Logo

Press Releases

[Security Column] Scraping, a New Cyber Threat Beyond Hacking and Phishing

2025.04.22

[Security Column] Scraping, a New Cyber Threat Beyond Hacking and Phishing

Scraping, which has been occurring frequently recently, is rapidly emerging as a major cyber threat alongside hacking and phishing. General programs called 'macros' that automatically collect and process info on web pages are also a type of scraping technology, and the two are essentially the same. When booking tickets for concerts or popular performances, these automated programs rob general consumers of purchase opportunities, leading to resale by scalpers at premium prices, deepening consumption inequality. Similar damage occurs in university course registrations and hospital appointments, leading to inequality in educational opportunities and decreased access to medical services. Unauthorized data scraping between companies is also a serious problem. The act of collecting a competitor's price info, product data, or user reviews without permission is not only an infringement of intellectual property rights but also leads to service quality degradation and additional costs due to overloading the target company's servers. In the financial and e-commerce industries, losses from such scraping are estimated to reach hundreds of billions of won annually. It was recently revealed that the National Tax Service's simplified refund service for individual taxpayers experienced connection delays due to scraping. Cases of AI companies indiscriminately scraping the web for learning data, infringing the rights of original authors or data-owning companies, are also surging. Furthermore, scraping is used as a new path for personal info leaks; info collected without permission from social media or job sites is highly likely to be misused for secondary crimes like targeted ads, spear phishing, or identity theft. Scraping technology continues to evolve. Moving beyond early simple HTML parsing, advanced techniques like headless browsers, proxy network bypassing, API request imitation, and AI-based CAPTCHA bypassing are being used. Modern scraping attacks neutralize existing security systems using browser fingerprinting bypass or distributed scraping networks, and it is concerning that such advanced scraping solutions are easily available as a service model on the dark web. Previously, methods like CAPTCHA, request limits, IP blocking, dynamic content loading, and behavioral pattern analysis were used for scraping prevention, but these had limitations as they had to be constantly updated to match rapidly evolving scraping tech. On the other hand, MTD (Moving Target Defense) technology, which fundamentally neutralizes an attacker's analysis by continuously changing the target environment, is a technology already verified through the domestic financial industry. This technology fundamentally blocks scraping tools from analyzing the environment or grasping patterns. Such a proactive defense system holds an advantage as it can block scraping and macros much more effectively than conventional methods while minimizing server load. However, technical defense alone cannot be a complete response. A shift in perception is needed to recognize that scraping is not just 'data collection' but can be a serious cybercrime. Currently, in Korea, scraping is often not clearly defined as an illegal act, and the level of punishment or intensity of crackdown is significantly lower compared to hacking or phishing. Scraping should now be recognized as a major cyber threat of the digital age. Technical countermeasures, legal and institutional improvements, and social awareness enhancement must occur simultaneously. As the value of data increases, establishing a comprehensive response strategy against the threat of scraping is urgent.

9-12th floor, 188 Noryangjin-ro, Dongjak-gu, Seoul

(+82) 02-2135-6239pr@everspin.co.kr

© 2026 Everspin Co., Ltd. All Rights Reserved.

Everspin white logo
Everspin Investors & IR - Growth Value of a Global AI Security Leader