▲ People Power Party Lawmaker Choi Hyung-du
Lawmaker Choi Hyung-du (Masan Happo, South Gyeongsang Province), who serves as the People Power Party’s ranking member on the National Assembly’s Science, ICT, Broadcasting and Communications Committee, addressed the recurring leak incidents involving Connecting Information (CI), stating, "Even if CI—which was introduced to replace resident registration numbers—is leaked, citizens are virtually forced to use the exact same value for life." He urged, "We must promptly introduce an expiration date for CI and establish institutional mechanisms to renew already-leaked CI."
CI is unique identification information generated by identity verification agencies based on a resident registration number to identify the same individual online.
It was introduced to verify an individual’s identity and confirm whether users across different platforms are the same person without directly using their resident registration numbers, and it is widely used for member identification and management across online services.
However, because CI virtually remains unchanged unless a person’s resident registration number changes, concerns have been raised that individuals must continue using the compromised identification information even after a leak.
While passwords can be changed upon being leaked, institutional means for users to directly change or discard their CI are limited.
Lotte Card, Tving, CU, Woori Bank... Recurring CI LeaksAccording to parliamentary audit inquiry documents prepared by Representative Choi Hyung-du's office, approximately 2.97 million people's CI was leaked from Lotte Card in August 2025, and personal information leak incidents involving CI continued to occur in the first half of 2026 at companies including Tving, CU, and Woori Bank.
Choi pointed out that because CI has been widely used across various online services for about 15 years, individual corporate responses to incidents may not be sufficient.
He stressed the need to assess the likelihood that CI belonging to a significant portion of the public has already been leaked through multiple personal information breach incidents, and to comprehensively assess the leak status and follow-up measures for each incident.
"Must Leaked CI Still Be Used?"... Structural Limits of Permanent Identification DataAlthough CI is designed so that resident registration numbers cannot be reverse-calculated from it alone, risks from a personal data protection perspective are raised because the exact same value is used across multiple services over long periods.
In particular, when CI is used as an identifier connecting databases of different services, it could potentially be combined with other personal information to identify individuals or link user information across different platforms.
Concerns have also been raised that if leaked CI cannot be altered, risks stemming from data breaches could persist over a prolonged period.
"If a substitute introduced to restrict the use of resident registration numbers has virtually turned into a permanently maintained identifier, we must fundamentally reexamine the safety of this system," Choi emphasized. "Effective measures are needed to either issue new values to citizens whose CI has been leaked or invalidate existing values."
Considering Max 1-Year CI Validity... Measures Needed to Renew Existing Leaked CIChoi suggested that setting a maximum validity period of one year for CI needs to be considered to reduce the risks associated with long-term, fixed use.
The intention is to establish a management framework where a new CI is issued through an identity verification process once the validity period expires, ensuring the previous CI can no longer be used in the same manner.
However, actual implementation requires comprehensive review of cross-service linking, system upgrades by identity verification agencies, transition costs for businesses, and methods for processing existing data.
He also pointed out that applying validity periods only to newly issued CI will not resolve the risks stemming from past leak incidents.
He noted that authorities should also explore plans to batch-renew or phase-renew already-leaked CI within a set timeframe, prioritizing businesses that experienced large-scale leaks.
Referring to cases such as the periodic renewal of personal customs clearance codes, Choi stated that institutional improvements should be reviewed to enable the modification and renewal of CI after a leak.
However, because the characteristics and scope of use of CI differ, he stressed that service continuity and personal information protection effectiveness must both be taken into account when actually adopting such measures.
"Commission Must Not Stop at Merely Reviewing... Must Submit Roadmap Before Comprehensive Audit"Choi called on the Broadcasting, Media and Communications Commission to devise a concrete roadmap for institutional improvement, including whether to adopt an expiration date for CI, the appropriate validity period, renewal measures for already-leaked CI, a schedule for revising related administrative notifications, system upgrade plans for identity verification agencies, and transition plans for businesses.
"As CI serves as core information identifying individuals online in place of resident registration numbers, we must not overlook a structure where people are virtually forced to keep using the same value even after it leaks," Choi said. "Instead of viewing recurring leaks merely as individual security lapses by companies, we must examine the structural risks inherent in the CI system itself."
He further urged, "The commission must not stop at simply replying that it will review institutional improvements; it must submit a concrete implementation plan to my office before the comprehensive parliamentary audit."
※
Copying, redistribution, and unauthorized use in AI training are strictly prohibited.