Personal Information Protection Commission and Ministry of Foreign Affairs: Growing number of gov't organizations hit by personal info leak: report

Personal Information Protection Commission and Ministry of Foreign Affairs: Growing number of gov't organizations hit by personal info leak: report

South Korean Public Institutions Face Rising Data Leaks, Majority Due to Negligence

South Korea’s public sector has seen a sharp increase in personal data leaks, with 164 government institutions affected in the first half of 2024 already surpassing last year’s total of 128. According to a report by Rep. Song Eon-seok of the People Power Party, based on data from the Personal Information Protection Commission (PIPC), the number of breaches has risen steadily since 2021, when just 22 cases were recorded.

Between 2022 and mid-2024, the PIPC handled 139 breach cases, with 67.6% (94 incidents) attributed to employee negligence. Hackers caused 44 leaks, while one case involved deliberate data exposure. The breaches compromised an average of 7.84 records per incident, including sensitive details such as names, contact information, resident registration numbers, bank accounts, and health data.

A notable incident last month involved a government-run online education system, which exposed the personal data of all South Korean diplomats approximately 10,000 records. The Ministry of Foreign Affairs shut down the system in February after detecting the breach. The trend highlights persistent vulnerabilities in public-sector cybersecurity, with human error remaining the leading cause of exposure.

Source: https://www.koreaherald.com/article/10842745

Personal Information Protection Commission(PIPC), Republic of Korea cybersecurity rating report: https://www.rankiteo.com/company/personal-information-protection-commission-pipc-republic-of-korea

The Ministry of Economy and Finance of the Republic of Korea cybersecurity rating report: https://www.rankiteo.com/company/the-ministry-of-economy-and-finance-of-the-republic-of-korea

"id": "PERTHE1786868980",
"linkid": "personal-information-protection-commission-pipc-republic-of-korea, the-ministry-of-economy-and-finance-of-the-republic-of-korea",
"type": "Breach",
"date": "1/2026",
"severity": "60",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'customers_affected': '10,000+ (diplomats and other '
                                              'individuals)',
                        'industry': 'Government',
                        'location': 'South Korea',
                        'name': 'South Korean government institutions',
                        'size': 'Large',
                        'type': 'Public Sector'}],
 'attack_vector': ['Employee Negligence', 'Hacking'],
 'data_breach': {'number_of_records_exposed': '7.84 records per incident '
                                              '(average), 10,000 records in '
                                              'one notable case',
                 'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Names',
                                              'Contact Information',
                                              'Resident Registration Numbers',
                                              'Bank Accounts',
                                              'Health Data']},
 'date_detected': '2024-02',
 'date_publicly_disclosed': '2024',
 'description': 'South Korea’s public sector has seen a sharp increase in '
                'personal data leaks, with 164 government institutions '
                'affected in the first half of 2024. The majority of breaches '
                '(67.6%) were attributed to employee negligence, compromising '
                'sensitive details such as names, contact information, '
                'resident registration numbers, bank accounts, and health '
                'data.',
 'impact': {'brand_reputation_impact': 'High',
            'data_compromised': 'Personal and sensitive data (names, contact '
                                'information, resident registration numbers, '
                                'bank accounts, health data)',
            'identity_theft_risk': 'High',
            'operational_impact': 'System shutdown (Ministry of Foreign '
                                  'Affairs online education system)',
            'payment_information_risk': 'High',
            'systems_affected': ['Government-run online education system']},
 'lessons_learned': 'Human error remains the leading cause of data breaches in '
                    'the public sector; persistent vulnerabilities in '
                    'cybersecurity need addressing.',
 'motivation': ['Negligence', 'Malicious Intent'],
 'post_incident_analysis': {'root_causes': ['Employee negligence',
                                            'Inadequate cybersecurity '
                                            'measures']},
 'references': [{'source': 'Rep. Song Eon-seok (People Power Party) / Personal '
                           'Information Protection Commission (PIPC)'}],
 'response': {'containment_measures': 'System shutdown'},
 'threat_actor': ['Insider (Negligent)', 'Hackers'],
 'title': 'South Korean Public Institutions Face Rising Data Leaks Due to '
          'Negligence',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.