The South Korean authority sanctions three companies for failures in personal data security measures

The South Korean authority sanctions three companies for serious and basic failures in security, including the lack of IP address access restrictions to administration interfaces and the use of weak authentication, leading to significant data breaches.

Facts and context

The South Korean data protection authority (Personal Information Protection Commission - PIPC) published on July 8 a series of sanction decisions against three companies for a total amount of 701 million won (approximately €467,000) in administrative fines and 5.4 million won (approximately €3,600) in penalties, for failures related to the security of personal data.

These cases follow personal data breaches suffered by the three companies, which revealed failures in their respective security measures.

Reasons for the decision

Regarding the company ㈜락앤락, a manufacturer of plastic products, an attacker exploited a vulnerability in its mail server to exfiltrate, in two phases in May and November 2024, data of about 1.3 million customers (name, phone number, address) and 1,111 employee files (containing copies of identity documents and bank statements).

  • Security obligation: The authority found that the company had not updated a known security vulnerability since 2022, used the same password for several administrator accounts of critical servers, and had not encrypted unique identifiers. Moreover, it was unable to detect the abnormally high network traffic generated by the exfiltrations, becoming aware of the incident only upon receiving a ransom email from the attacker.
  • Data retention limitation obligation: It was also established that the company retained without justification personal data of employees as well as information of 49,466 store buyers from stores that had been closed, violating the data retention limitation principle.

Regarding the company ㈜유베이스, a call center service provider, an attacker accessed in April 2024 the administrator account of its main website. They were thus able to steal data of 1,852 users of the contact form (name, phone, email, company name) and published it on the Telegram messaging service.

  • Security obligation: The investigation revealed that the administration page of the site was accessible from the public internet without any IP address access restriction. Authentication relied solely on a username and password, without a strong authentication mechanism, which constitutes an insufficient security measure.
  • Logging obligation: The company also failed in its obligation to properly retain and manage connection logs to the personal data processing system, preventing traceability of accesses.

Regarding the company 썬포토㈜, specialized in photographic equipment sales, an attacker accessed in August 2024 the administrator account of its website. They exfiltrated data of about 170,000 members (name, ID, phone, gender) and 13 order files, then attempted a voice phishing attack on a client by impersonating an employee.

  • Security obligation: Similarly, the authority reproached the company for not limiting access to its administration page by IP address, leaving it exposed on the internet.
  • Logging obligation: It was found that the company did not retain any connection logs related to its personal data processing system, violating its obligations to ensure the security and traceability of processing.

Authority's decision

Consequently, the authority imposed an administrative fine of 503 million won (approximately €335,000) and a penalty of 5.4 million won (approximately €3,600) on ㈜락앤락.

The company ㈜유베이스 was fined 168 million won (approximately €112,000).

The company 썬포토㈜ was sanctioned with an administrative fine of 30 million won (approximately €20,000).

Furthermore, the authority ordered the three companies to publish on their respective websites a statement informing of the sanction received.

Lessons learned

This decision reminds that:

  • Administration interfaces of personal data processing systems must not be exposed on the public internet without strict access control measures, such as IP address restriction.
  • Remote access to critical systems, when necessary, must be secured by a strong authentication mechanism beyond a simple username and password pair.
  • Retention and regular review of connection logs are fundamental security measures to detect unauthorized access and allow analysis in case of incident.
  • Rigorous IT security hygiene is essential, including prompt application of security patches, use of unique and strong passwords for privileged accounts, and encryption of sensitive data.
  • Personal data must only be retained for the duration necessary for the purpose for which it was collected and must be securely deleted once this purpose is achieved.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire