The 'Online Resident Registration Number' Cannot Be Changed Once Leaked... Cho Kyung-tae: "It Should Be Renewed Every Year"
- Input
- 2026-09-21 14:09:20
- Updated
- 2026-09-21 14:09:20

On the 21st, Cho Kyung-tae, a member of the Science, ICT, Broadcasting, and Communications Committee of the National Assembly and a lawmaker from the People Power Party, said he plans to call on the Korea Media and Communications Commission (KMCC) during this year's National Assembly audit to introduce a one-year CI validity system and establish an emergency change and reissuance system for victims of data breaches.
CI is identification information generated when internet users verify their identities and used to confirm that the same person is accessing different online services. Because the same value is used across multiple services, it is also known as an "online resident registration number." Although CI alone cannot immediately identify a specific individual, concerns have been raised that personal information leaked from different companies could be combined using CI as a link.
The main concern is that, unlike passwords or card numbers, users cannot easily change or have a leaked CI reissued. CI was also included in recent personal information breaches involving Lotte Card, TVING, BGF Networks, and Woori Bank in the financial, online video streaming, and lifestyle services sectors.
Rather than abolishing the CI system, Cho proposed assigning it a one-year validity period and periodically renewing it with a new value. The approach would be similar to the Korea Customs Service's application of a one-year validity period to the Personal Customs Clearance Code to prevent identity theft.
He also argued that an emergency change and reissuance system should be introduced as a priority so that users whose CI has already been confirmed to have been leaked can discard their existing CI and receive new identification information. He plans to call for a review of measures to phase in the transition from existing CIs, as well as the need to revise relevant notices, enforcement decrees, and laws.
Cho said, "If a password is leaked, people change it, and if a card number is leaked, they have it reissued. But with CI, which is called an 'online resident registration number,' citizens have no practical way to change it themselves once it is leaked." He added, "If we cannot prevent hacking and personal information breaches 100% of the time, we need to shift to a system that minimizes even the risks after a breach."
[email protected] Yoon Hong-jip Reporter