기사 메일전송
Incruit fined 400 million won for not knowing about 7.3 million user data leak for two months
  • Yonhap News
  • October 23, 2025 at 12:32 PM
기사수정

Incruit Fined 400 Million Won for Not Knowing About Personal Information Leak of 7.3 Million Users for Two Months


Personal Information Leak in 2023... PIBC: "Strict Application of Laws Due to Repeated Incidents"


Speaking, Chairperson Song Kyung-heeSpeaking, Chairperson Song Kyung-hee (Seoul=Yonhap News) Reporter Lee Jung-hoon = Song Kyung-hee, Chairperson of the Personal Information Protection Commission, is speaking at the 22nd plenary session in 2025 held at the Government Complex Seoul in Jongno-gu, Seoul on the 22nd. 2025.10.22 uwg806@yna.co.kr


The Personal Information Protection Commission (PIBC) announced on the 23rd that it decided at its plenary session on the 22nd to impose a fine of 463 million won on the online job portal Incruit, which experienced a personal information leak of approximately 7.3 million members due to hacking.


According to the investigation, hackers planted malware on an Incruit employee's work computer in January of this year and then infiltrated the internal system using stolen database (DB) access credentials.


During this process, it was revealed that personal information of 7,275,843 members and 54,475 personal storage files, such as resumes, cover letters, and copies of certificates (approximately 438GB), were stolen over about a month.


Despite abnormal DB access records and large traffic volumes outside of work hours, Incruit did not take any specific measures, and it was confirmed that the company only became aware of the incident two months later after receiving a threatening email from the hackers.


Furthermore, it was found that Incruit also violated its duty to take safety measures, such as not separating the computer used by personal information handlers, which could download and delete a large amount of personal information including sensitive information, from the internet network.


Overview of Incruit Personal Information Leak IncidentOverview of Incruit Personal Information Leak Incident [Provided by the Personal Information Protection Commission. Resale and DB prohibited]


Incruit had previously been fined 70.6 million won and a penalty of 3.6 million won by the PIBC in 2023 for a leak of over 35,000 member credentials due to a 'credential stuffing' attack.


Credential stuffing is a hacking attack that attempts to log in by randomly entering user account information collected from other sites.


The PIBC explained that it took the repeated leak incidents by the same business operator within three years seriously and calculated the fine by strictly applying the current laws and regulations.


In addition, the company was ordered to designate a new Chief Personal Information Officer (CPO) to clarify roles and responsibilities, and to submit a recurrence prevention plan, including support for data subject damage recovery, within 60 days.


The PIBC stated, "We are preparing an improvement plan for the punitive fine system for companies that are clearly negligent in personal information protection, such as repeated leak incidents," and "We will enhance the effectiveness of sanctions to raise awareness among companies." Yonhap News



What do you think of this article?
recommend
0
great
0
moved
0
정기구독배너
Go to Mobile Site