Netmarble

Netmarble

Netmarble, a leading South Korean game publisher, disclosed a data breach on its legacy PC gaming platform, exposing customer names, birth dates, and encrypted passwords. The incident drew sharp criticism from lawmakers, particularly Ruling Party lawmaker Choi Min-hee, for violating South Korea’s network law, which mandates reporting cybersecurity incidents within 24 hours. Netmarble delayed disclosure by three days, risking fines up to 30 million won (≈$22,500). The breach aligns with a rising trend of hacker-targeted companies in 2025, raising concerns over data privacy compliance and regulatory accountability. While the exposed data was limited to personal (non-financial) information, the delay exacerbated reputational damage and potential legal repercussions. The attack did not involve ransomware or financial theft but highlighted vulnerabilities in legacy systems, reinforcing the need for stricter incident response protocols in the gaming industry.

Source: https://www.mlex.com/mlex/data-privacy-security/articles/2416127/south-korean-gaming-giant-netmarble-faces-criticism-over-breach-disclosure-delay

Netmarble cybersecurity rating report: https://www.rankiteo.com/company/netmarble-games

"id": "NET2040020112725",
"linkid": "netmarble-games",
"type": "Breach",
"date": "6/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Gaming',
                        'location': 'South Korea',
                        'name': 'Netmarble',
                        'size': 'Large (one of South Korea’s biggest game '
                                'publishers)',
                        'type': 'Company'}],
 'data_breach': {'data_encryption': 'Passwords were encrypted',
                 'data_exfiltration': 'Likely (data exposed)',
                 'personally_identifiable_information': ['Names',
                                                         'Birth dates'],
                 'sensitivity_of_data': 'Moderate to High (names, birth dates, '
                                        'encrypted passwords)',
                 'type_of_data_compromised': ['Personal Information (PII)']},
 'date_publicly_disclosed': '2025-11-27',
 'description': 'Netmarble disclosed a data breach affecting its PC gaming '
                'platform, exposing customer names, birth dates, and encrypted '
                'passwords. The company faced criticism for delaying the '
                'report to regulators by three days, potentially violating '
                "South Korea's network law requiring incidents to be reported "
                'within 24 hours. The breach is part of a growing trend of '
                'cyberattacks targeting major companies this year.',
 'impact': {'brand_reputation_impact': 'Criticism from lawmakers and potential '
                                       'regulatory fines',
            'data_compromised': ['Customer names',
                                 'Birth dates',
                                 'Encrypted passwords'],
            'identity_theft_risk': 'Possible (due to exposed PII)',
            'legal_liabilities': "Potential violation of South Korea's network "
                                 'law (fines up to 30 million won)',
            'systems_affected': ['Legacy PC gaming platform']},
 'references': [{'date_accessed': '2025-11-27', 'source': 'MLex Insight'}],
 'regulatory_compliance': {'fines_imposed': 'Potential fines up to 30 million '
                                            'won',
                           'regulations_violated': ["South Korea's network law "
                                                    '(24-hour incident '
                                                    'reporting requirement)'],
                           'regulatory_notifications': 'Reported to regulators '
                                                       '(with a 3-day delay)'},
 'response': {'communication_strategy': 'Public disclosure (with delay)'},
 'title': 'Netmarble Data Breach Affecting Legacy PC Gaming Platform',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.