'Dareungi Data Leak' Victims to Receive '30-Day Pass' Compensation
Individual Notifications Sent to 4.62 Million Citizens Starting on the 21st
Web Vulnerabilities Addressed and Security Assessments Underway
The Seoul Facilities Corporation announced on the 21st that it will provide a "30-day regular pass" to victims of the Darungi public bicycle membership information leak.
Approximately 4.62 million citizens are affected. Compensation coupons will be distributed via the Darungi app next month. Members who already have a regular pass may use the new pass within three months after the expiration of their current pass.
Seoul Jung-gu Sejong-daero near City Hall Station Seoul Public Bike Storage. The Asia Business Daily
View original imageThe corporation recently finalized the specific leaked data for each individual after discussions with the National Police Agency and the Personal Information Protection Commission, and has begun informing the 4.62 million affected citizens through individual text messages and website notices. The notification messages contain each individual's actually leaked personal information (such as ID, mobile phone number, date of birth, gender, weight, email address, home address, guardian’s mobile phone number), the circumstances of the leak, and preventive measures against further harm.
Hot Picks Today
"Can't Get This in the U.S., Korea Is the Best": Americans Flock to Korea as 'K-Comprehensive Health Check-ups' Surge
- "Broke the Piggy Bank... Salaries Just Aren't Enough": The Stocks Individual Investors Are Rushing to Buy Worldwide
- Chinese Group Tourists Abandoned from Noon to Evening After Refusing Shopping... Korea Embarrassed by ‘Low-Quality Tours Focused Only on Headcount’
- KOSPI Closes Above 6,700, Up Over 3% on Foreign and Institutional Buying
- "I Almost Died Just 30 Minutes After Wearing Them"... Why Zara Pants Are Being Called 'Death Pants'
In 2024, over 4.6 million records of Darungi members were leaked during a DDoS attack. According to the police investigation, two teenage suspects were referred to the prosecution. They exploited a vulnerability that allowed them to access member information stored on the Darungi servers—such as user IDs, mobile phone numbers, email addresses, addresses, dates of birth, gender, and weight—without any authentication process. The leaked information did not include names or resident registration numbers.
After the incident, the corporation and Seoul Metropolitan Government activated an emergency response center, addressed the web vulnerability that caused the breach, and strengthened monitoring of abnormal server access. To prevent recurrence, they are regularizing security checks and penetration tests, as well as coordinating with relevant authorities to secure additional IT personnel and budget. Kim Young, President of the Seoul Facilities Corporation, stated, "We deeply apologize once again for the concern and inconvenience caused by this personal information leak. We will overhaul our security system to ensure citizens can use Darungi with peace of mind and will devote our utmost efforts to this end."
© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.