More than 30,000 phishing emails were sent under the name of an online shopping mall that went out of business last year. It turned out that the emails were sent by a hacker. Customer information that remained intact even after the business closed was stolen, and customers were not even notified.
Reporter Choi Seung-hun has the details.
[Reporter]
Kim Yong-bin, a resident of Dobong-gu, Seoul, received an email on July 19 asking him to reactivate his Netflix membership.
The email stated that there was a problem with his payment and instructed him to click a button to restart his membership.
However, the sender's address was not Netflix, but "Funshop."
It was an online shopping mall operated by a subsidiary of CJ ENM that had already terminated its operations in March of last year.
[Kim Yong-bin / Funshop User: Funshop has shut down, so why are they sending me an email? I wondered if they started operating under a different name, so I checked, only to find that user data had been completely deleted.]
According to CJ's internal investigation, the email account of an employee at Appier, the marketing agency responsible for sending Funshop's promotional emails, was hijacked by a hacker.
Although two years had passed since the marketing contract ended and the employee had resigned, two customer email distribution lists still remained in the account.
The hacker used these lists to send more than 30,000 phishing emails.
Appier failed to detect the transmission of the phishing emails until SBS reporters first made inquiries, and did not notify the recipient customers of the risks.
[Appier Korea Branch Employee: The person in charge is working from home, so they are not at their desk. (Then, what about the superiors?) They are at the headquarters. (Where is the headquarters?) Taiwan.]
Appier reported the incident to the Korea Internet & Security Service (KISS) as a security breach rather than a personal data leak, claiming there was no evidence that the hacker downloaded customer information.
However, additional investigations revealed that a hacker had directly accessed the names, email addresses, and IP addresses of about 20 customers. CJ ENM reported the breach to the Personal Information Protection Commission four days after becoming aware of it.
CJ ENM explained, "While the primary responsibility for this incident lies with the agency, we felt a moral obligation as it involved our customers' data, so we reported it directly."
The Personal Information Protection Commission has launched a formal investigation, stating that under the Personal Information Protection Act, business agents must securely process customer information, and consignors also have a duty to manage and supervise them.
[Notice]
Appier stated, "It has been determined that an unauthorized third party made unauthorized use of the Funshop manager's account used on our platform."
(Video reporting: Choi Ho-jun and Lee Byung-joo | Video editing: Kim Jong-mi | Design: Kang Yoon-jung)
※ Please note: This article was translated by AI and may contain errors.
Video News
Video News
Video News
Video News