[Editorial] Hackings Reach Even KNDA, Exposing a Gaping Hole in Cybersecurity
- Input
- 2026-07-21 18:17:00
- Updated
- 2026-07-21 18:17:00

Most serious of all, the server in question was inside the Ministry of Foreign Affairs (MOFA) headquarters, yet it was excluded from regular security inspections, creating a blind spot in security. Hackers had been slipping in and out for 10 months before the relevant authorities were notified, and no one noticed. Even after it was urgently blocked in February, the breach was not made public until five months later. The response was slow, and the disclosure came only after the fact. Critics also say the damage worsened because information on retirees and employees who had returned to their parent ministry was left undeleted.
Unacceptable security breaches at government agencies have been piling up recently. Personal information and startup ideas belonging to 5,000 winners of the government's startup support program, Everyone's Startup, were leaked, prompting a direct apology from the minister in charge at the time. Personal data belonging to 4.62 million users of Seoul's public bike-sharing service, Seoul Public Bike Ttareungyi, was also leaked. Experts point out that incidents keep recurring because penalties for public institutions are weaker than those for private companies.
Private companies are no different. Data breaches have continued at telecom firms such as Lotte Card, KT, and SK Telecom, as well as at Coupang and TVING. The scale of the damage is also growing, with 33.7 million people affected at Coupang and 23.24 million at SK Telecom. The Personal Information Protection Commission (PIPC) is also investigating YES24, GS Retail, and Netmarble. Because security incidents are so frequent, people may not even know their personal information has been leaked unless companies announce it. In effect, everyday life has become exposed to cyberattacks.
Security incidents keep happening because sanctions are little more than a slap on the wrist. Nearly half of the institutions that suffered two or more personal data breaches reportedly received only corrective recommendations or fines instead of heavier penalties. A surcharge is far stronger than an administrative fine. In many repeated cases, punishment has remained weak. The government is also moving to improve the system by raising the upper limit on surcharges and pushing for a class action system. Coupang was hit with a record surcharge of 620 billion won.
But fundamental prevention will remain difficult unless the mindset changes and security is seen not as a cost, but as an investment. Security breaches are like fires or natural disasters. Once they happen, the scale of the damage is hard to measure, and the blow to corporate trust can be devastating. Every time an incident occurs, people call for countermeasures, but those promises soon fade away. Security often gets pushed down the priority list whenever investment plans are drawn up.
Cyberattacks are now a national disaster that threatens both security and the economy. The cybersecurity system must be completely overhauled. A national control tower should be established, along with a response framework that covers both the public and private sectors. For institutions and companies that conceal personal data leaks or neglect management, surcharges should be sharply increased and responsibility should be held to account. Above all, cybersecurity must be recognized not as a cost, but as an essential investment for national security and survival. Only then can this vicious cycle be broken.