Two-thirds of the cases occurred because of negligence
Data leaks regarding personal information occurred at 164 public institutions in the first half of this year, marking a consistent increase since 2021, according to data from the Personal Information Protection Commission on Sunday.
The number of state-run institutes hit by personal information leaks has been rising every year from 22 in 2021, to 23 in 2023, 41 in 2023, 104 in 2024, and 128 in 2025, according to a report by Rep. Song Eon-seok of the main opposition People Power Party based on the PIPC data. This year’s figure as of June has already surpassed the total number for last year.
Song’s report showed that of the 139 cases of personal information leak that have been handled by the PIPC between 2022 and this year, 94 occurred because of employee negligence. This means 67.6 percent of the data breach happened because of human error.
Hackers were responsible for 44 cases, and the data was leaked deliberately on one occasion.
It was found that 7.84 records of personal information were leaked in the aforementioned 139 cases. This includes name, contact information, address, resident registration number, bank account number, and information related to one’s health.
It was reported last month that personal information of all South Korean diplomats are presumed to have been leaked in a data breach at a government-run online education system. The Ministry of Foreign Affairs shut down the system after being notified of the data breach in February, and the system held approximately 10,000 records of personal data.
