▲ Major audit results by the Board of Audit and Inspection
An audit has revealed that security management at some government-funded science and technology research institutes is lax, with researchers taking out hard disk drives (HDDs) and leaking research data.
The Board of Audit and Inspection (BAI) released the results of its audit on the security management status of public computer networks today (July 28).
According to the BAI, under the security management guidelines for national research and development projects, research institutes are required to establish entry and exit procedures for laptops and external storage media used in carrying out security projects, and the use of unauthorized media is prohibited.
However, the BAI pointed out that HDDs installed in PCs are left to the autonomous management of research institutes without such security measures, raising concerns over security incidents such as the leakage of technical data due to unauthorized removal and taking out of HDDs.
In fact, the six research institutes subject to the audit (Korea Institute of Science and Technology, Korea Research Institute of Bioscience and Biotechnology, Electronics and Telecommunications Research Institute, Korea Atomic Energy Research Institute, Korea Institute of Science and Technology Information, and Korea Aerospace Research Institute) did not manage current HDD usage status, leaving security controls poor as they could not verify the quantity of used HDDs or whether they were taken out.
An analysis of HDD removal from internal PCs across five of the institutes (excluding the Electronics and Telecommunications Research Institute) between October 2024 and September 2025 by the BAI confirmed that 690 HDDs were removed. In particular, out of 39 HDDs used by former employees, 12 were untraceable or missing from the research institutes.
There was also a case where person A, who moved from the Korea Aerospace Research Institute to work as an associate professor at a university, removed an HDD containing 60,956 files—including four security projects—without deleting them while using the HDD without authorization, thereby taking out research data.
Consequently, the BAI notified the Ministry of Science and ICT and the Korea AeroSpace Administration to ban the use of unauthorized hard disks, establish entry and exit procedures, and conduct additional investigations and follow-up measures regarding the 12 hard disks presumed to have been taken outside.
Cases raising concerns over data leakage were also detected, such as research institute employees installing Network Attached Storage (NAS) servers enabling internet access from external locations like home to store and use work data, or installing virtual private network (VPN) software on internal and external terminals that allows internal network access from the outside.
An inspection of NAS servers at one institute revealed that 7 out of 26 servers were operating with 20,000 work files stored on them, and about 60,000 login attempts from overseas were detected over a period of about two months, leaving them exposed to hacking.
In addition, the adoption of antivirus software for servers operated by research institutes was low, and they remained vulnerable as security vulnerability checks were conducted on only some servers.
Furthermore, the BAI pointed out that although the latest security update advisories are posted on bulletin boards, whether actions are taken is not managed, leaving security updates undone on most major servers.
(Photo: Provided by the Board of Audit and Inspection, Yonhap News)
※ Please note: This article was translated by AI and may contain errors.
Video News
Video News
Video News