Add preferred source
Korea Electric Power Corporation (KEPCO) suffered a data exposure incident in which the personal information of approximately 24,000 employees—including names, department affiliations, and phone numbers—was exposed on an external webpage. The company became aware of the incident at around 3:59 p.m. on the 1st and immediately blocked access to internal systems, but actual deletion of the information did not occur until around midnight the following day, taking roughly 32 hours. KEPCO stated that unique identifiers such as resident registration numbers and sensitive information were not exposed, and that customer information is managed separately through a dedicated system and was therefore not included in the breach. The company has activated an emergency response command center, is conducting a joint investigation with law enforcement authorities, and said it will pursue compensation procedures if damage reports are filed.
Key Elements
Korea Electric Power Corporation (KEPCO) has suffered a data exposure incident in which the personal information of approximately 24,000 employees was exposed on an external webpage. The incident adds the state-owned utility to a growing list of organizations affected by data breaches, as personal information leaks stemming from hacking attacks on the financial sector continue to be reported in succession.
KEPCO said in a statement on the 4th that it became aware of the exposure of employee personal information on an external webpage at approximately 3:59 p.m. on the 1st. The exposed data included names, department affiliations, and phone numbers, and the company confirmed that unique identifiers such as resident registration numbers and other sensitive information were not included.
The company said it immediately blocked access to internal systems linked to employee personal information upon recognizing the incident and requested that the operator of the webpage delete the information. Actual deletion took place around midnight on the 2nd, the following day—approximately 32 hours after KEPCO first detected the exposure.
KEPCO is currently operating an emergency response command center and maintaining a coordination framework with relevant agencies. The company has sent text messages and emails to affected employees explaining the circumstances of the incident and providing precautions to prevent secondary damage. A joint investigation with law enforcement authorities is also underway.
A KEPCO official said, “If damage reports are filed—whether actual or anticipated—we will conduct the necessary investigations and proceed with relief procedures including compensation,” adding, “We will thoroughly identify the cause of the information exposure and implement measures to prevent recurrence.”
Customer information was not included in the exposure. KEPCO explained that customer data is managed separately from employee information through a dedicated system with appropriate security controls.
Data Breach Raises Alarm Bells Amid Wave of Financial Sector Leaks
The incident coincides with a series of recent personal information leaks in the financial sector, heightening concerns about the information security posture of public institutions in South Korea. Following revelations that financial companies have been defenseless against hacking attacks, the incident at a state-owned utility responsible for national critical infrastructure confirms that even basic access controls have not been properly enforced.
KEPCO has not yet provided specific details on the cause of the exposure. However, given that the information appeared on an external webpage, questions have been raised about potential vulnerabilities in internal system access permission management or in information-sharing processes with external contractors. The company has stated it will develop recurrence prevention measures based on the findings of the joint investigation.
Relevant authorities, including the Personal Information Protection Commission and the Korea Internet & Security Agency, are expected to review whether the incident triggers mandatory reporting obligations under South Korea’s Personal Information Protection Act. Under current law, personal information handlers must report to authorities without delay when a breach affecting 1,000 or more individuals occurs. It has not yet been confirmed when KEPCO reported the incident to authorities after becoming aware of it.
The 32-Hour Gap Raises Questions
The 32-hour delay between detection and actual deletion is also likely to come under scrutiny. During that window, the possibility that the exposed information was collected or used by third parties cannot be ruled out. KEPCO stated that it requested deletion from the operator immediately upon detection, but has not provided a clear explanation for why it took more than a full day for the deletion to be completed.
Security industry experts note that the scale of damage from a personal information exposure incident is not determined solely by the type of information exposed. Names, department affiliations, and phone numbers alone can serve as material for social engineering attacks. In particular, the identity information of KEPCO employees could provide useful leads for attackers targeting power infrastructure, warranting heightened caution.
KEPCO has urged affected employees to guard against secondary damage such as smishing and voice phishing scams. The company also plans to strengthen its monitoring systems. However, given that already-exposed information cannot be retrieved, the effectiveness of post-incident measures for damage prevention will be a key concern going forward.
Once added, BigGo Finance appears first in Google Search Top Stories, so you get the broadest, most up-to-the-minute, and most comprehensive global financial news first.
