Monday, October 5, 2026

Resident Registration Numbers Cannot Even Be Changed—More Than 5.05 Million Leaked in Six Years

Input
2026-10-05 14:10:55
Updated
2026-10-05 14:10:55
Newsis

[Financial News] More than 5.05 million resident registration numbers were found to have been leaked externally in personal information breach incidents over the past six years. In addition, more than 2.78 million CI and DI records, known as so-called "online resident registration numbers," were also leaked. As large amounts of personal identification information that is difficult to change or retrieve once exposed have been leaked, calls are growing for stronger personal information management systems.
According to an analysis released on the 5th by the office of Rep. Han Chang-min of the Social Democratic Party, based on data submitted by the Personal Information Protection Commission (PIPC) and the Financial Supervisory Service, as well as publicly available written resolutions, there were 130 cases involving leaked resident registration numbers among cases subject to dispositions from 2021 through September 2026. Excluding three cases in which the scale of the leak could not be determined, the total number of leaked records was 5,056,653.
However, this figure is the sum of the number of leaked records in each case and does not represent the actual number of victims, as the same person's resident registration number may have been leaked repeatedly. The figures were also compiled based on the dates of dispositions, rather than the dates on which the incidents occurred.
By institution and company, the National Center for the Rights of the Child recorded the largest number of leaked resident registration numbers, totaling 1,161,042 across three breach incidents.
It was followed by Yanolja with 1,002,898 records, NHN Witu with 524,620, Lotte Card with 452,313, DUOINFO with 427,464 (encrypted), and LG Uplus with 297,117 (encrypted).
The scale of the leaks could not be determined in three cases, including those involving Woori Card and the Busan International Finance Promotion Institute, due to deleted data, missing log records, and differences in the leaked information for each data subject.
Four cases involving leaked CI (linking information) or DI (duplicate-subscription verification information) were identified. CI is generated based on a resident registration number and serves as an "online resident registration number" for identifying the same person across multiple services. DI is used to determine whether someone has registered more than once on the same website.
In particular, because CI is used to link information from multiple services, concerns have been raised that, if it is leaked and combined with other personal information, it could be misused to connect and track an individual's usage history.
The cases for which the scale of the leak was confirmed were Yanolja (DI), with 1,002,898 records; Modetour Network (CI and DI), with 948,393; and Lotte Card (CI), with 836,382. The total was 2,787,673 records.
Rep. Han Chang-min said, "Resident registration numbers are unique identifying information whose handling is strictly restricted. Once leaked, they are virtually impossible to retrieve, and damage such as identity theft can continue for a long time." He added, "The Personal Information Protection Commission must also closely assess the status of resident registration number leaks and respond sternly to poor management."

[email protected] Yeon Ji-an Reporter