Video
[Anchor]
More than 30,000 phishing emails were sent under the name of a shopping mall that went out of business last year. It turned out to be sent by hackers. Customer information that remained intact even after the closure was stolen, yet customers were never even notified.
Reporter Choi Seunghun.
[Reporter]
Kim Yong-bin, a resident of Dobong-gu, Seoul, received an email on June 19 asking him to reactivate his Netflix membership.
The email stated that there was an issue with his payment and instructed him to click a button to restart his membership.
However, the sender's address was not Netflix, but Funshop.
It was an online shopping mall operated by a subsidiary of CJ ENM that had already ceased operations in March of last year.
[Kim Yong-bin / Funshop User: Funshop has shut down, so why are they sending me an email? I wondered if they might be operating under a different name, so I checked, and it said that all user data had been completely deleted.]
According to CJ's internal investigation, the email account of an employee at Appier, a marketing agency that was in charge of sending promotional emails for Funshop, was hacked.
Although two years had passed since the marketing contract ended and the employee had left the company, two customer email distribution lists still remained in the account.
The hackers used these lists to send out more than 30,000 phishing emails.
Appier failed to detect the sending of the phishing emails until SBS reporters first made inquiries, and did not inform the receiving customers of the risks.
[Appier Korea Employee: The person in charge is working from home, so they are not at their desk. (Then where are the superiors?) They are at the headquarters. (Where is the headquarters?) Taiwan.]
Appier reported the incident to the Korea Internet & Security Agency as a security breach rather than a personal data leak, claiming there was no evidence that hackers downloaded customer information.
However, further investigation revealed that a hacker had directly accessed the names, email addresses, and IP addresses of about 20 customers, and CJ ENM reported the incident to the Personal Information Protection Commission four days after becoming aware of the breach.
CJ ENM explained, "While the primary responsibility for this incident lies with the agency, we felt a moral responsibility as it involved our customers' data, so we reported it directly."
The Personal Information Protection Commission has launched a formal investigation, stating that under the Personal Information Protection Act, business agents must handle customer information securely, and outsourcing companies also have a duty to manage and supervise them.
(Photo: Yonhap News)
Reported by Choi Ho-jun and Lee Byung-joo | Video by Kim Jong-mi | Graphics by Kang Yoon-jung