[Anchor]
Phishing emails were sent to customers under the name of a closed shopping mall. Hackers stole customer email addresses that remained even after the business shut down. Although more than 30,000 emails were sent, no warnings were even given to the customers.
Reporter Choi Seung-hun has the details.
[Reporter]
Kim Yong-bin, a resident of Dobong-gu, Seoul, received an email on June 19 asking him to reactivate his Netflix membership.
The message stated that a payment issue had occurred and instructed him to click a button to restart his membership.
However, the sender address was not Netflix, but "Funshop."
It was an online shopping mall operated by a subsidiary of CJ ENM that had already ceased operations in March of last year.
[Kim Yong-bin / Funshop User: Funshop has shut down, so why are they sending me an email? I wondered if they might be operating under a different name, so I checked, and it said that all user data had been completely deleted.]
According to CJ's internal investigation, the email account of an employee at Appier, a marketing agency previously in charge of sending promotional emails for Funshop, was hacked.
Even though two years had passed since the marketing contract ended and the employee had left the company, two customer email distribution lists remained in the account.
The hacker used these lists to send more than 30,000 phishing emails.
Appier failed to detect the phishing email transmission until SBS reporters first inquired about it, and did not notify the receiving customers of the risk.
[Appier Korea Branch Employee: The person in charge is working from home, so they are not at their desk. (Then where are the superiors?) They are at the headquarters. (Where is the headquarters?) Taiwan.]
Appier reported the incident to the Korea Internet & Security Agency (KISA) as a security breach rather than a personal data leak, claiming there was no trace of the hacker downloading customer information.
However, further investigation revealed that the hacker directly viewed the names, email addresses, and IP addresses of about 20 customers, prompting CJ ENM to report the incident to the Personal Information Protection Commission (PIPC) four days after recognizing the breach.
CJ ENM explained, "While the primary responsibility for the incident lies with the agency, we felt a moral responsibility since it affected our customers, so we filed the report ourselves."
The PIPC has launched a formal investigation, stating that under the Personal Information Protection Act, business agents must securely process customer information, and consignors also have a duty to manage and supervise them.
(Camera: Choi Ho-jun, Lee Byung-joo | Video Editing: Kim Jong-mi | Design: Kang Yoon-jung)
※
Copying, redistribution, and unauthorized use in AI training are strictly prohibited.