Local Chorus
Local news from local sources, read in your language.
Settled

Over six years, penalised data leak cases involved 5.05 million resident numbers

🇰🇷 South Korea 10:27 IT & software Business2 Official updated 1 d ago first reported by 연합뉴스

In short

Personal data leak cases penalised by South Korea’s Personal Information Protection Commission and Financial Supervisory Service over the past six years involved more than 5.05 million resident registration numbers, according to figures reported on 5 October. Leaks of CI and DI — online identifiers used to link records across services — exceeded 2.78 million, with Yanolja, Modetour Network and Lotte Card the largest confirmed cases. Yonhap said three cases could not be sized because records or logs were missing.

Read the full story 1 min read

More than 5.05 million resident registration numbers were found to have leaked over the past six years in personal data leak cases penalised by the Personal Information Protection Commission and the Financial Supervisory Service, according to reports on 5 October. Yonhap, citing the compiled figures, said the confirmed leak total was 5,056,653 records after excluding three cases whose scale could not be determined. [ 1 , 2 , 3 ]

Yonhap listed the largest individual cases as Yanolja with 1,002,898 records, NHN WeToo with 524,620, Lotte Card with 452,313, Duo Information with 427,464 (encrypted) and LG Uplus with 297,117 (encrypted). [ 1 ]

CI (linking information) and DI (duplicate-registration confirmation information), described in the coverage as the equivalent of an online resident registration number, leaked in four cases, with the confirmed total at 2,787,673 records: Yanolja (DI) 1,002,898, Modetour Network (CI and DI) 948,393 and Lotte Card (CI) 836,382, Yonhap reported. Chosun Ilbo put the CI and DI figure at more than 2.78 million. [ 1 , 2 , 3 ]

Yonhap said CI is used to link information across services, and that if it is leaked and combined with other personal information it could be abused to link and track an individual’s usage history. [ 1 ]

Three cases, including Woori Card and the Busan International Finance Promotion Institute, could not be sized because data had been deleted, log records were absent or leaked information differed by data subject, Yonhap said. Jeonnam Technopark’s DI leak could not be sized because no log records existed at the time. [ 1 ]

Chosun Ilbo reported the analysis was based on data submitted by the Personal Information Protection Commission and the Financial Supervisory Service and on published decisions, and was carried out by the office of Social Democratic Party lawmaker Han Chang-min. The other documents do not name the office behind the figures. [ 2 ]

Why it matters

The figures cover only cases the two regulators penalised, and they put the scale of past enforcement on the public record. Yonhap said CI is used to link information across services, so leaked identifiers can be combined with other personal data to link and track an individual’s usage history. The documents do not say what follow-up action, if any, is planned.

Key facts

  • More than 5.05 million resident registration numbers leaked over the past six years in personal data leak cases penalised by the Personal Information Protection Commission and the Financial Supervisory Service, according to the reported figures. [ 1 , 2 , 3 ]
  • CI and DI leaks exceeded 2.78 million; the confirmed cases were Yanolja (DI) at 1,002,898, Modetour Network (CI and DI) at 948,393 and Lotte Card (CI) at 836,382. [ 1 , 2 , 3 ]
  • Yonhap said the confirmed leak total was 5,056,653 records, excluding three cases whose scale could not be determined. [ 1 ]
  • Individual case figures reported by Yonhap: Yanolja 1,002,898, NHN WeToo 524,620, Lotte Card 452,313, Duo Information 427,464 (encrypted) and LG Uplus 297,117 (encrypted). [ 1 ]
  • Three cases, including Woori Card and the Busan International Finance Promotion Institute, could not be sized because data had been deleted, log records were absent or leaked information differed by data subject. [ 1 ]
  • Jeonnam Technopark’s DI leak could not be sized because no log records existed at the time. [ 1 ]
  • Chosun Ilbo reported the analysis was carried out by the office of Social Democratic Party lawmaker Han Chang-min using data submitted by the two regulators and published decisions. [ 2 ]
  • Yonhap said CI can be used to link information across services, raising concern it could be abused to link and track a person’s usage history if combined with other personal data. [ 1 ]

Confirmed by several sources

  • Over the past six years, personal data leak cases penalised by the Personal Information Protection Commission and the Financial Supervisory Service involved more than 5.05 million resident registration numbers. [ 1 , 2 , 3 ]
  • Leaks of CI and DI — described as so-called online resident registration numbers — exceeded 2.78 million. [ 1 , 2 , 3 ]

Still unclear

  • The exact size of the total: Yonhap reported 5,056,653 resident registration numbers, Chosun Ilbo said more than 5.05 million and Newsis put the figure at 5.06 million in its headline. Outlets state the total with slightly different precision; the exact number appears in one document only.
  • Who compiled the analysis: Chosun Ilbo attributes it to the office of Social Democratic Party lawmaker Han Chang-min, while the other documents do not name the office behind the figures. Single-source attribution.
  • Whether the total covers every personal data leak in the six-year period, or only cases penalised by the two regulators. The documents describe penalised cases and do not state whether other leaks exist outside that set.

What local media are saying

Official sourcesYonhap, the national news agency, carried the fullest breakdown, naming the companies and record counts, flagging CI and DI as identifiers that can be used to link and track individuals, and listing the cases that could not be sized. [ 1 ]
Business mediaChosun Ilbo and Newsis led with the aggregate totals, reporting more than 5.05 million resident registration numbers and about 2.79 million CI and DI records over six years; Chosun Ilbo attributed the analysis to the office of Social Democratic Party lawmaker Han Chang-min. [ 2 , 3 ]

Timeline, local time

  1. Yonhap publishes the detailed breakdown of personal data leak cases over six years. [ 1 ]
  2. Chosun Ilbo reports the analysis of regulator data by a lawmaker’s office. [ 2 ]
  3. Newsis publishes its report on the same figures. [ 3 ]