Back Koreajoongangdaily Hack exposes personal data of 5000 Kia union members
The Gwangmyeong plant they worked at had outsourced management of its online education system to a third party.
The personal information of 5,000 union members at Kia’s Gwangmyeong plant in Gyeonggi was leaked after a server run by an outside online training provider was hacked, according to the labor union on Wednesday.
The server managed by Malgnsoft was hit by an external cyberattack on Sept. 19, which exposed names, employee ID numbers, encrypted phone numbers and other personal information of union members at the plant.
The union had outsourced management of its online education system and servers to Malgnsoft.
Hackers used multiple IPs used to hide origins of financial cyberattacks: Police
Hackers used multiple IPs used to hide origins of financial cyberattacks: Police
Shinhan Bank likely to face collective lawsuit over customer data breach
Shinhan Bank likely to face collective lawsuit over customer data breach
Cyberattacks expose member data, donation records at two Seoul megachurches, report says
Cyberattacks expose member data, donation records at two Seoul megachurches, report says
Police launch probe into recent cyber attacks at financial firms
Police launch probe into recent cyber attacks at financial firms
“Phone numbers and passwords were stored in encrypted form, so the actual numbers and passwords were not exposed,” the union said in a text message alert sent to members. “No additional damage from the incident has been confirmed so far.”
The leak follows strings of recent data breaches experienced by major commercial banks such as KB Kookmin, Shinhan and Hana.
“Unauthorized external access occurred to systems we manage for the operation of online education sites,” Malgnsoft said in a notice posted on its website on Sept. 20.
The software company said it confirmed that some user information under its management had been leaked.
The breach reportedly affected not only Kia union members but also employees at more than 20 organizations whose systems Malgnsoft managed, including the Anti-corruption & Civil Rights Commission and the Ministry of National Defense.
The Kia union warned members not to click suspicious text messages or links after being notified of the breach by Malgnsoft on Sept. 25.
Malgnsoft reportedly blocked the external attack and completed security measures on the servers. The company also reported the incident to the Korea Internet & Security Agency and the Personal Information Protection Commission and is undergoing additional inspections.
BY KO SEUNG-PYO [[email protected]]
This article was originally written in Korean and translated by a bilingual reporter with the help of generative AI tools. It was then edited by a native English-speaking editor. All AI-assisted translations are reviewed and refined by our newsroom.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
