
Image to help understand the article
Employee Information Leak Discovered After Intelligence Agency Notification
The Korea Electric Power Corp. (KEPCO), South Korea’s state-run electricity provider, said that personal information belonging to more than 24,000 employees was exposed on an external webpage, according to an announcement on Oct. 4.
KEPCO said it became aware of the incident after receiving notification from South Korea’s National Intelligence Service (NIS). The company said the exposure was first identified by the intelligence agency rather than through KEPCO’s own internal monitoring.
The exposed information included employee names, departments, employee identification numbers, mobile phone numbers, internal phone numbers, email addresses and job titles. KEPCO said the leaked data did not include sensitive information such as national identification numbers or other unique personal identifiers.
Access Blocked and Data Removed
After learning of the incident, KEPCO blocked access to internal systems connected to the employee information and requested that the operator of the webpage remove the exposed data. The company said the information was deleted around midnight on Oct. 2, about 32 hours after the incident was discovered.
KEPCO also established an emergency response team and notified affected employees through text messages and email. The company provided guidance on steps employees could take to help prevent potential secondary damage.
Joint Investigation Underway
KEPCO said it is conducting an investigation with government agencies, including the National Intelligence Service and the Ministry of Climate, Energy and Environment, to determine how the information was exposed. Investigators are examining whether the incident resulted from an internal mistake or an external intrusion.
The company said customer information was not affected. Data such as electricity usage records, billing information and customer contract details are managed separately through a dedicated personal information system, KEPCO said.
KEPCO said it will develop measures to prevent similar incidents after the investigation is completed. It also said it would review possible compensation procedures if employees report damages linked to the exposure.
Cybersecurity Concerns in South Korea
The incident comes as South Korean financial institutions have recently faced a series of cybersecurity threats, including hacking attempts involving artificial intelligence tools. KEPCO said no connection between those incidents and the employee data exposure has been confirmed.
Comments
Post a Comment