithumb customer; multiple smaller losses across the affected user population accumulated through 2017-07 to 2017-09. Class-action litigation in Korea followed, with mixed first-instance outcomes and partial damages awards over the following years.

For OAK's purposes the Bithumb 2017 case is the foundational worked example of the chain pattern — upstream custodial-data exfiltration providing targeting feedstock for a downstream targeted-phishing-driven account-drain operation. The two halves are operationally distinct (different OAK Tactic classes, different attacker tradecraft, different defender control surfaces) but causally inseparable: the downstream phishing wave was effective precisely because the upstream exfiltration provided the actor with verified-active Bithumb-customer contact records. Contributors writing future T4-class (targeted-phishing) or T11.002-class (custody-adjacent host compromise) Technique pages should treat Bithumb 2017 as the canonical chained-operation reference and the foundational case for the South Korean exchange-incident cohort that runs through Coinrail 2018, Bithumb 2018, and Upbit 2019.

Timeline (UTC unless noted)

When Event OAK ref
Pre-event (2017-04 to 2017-06) Employee-laptop compromise at Bithumb; the affected endpoint held a copy of a customer-information database. The exact entry vector (phishing-led malware delivery is the candidate vector per contemporaneous Korean reporting) was not publicly disclosed in technical detail T11.002-broadly-construed entry — employee endpoint with access to customer-data systems
2017-06 Customer PII for ~31,800 users (names, mobile-phone numbers, email addresses) exfiltrated from the compromised endpoint Upstream exfiltration — targeting feedstock for downstream phishing
2017-06-29 / 2017-06-30 Bithumb publicly discloses the breach; statement specifies that no passwords or private keys were affected (operator disclosure)
2017-07 onward Targeted phishing wave begins against affected Bithumb customers; phone-call and SMS-based social-engineering operations pass plausibility checks using the exfiltrated PII; SMS-spoofing-driven 2FA bypass operations chain with credential elicitation T4-class downstream — targeted phishing → customer account drain
2017-07 to 2017-09 Multiple individual customer losses publicly reported; largest single reported loss ₩1.2B ($1M+) (sustained extraction wave)
2017-09 onward Korean Communications Commission (KCC) and Personal Information Protection Commission investigation initiated (regulatory response)
2018-01 KCC fines Bithumb ₩60M (~$55,000 at the time) for the personal-information protection failure underneath the breach Regulatory enforcement
2018 onward Class-action litigation by affected customers in Korean courts; partial damages awards in subsequent first-instance and appellate proceedings (civil litigation)
2019 onward Subsequent industry attribution (Chainalysis, Recorded Future, FireEye / Mandiant) and South Korean NIS attribution of the 2017–2019 South Korean exchange-incident cohort to North Korean state-aligned actors G01 attribution — inferred-strong

What defenders observed and learned

  • Pre-event: the compromised asset was an employee laptop holding a copy of the customer-information database, not a properly-segregated production database with access controls. The structural failure under the headline incident is that customer PII at exchange scale (~31,800 records) was reachable from a single employee endpoint at all. A defender writing an exchange operations runbook should treat "customer-information database accessible from any single employee endpoint" as a primary control to fix; the post-2018 industry baseline of segregated production-data access via just-in-time / break-glass workflows is retro-engineered against precisely this failure shape.
  • At-event: detection happened after the exfiltration — there is no public-record indication that the upstream compromise was caught by an endpoint-side detection capability or by anomaly-detection on customer-data egress. The defender lesson is that customer-data egress monitoring (volume, destination, time-of-day) is its own control class, and that the lack of it allowed the exfiltration to complete unobserved.
  • Post-event (chain side): the downstream phishing wave's effectiveness was a direct function of the quality of the targeting feedstock. Generic phishing produces low yield; phishing armed with verified-active contact records and account-context plausibility produces high yield. The Bithumb chain is the cleanest historical illustration that a "data-protection event" should be classified operationally as "pre-positioning for targeted phishing" — and that a defender posture which treats those as separate categories systematically under-prices the operational risk of the upstream exfiltration.
  • Post-event (regulatory side): the ₩60M fine is structurally trivial against the customer-loss magnitude. The Korean regulatory response in 2018 was retro-fit against a pre-cryptocurrency data-protection statutory regime; the post-2020 South Korean exchange-regulatory framework (Special Financial Information Act amendments effective 2021) was driven, in significant part, by the inadequacy demonstrated in this case. Contributors writing regulatory-context pages should treat Bithumb 2017 as the case that catalysed the post-2020 South Korean exchange-licensing regime.

What this example tells contributors writing future Technique pages

  • The chain pattern (upstream T11-class data exfiltration → downstream T4-class targeted-phishing account drain) is its own analytic shape and should be documented as such. Most OAK worked examples treat a single-event compromise; Bithumb 2017 is one of the cleanest available illustrations that the chain is the meaningful unit, not the upstream or downstream events in isolation. Contributors writing T4-class Technique pages should reference Bithumb 2017 as the canonical case for "phishing armed with verified-active customer contact records is operationally distinct from generic phishing"; contributors writing T11.002-class pages should reference it as "customer-data exfiltration is targeting feedstock for downstream T4 operations, not a discrete data-protection event."
  • Bithumb 2017 is the foundational case for the South Korean exchange-incident cohort. The 2017–2019 cohort — Bithumb 2017, Coinrail 2018-06, Bithumb 2018-06, Upbit 2019-11 — is consistently attributed to OAK-G01-aligned actors and forms a tight operational cluster. Contributors writing G01 pages or Korean-jurisdiction worked examples should treat Bithumb 2017 as the chronological anchor for the cohort and avoid framings that imply the cohort begins later.
  • inferred-strong attribution is the right marker. No DOJ indictment names the Bithumb 2017 case specifically at the OAK v0.1 cutoff; the attribution rests on South Korean NIS findings and the industry-forensic corroboration from Chainalysis, Recorded Future, and FireEye / Mandiant. By OAK convention this is inferred-strong, not confirmed. The same attribution-surface pattern recurs across the Korean cohort and across pre-2022 G01 cases generally — contributors writing other G01-attributed events from this period should expect industry-forensic attribution without DOJ / Treasury naming.
  • The PIPC / KCC fine magnitude is itself a documentation signal. A regulatory fine that is orders of magnitude smaller than the user-loss magnitude is a structural feature of the pre-2020 South Korean enforcement regime, not a defender mitigation. Contributors writing regulatory-context analysis should distinguish "fine imposed" from "deterrent effect" and not present small-fine outcomes as evidence of effective enforcement.

Public references

  • [bithumbpress2017] — Bithumb Co. Customer-Information Leakage Notice and Apology. 2017-06-30 / 2017-07-04 announcements; primary-source operator disclosure of the breach.
  • [koreaheraldbithumb2017]Korea Herald. Bithumb hack victims demand compensation. 2017-07; contemporaneous Korean press coverage of the breach disclosure and customer-loss reports.
  • [koreatimesbithumb2017]Korea Times. Bithumb under fire after hack of customer data. 2017-07; second-source contemporaneous coverage.
  • [kccbithumbfine2018] — Korea Communications Commission. Administrative penalty against Bithumb for personal-information protection failure. 2018-01; primary-source regulatory disposition.
  • [chainalysisdprkkorea2019] — Chainalysis cumulative analysis of DPRK-attributed activity targeting South Korean exchanges across the 2017–2019 cohort.
  • [recordedfuturedprkfinancial2018] — Recorded Future. North Korea Targeting of South Korean cryptocurrency exchanges and adjacent infrastructure. 2018; industry-forensic attribution covering the cohort.
  • [mandiantdprkfinancial2019] — FireEye / Mandiant analysis of DPRK-attributed financial-sector targeting including the South Korean exchange-incident cohort.

Discussion

Bithumb 2017 is the OAK record's foundational chained-operation worked example. The case demonstrates, at exchange scale and in primary-source detail, that an upstream customer-data exfiltration and a downstream targeted-phishing wave are not two independent incidents but a single chained operation in which the downstream extraction's effectiveness is a direct function of the upstream exfiltration's targeting feedstock. Contributors writing future T4-class or T11.002-class Technique pages should treat the chained-operation framing as the structural unit and Bithumb 2017 as the canonical illustration.

The South Korean cohort context matters for OAK's attribution discipline. The 2017–2019 cohort — Bithumb 2017, Coinrail 2018-06, Bithumb 2018-06, Upbit 2019-11 — is consistently attributed by South Korean NIS and the industry-forensic record to OAK-G01-aligned actors. The cohort sits at the historical inflection point between the pre-DPRK-attribution exchange-hack record (Mt. Gox 2011–2014, Bitstamp 2015, Bitfinex 2016) and the post-2018 DPRK-dominated record. Bithumb 2017 is the chronological anchor for the inflection, and contributors writing actor-axis material should preserve the cohort framing rather than treating each Korean exchange incident in isolation. The operational specifics differ across the cohort (data exfiltration in 2017, hot-wallet drain in Coinrail 2018, hot-wallet drain in Bithumb 2018, hot-wallet drain in Upbit 2019), but the actor-cluster framing is the same and the cumulative South-Korea-targeting pattern is the load-bearing context.

The regulatory-response side of the case is structurally instructive in its own right. The ₩60M (~$55,000) PIPC fine is orders of magnitude smaller than the cumulative customer-loss magnitude, and that disproportion is the single clearest illustration in the OAK record of why pre-2020 personal-information-protection statutory regimes were inadequate to the operational risk that exchange-scale custodial-data breaches actually carry. The post-2020 South Korean exchange-regulatory framework (Special Financial Information Act amendments effective 2021) was driven, in significant part, by the inadequacy this case demonstrated. Contributors writing regulatory-context pages — particularly any pages that compare jurisdiction-of-incorporation choices for exchanges or custodians — should treat Bithumb 2017 as the canonical case for the inadequacy-of-pre-2020-regime point, with the post-2021 South Korean licensing regime as the response.

Finally, the Bithumb 2017 case is operationally distinct from the direct hot-wallet drain exchange compromises that surround it in the OAK record (Bitstamp 2015, NiceHash 2017, Coincheck 2018, Bithumb 2018, Coinrail 2018). The load-bearing extracted asset in 2017 was customer PII, used as targeting feedstock for the downstream phishing wave; the load-bearing extracted asset in the surrounding cases was custody key material producing direct hot-wallet drain. The two shapes coexist in the actor cohort's tradecraft and contributors should not collapse them into a single category. The correct framing is that the OAK-G01 cohort's South-Korea-targeting pattern in this period included both chained-operation customer-data-into-phishing operations (Bithumb 2017) and direct hot-wallet compromises (Coinrail 2018, Bithumb 2018, Upbit 2019); both shapes are represented in the cohort and both should be documented as part of the actor-cluster's tradecraft surface.

Techniques demonstrated (2)