Last year, personal information of 48.19 million people leaked... Virtually the entire population was exposed
- Input
- 2026-09-28 11:41:39
- Updated
- 2026-09-28 11:41:39

[Financial News] The number of people affected by personal information leaks reached 48.19 million last year. This year, personal information belonging to 43.88 million people was leaked in the first half alone, as large-scale data breaches continued.
For the second consecutive year, personal information was repeatedly leaked on a scale that effectively covered the entire population. This has prompted calls for stronger accountability and a prevention-focused management and oversight system for protecting personal information.
According to data submitted by the Personal Information Protection Commission (PIPC) to Kim Sunmin, a lawmaker from the Rebuilding Korea Party (RKP) and a member of the Science, ICT, Broadcasting, and Communications Committee of the National Assembly, the number of people affected by personal information leaks fell from 14.64 million in 2023 to 8 million in 2024 before surging to 48.19 million last year. In the first half of this year alone, the figure reached 43.88 million, exceeding 90% of last year's annual total.
However, the number of cases that resulted in action following review and resolution by the PIPC stood at 158 in 2023, 119 in 2024, and 115 in 2025. There were 75 such cases in the first half of this year.
In particular, as large-scale personal information breaches affecting more than 10 million people have occurred one after another recently, concerns are also growing over secondary harm caused by combining or reconstructing the leaked information.
A recent breach involving TVING also exposed a large volume of account information. According to an investigation by the Ministry of Science and ICT, the breach that occurred at TVING in May resulted in the leakage of 7.26 million directly registered TVING accounts, 8.63 million CJ ONE integrated member accounts, and 22.47 million easy-sign-up accounts linked through social networking services (SNS) such as Naver, Kakao, Facebook, Apple, and X. Including duplicate accounts, a total of 39.54 million accounts were leaked.
The scope of the leaked information was also extensive. The investigation found that 70 types of information across 20 categories had been exposed, including IDs, one-way encrypted passwords, CJ ONE integrated IDs, names, mobile phone numbers, email addresses, dates of birth, and connecting information (CI).
Kim Sunmin said, "Even taking into account the possibility that one person's personal information may be leaked multiple times, the fact that personal information on a scale comparable to South Korea's population was leaked in a single year is by no means something to be taken lightly. Once personal information is leaked, it is difficult to recover, and it is highly likely to lead to secondary harm such as voice phishing, identity theft, and financial fraud. The public's personal information cannot be protected by dealing with each breach after the fact."
Kim Sunmin called for stronger corporate accountability for personal information protection, along with a prevention-focused government management and oversight system. Kim Sunmin emphasized, "The government must no longer dismiss repeated personal information breaches as merely the result of individual companies' negligence. While strengthening companies' responsibility to protect personal information, the government must also establish an effective management and oversight system that can prevent leaks themselves, rather than merely punishing companies after an incident occurs."
[email protected] Choi Hyerim Reporter