HD Hyundai Affiliates Penalized for Leaving Unnecessary Intercompany Server Links Unsecured After Personal Data Leak
- Input
- 2026-08-27 11:55:09
- Updated
- 2026-08-27 11:55:09
The companies were found to have violated their duty to take security measures under the Personal Information Protection Act by leaving affiliate servers accessible even though there was no business need to do so.
The PIPC said on the 27th that it had held its 17th plenary meeting on the 26th and imposed a fine of 73.5 million won on HD Construction Equipment for violating the Personal Information Protection Act, as well as a 4.8 million won penalty on HD Korea Shipbuilding & Offshore Engineering (HDKSOE), which was used as the route for the breach.

In March 2024, a hacker who discovered a vulnerability in the mobile device management server operated by HDKSOE accessed an internal business system at HD Construction Equipment that could communicate with the server, leaking personal information, including names and employee numbers, of 9,503 people from HD Construction Equipment and its partner companies.
“Our investigation found that the HDKSOE mobile device management server and HD Construction Equipment’s internal business system had no business need to be linked, yet the companies failed to restrict system access between them, which led to the personal data breach,” the PIPC said.
Along with the fines, the commission urged personal data handlers to regularly review security measures so that personal information is not leaked or exposed through web vulnerabilities.
It also stressed that access to personal data processing systems should be restricted by IP addresses and other methods to block unnecessary access and prevent illegal intrusion and security incidents.
[email protected] Lee Gu-soon Reporter