GitHub: BOK faces scrutiny over cybersecurity after staff data breach

GitHub: BOK faces scrutiny over cybersecurity after staff data breach

Bank of Korea Faces Cybersecurity Scrutiny After Employee Data Breach

The Bank of Korea (BOK) is under investigation following a cybersecurity breach that exposed the personal data of 186 employees. The incident, which occurred between May and June, stemmed from a hack of a GitHub system managed by a contractor for the bank’s online training program.

The leaked information included employees' names, email addresses, phone numbers, job titles, duties, and passwords. The BOK was notified of the breach by the contractor on June 11 and informed affected staff the next day, later reporting the incident to the Personal Information Protection Commission.

Opposition lawmaker Rep. Lee Jong-wook of the People Power Party (PPP) criticized the central bank for not taking the breach and repeated website disruptions seriously, urging a thorough review of its security systems to prevent future incidents.

Hacking attempts against the BOK have surged this year, with 135 cases detected in the first eight months 4.5 times the total recorded in 2023. Between 2021 and August 2024, the bank logged 2,063 hacking attempts, with unauthorized access (1,951 cases) and malware (95 cases) being the most common attack vectors. The majority of attacks (2,024) originated from overseas, primarily targeting the BOK’s public website, statistics portal, and electronic library.

The BOK noted that security improvements, including a 2022 migration to a cloud-based email server and stricter login protocols, contributed to a decline in detected attacks in recent years. However, the recent spike in incidents has raised concerns about the bank’s cybersecurity resilience.

Source: https://www.koreatimes.co.kr/business/banking-finance/20260928/bok-faces-scrutiny-over-cybersecurity-after-staff-data-breach

GitHub cybersecurity rating report: https://www.rankiteo.com/company/github

"id": "GIT1790576967",
"linkid": "github",
"type": "Breach",
"date": "5/2026",
"severity": "60",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'customers_affected': '186 employees',
                        'industry': 'Financial Services',
                        'location': 'South Korea',
                        'name': 'Bank of Korea',
                        'type': 'Central Bank'}],
 'attack_vector': 'Unauthorized Access (GitHub system hack)',
 'data_breach': {'number_of_records_exposed': '186',
                 'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'High (Personally Identifiable '
                                        'Information and passwords)',
                 'type_of_data_compromised': ['Names',
                                              'Email addresses',
                                              'Phone numbers',
                                              'Job titles',
                                              'Duties',
                                              'Passwords']},
 'date_detected': '2024-06-11',
 'date_publicly_disclosed': '2024-06-12',
 'description': 'The Bank of Korea (BOK) experienced a cybersecurity breach '
                'that exposed the personal data of 186 employees. The incident '
                'occurred between May and June due to a hack of a GitHub '
                'system managed by a contractor for the bank’s online training '
                'program. The leaked information included names, email '
                'addresses, phone numbers, job titles, duties, and passwords.',
 'impact': {'brand_reputation_impact': 'Criticism from lawmakers and public '
                                       'scrutiny',
            'data_compromised': 'Personal data of 186 employees',
            'identity_theft_risk': 'High (exposed PII and passwords)',
            'systems_affected': 'GitHub system (contractor-managed online '
                                'training program)'},
 'investigation_status': 'Under investigation',
 'post_incident_analysis': {'corrective_actions': 'Security improvements '
                                                  'including cloud-based email '
                                                  'server migration and '
                                                  'stricter login protocols',
                            'root_causes': 'Hack of a GitHub system managed by '
                                           'a contractor'},
 'recommendations': 'Thorough review of security systems to prevent future '
                    'incidents',
 'references': [{'source': 'Opposition lawmaker Rep. Lee Jong-wook (People '
                           'Power Party)'}],
 'regulatory_compliance': {'regulatory_notifications': 'Reported to the '
                                                       'Personal Information '
                                                       'Protection Commission'},
 'response': {'communication_strategy': 'Informed affected staff and reported '
                                        'to the Personal Information '
                                        'Protection Commission',
              'enhanced_monitoring': 'Security improvements including '
                                     'cloud-based email server migration and '
                                     'stricter login protocols'},
 'title': 'Bank of Korea Employee Data Breach',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.