Skip to content
Hack exposes personal data of 5000 Kia union members

Hack exposes personal data of 5000 Kia union members

Koreajoongangdaily • October 7, 2026

The Gwangmyeong plant they worked at had outsourced management of its online education system to a third party.

The personal information of 5,000 union members at Kia’s Gwangmyeong plant in Gyeonggi was leaked after a server run by an outside online training provider was hacked, according to the labor union on Wednesday.

The server managed by Malgnsoft was hit by an external cyberattack on Sept. 19, which exposed names, employee ID numbers, encrypted phone numbers and other personal information of union members at the plant.

The union had outsourced management of its online education system and servers to Malgnsoft.

Hackers used multiple IPs used to hide origins of financial cyberattacks: Police

Hackers used multiple IPs used to hide origins of financial cyberattacks: Police

Shinhan Bank likely to face collective lawsuit over customer data breach

Shinhan Bank likely to face collective lawsuit over customer data breach

Cyberattacks expose member data, donation records at two Seoul megachurches, report says

Cyberattacks expose member data, donation records at two Seoul megachurches, report says

Police launch probe into recent cyber attacks at financial firms

Police launch probe into recent cyber attacks at financial firms

“Phone numbers and passwords were stored in encrypted form, so the actual numbers and passwords were not exposed,” the union said in a text message alert sent to members. “No additional damage from the incident has been confirmed so far.”

The leak follows strings of recent data breaches experienced by major commercial banks such as KB Kookmin, Shinhan and Hana.

“Unauthorized external access occurred to systems we manage for the operation of online education sites,” Malgnsoft said in a notice posted on its website on Sept. 20.

The software company said it confirmed that some user information under its management had been leaked.

The breach reportedly affected not only Kia union members but also employees at more than 20 organizations whose systems Malgnsoft managed, including the Anti-corruption & Civil Rights Commission and the Ministry of National Defense.

The Kia union warned members not to click suspicious text messages or links after being notified of the breach by Malgnsoft on Sept. 25.

Malgnsoft reportedly blocked the external attack and completed security measures on the servers. The company also reported the incident to the Korea Internet & Security Agency and the Personal Information Protection Commission and is undergoing additional inspections.

BY KO SEUNG-PYO [[email protected]]

This article was originally written in Korean and translated by a bilingual reporter with the help of generative AI tools. It was then edited by a native English-speaking editor. All AI-assisted translations are reviewed and refined by our newsroom.

Extracted Entities

Attack Types (1)

Companies (2)

Countries (1)

Domains (1)

Email Addresses (1)