No Customer Information Exposed
Joint Investigation with the Ministry of Climate, Energy, and Environment
Cause of Exposure Under Review

Personal Data of 24,000 KEPCO Employees Exposed... No Customer Information Affected View original image

An incident has occurred in which the personal information of approximately 24,000 employees of Korea Electric Power Corporation (KEPCO) was exposed on an external web page. Employee information, including names, departments, and phone numbers, was posted externally on a large scale, and the National Intelligence Service (NIS) was the first to discover it and notified KEPCO. KEPCO is jointly investigating the circumstances of the exposure of personal information with the National Intelligence Service and the Ministry of Climate, Energy, and Environment.


According to KEPCO on the 4th, the National Intelligence Service identified on the afternoon of the 1st that personal data belonging to KEPCO employees had been posted on an external web page. The NIS informed KEPCO of this matter at 3:59 p.m. on the same day.


The exposed information included the names, departments, and phone numbers of approximately 24,000 KEPCO employees. It was confirmed that unique identification numbers and sensitive information, such as resident registration numbers, were not included. KEPCO explained that no customers’ personal information, other than that of employees, was exposed in this incident.


Immediately after being notified by the NIS, KEPCO blocked access to its internal systems related to staff personal information and requested the operator of the external web page to delete the exposed data. However, the actual deletion was completed around midnight on the 2nd, about 32 hours after KEPCO was made aware of the breach.


The web page in question is reportedly not open to the general public. So far, there have been no signs of external hacking attempts, and KEPCO believes the incident is unrelated to recent AI-based hacking attacks that have occurred in the financial sector.


The exact cause of the personal information exposure has not yet been determined. KEPCO has established a comprehensive emergency response center and is conducting a joint investigation with the NIS and the Ministry of Climate, Energy, and Environment. KEPCO is also conducting its own internal investigation to determine through which channels the employee data was posted on the external web page.


KEPCO has individually notified employees whose information was exposed via text messages and emails about the incident and preventive measures to avoid secondary damage. If reports of actual or anticipated damage are received in the future, KEPCO will proceed with the necessary investigation and provide remedies such as compensation.



KEPCO stated, "We plan to establish measures to prevent recurrence based on the results of the ongoing investigation," adding, "No customer information outside of the staff has been exposed, as such data is managed separately and securely in a dedicated system."


This content was produced with the assistance of AI translation services.

© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.

Today’s Briefing