LocknLock Failed to Detect Large-Scale Traffic, Only Noticed After Hacker's Email

UBase Fined 168 Million Won, Sunphoto 30 Million Won

The Personal Information Protection Commission announced on July 9 that it has imposed an administrative fine of 530 million won and a penalty of 5.4 million won on LocknLock after a data breach that exposed the personal information of approximately 1.3 million individuals.


Song Kyunghee, Chairperson of the Personal Information Protection Commission, is striking the gavel at the 13th plenary session held at the Government Seoul Office Building on the afternoon of the 8th. Photo by Personal Information Protection Commission

Song Kyunghee, Chairperson of the Personal Information Protection Commission, is striking the gavel at the 13th plenary session held at the Government Seoul Office Building on the afternoon of the 8th. Photo by Personal Information Protection Commission

View original image


At the 13th plenary session held the previous day, the Commission decided to impose a total of 701 million won in administrative fines and 5.4 million won in penalties on three companies—LocknLock, Ubase, and Sunphoto—for violations of the Personal Information Protection Act. The Commission also resolved that each company must publish details of the sanctions on their respective websites.


According to the investigation, in April 2024, a hacker exploited a security vulnerability in LocknLock’s mail server to infiltrate its internal system and subsequently leaked the membership database (DB) at the end of May. The same hacker re-entered the internal system in November of that year and leaked additional work-related files from the file server. During this process, the personal information of about 1.3 million members (names, mobile phone numbers, addresses, etc.) and 1,111 records of employee data were leaked externally. The leaked employee information included copies of resident registration cards, driver’s licenses, and bankbooks.


The Commission explained that LocknLock failed to detect or respond to the abnormal large-scale traffic that occurred during the breach and only became aware of the leak after receiving a threatening email from the hacker. The Commission also pointed out that LocknLock did not address security vulnerabilities disclosed in 2022, used the same password for key server administrator accounts, and failed to encrypt unique identification information, thereby violating multiple security obligations. It was also found that LocknLock did not destroy a total of 49,466 records of personal information belonging to employees and customers from closed stores.


Ubase, a company providing call center outsourcing services to businesses, was fined 168 million won and ordered to publish the sanction details on its website. In 2024, a hacking incident targeting the administrator account of Ubase’s main website led to the leakage of names, phone numbers, email addresses, and company names of 1,852 inquiry board users. The hacker also posted this information on Telegram.


The investigation revealed that Ubase allowed external access to the administrator page without restricting access rights by internet protocol (IP) address or similar measures. The administrator page could be accessed using only an ID and password, without secure authentication methods, and access logs for the personal information processing system were inadequately maintained and managed.


Sunphoto, a company specializing in the sale of photo and video equipment, also suffered a data breach in 2024 when its website administrator account was hacked, resulting in the leakage of personal information of approximately 170,000 members and 13 order records. The leaked data included names, IDs, mobile phone numbers, and gender. It was confirmed that the hacker attempted voice phishing by impersonating a Sunphoto employee to one customer.


The Commission determined that Sunphoto violated security obligations by failing to restrict access rights to the administrator page by IP address or other means and by not maintaining or managing access logs for the personal information processing system. Consequently, an administrative fine of 30 million won was imposed, and the company was ordered to publish details of the sanction on its website.



The Commission stated, “Incidents of personal information leakage continue to occur due to neglect of basic security measures. Access rights to personal information processing systems must be restricted by IP address or similar methods, and in particular, when external access is required, additional authentication methods beyond ID and password should be implemented.”


This content was produced with the assistance of AI translation services.

© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.

Today’s Briefing