Wednesday, October 7, 2026

ACRC also hit by ‘hacking’: Personal data of 100,000 users at affiliated agency leaked; failure to delete data after system replacement cited as cause

Input
2026-10-06 23:33:23
Updated
2026-10-06 23:33:23
Anti-Corruption and Civil Rights Commission / Photo: Yonhap News

[Financial News] The Integrity and Rights Learning Center, an online education platform run by an agency affiliated with the Anti-Corruption and Civil Rights Commission (ACRC), was hit by a hacking attack, exposing the personal data of around 100,000 users.
According to the ACRC and the National Integrity and Rights Education Institute on the 6th, servers belonging to Malgeun Soft, the company contracted to operate the online education site, were recently hacked, and the database (DB) containing the personal information of around 100,000 users of the Learning Center, which had been stored there, was leaked externally.
The Integrity and Rights Learning Center is a platform where employees of public institutions, staff at private schools, and others affiliated with organizations related to public service complete integrity training online.
The database leaked in this incident contained data from before the system was replaced in April last year. The leaked fields were found to include users’ names, IDs, passwords (encrypted using one-way encryption), gender, dates of birth, mobile phone numbers (encrypted), email addresses, affiliations, and job titles.
The cause of the breach was found to be poor management by the contractor. Malgeun Soft was supposed to destroy the old data after the system replacement, in accordance with the applicable principles, but instead retained it without deleting it and was then hacked. The attack reportedly also exposed data from other institutions besides the ACRC.
The ACRC is working to determine the exact cause of the incident while conducting a comprehensive review of the status of personal data deletion across all outsourced projects carried out over the past three years.
In response to the incident, the ACRC also plans to rigorously carry out security reviews from the planning stage of future IT projects and, once projects are completed, further strengthen its oversight of procedures for confirming and documenting the deletion of personal data.  

[email protected] Park Ji-hyun Reporter