Video
[Anchor]
Amid growing fallout from personal data leaks in the financial sector, an incident has occurred in which the personal information of all Korea Electric Power Corporation (KEPCO) employees, numbering over 20,000, was exposed externally. KEPCO stated, "Information on general customers is safe."
Reporter Kwon Ran has the details.
[Reporter]
KEPCO confirmed around 4:00 PM on October 1 that employee personal information had been exposed on an external webpage.
Information including the names, affiliations, phone numbers, and email addresses of all 24,000 employees was made public.
However, it was determined that unique identification information such as resident registration numbers or sensitive information was not included.
KEPCO immediately blocked access to internal systems related to employee personal information and requested the operator of the external webpage to delete the exposed information.
However, the information was not deleted until around 12:00 AM yesterday (October 3), taking about 32 hours from the time of detection.
The exact cause of the exposure has not yet been confirmed.
Since the place where the information was exposed was an external webpage rather than KEPCO's own homepage, the company is investigating various possibilities with related organizations, including whether it was a mistake by an outsourced data management company or an external attack.
Regarding the possibility of hacking using AI tools, which has recently occurred consecutively in the financial sector, KEPCO took a cautious stance, stating, "No signs of hacking have been identified so far," and referred to the incident as an "exposure" rather than a "leak."
KEPCO emphasized that general customers' personal information is managed in a separate dedicated system and was not exposed in this incident.
(Video by Lee Seung-jin)