The South Korean authority sanctions two entities of the HD Hyundai group for failures in personal data security measures
A data breach resulting from an unpatched vulnerability on a server and a lack of network segmentation between two companies of the same group led the South Korean authority to sanction the two entities, distinguishing the responsibility of the one whose system served as the entry point and the one whose data was exfiltrated.
Facts and context
The South Korean data protection authority, the Personal Information Protection Commission (PIPC), issued a sanction decision against two companies of the HD Hyundai group, HD Construction Equipment and HD Korea Shipbuilding & Offshore Engineering, including fines totaling 78.3 million won (approximately €52,200) for failures related to the security of processing systems.
The case originated from a personal data breach suffered by HD Construction Equipment in March 2024, resulting from a cyber intrusion carried out by an unidentified malicious actor.
Grounds for the decision
The authority found several failures to security obligations, which can be analyzed in light of the GDPR principles:
Obligation to ensure the security of processing (equivalent to Article 32 of the GDPR): The investigation showed that HD Korea Shipbuilding & Offshore Engineering had not implemented appropriate technical measures to secure its mobile device management server. A file upload vulnerability had not been patched, allowing an attacker to upload a malicious file (a "webshell") and use this server as an entry point for the attack.
Obligation to control access to processing systems (equivalent to Article 32 of the GDPR): It was established that no measures limited access between the compromised server of HD Korea Shipbuilding & Offshore Engineering and the internal management system of HD Construction Equipment. The authority emphasized that this interconnection was not justified by any operational necessity. This lack of network segmentation allowed the attacker, once the first server was compromised, to move laterally to access the second company's system and exfiltrate personal data of 9,503 employees and partners (name, employee number).
Authority's decision
Consequently, the authority imposed a fine of 73,500,000 won (approximately €49,000) on HD Construction Equipment, as the data controller of the personal data that was leaked.
Furthermore, the authority ordered HD Korea Shipbuilding & Offshore Engineering to pay a fine of 4,800,000 won (approximately €3,200) for its security failure that allowed the initial intrusion.
Lessons learned
This decision reminds that:
Vulnerability management is an essential component of technical security measures and must be applied rigorously and regularly on all systems, especially those exposed on the internet.
Network segmentation and strict access control between different information systems are fundamental measures to prevent the spread of an attack and limit its impact.
Interconnections between systems of different entities, even within the same group, must be limited to the strict necessary and secured by access controls (for example, by internet protocol addresses).
Responsibility for a data breach can be shared: the entity whose system served as the entry point can be sanctioned for its own security failure, independently of the higher sanction imposed on the data controller whose data was compromised.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire