How Many Times Has My Information Been Leaked… Personal Data Breaches Exceed Population Scale in a Year

Photo of author

By Global Team

Key points

▶ The number of people affected by personal information leaks totaled 48.19 million last year. This year, the figure has already reached 43.88 million in the first half alone.

▶ The number of people affected rose sixfold last year, after totaling 14.64 million in 2023 and 8 million in 2024.

▶ The number of cases resulting in sanctions fell from 158 in 2023 to 119 in 2024 and 115 last year. There were fewer incidents, but more people were affected.

Photo: Solution News Magnific
Photo: Solution News Magnific

The amount of personal information leaked in a single year has reached a scale comparable to South Korea’s population. According to data provided by the Personal Information Protection Commission to Rep. Kim Seon-min of the Rebuilding Korea Party on the 28th, the number of people affected by personal information leaks rose from 14.64 million in 2023 and 8 million in 2024 to 48.19 million last year. In the first half of this year alone, the figure reached 43.88 million—already more than 91% of last year’s total.

The figures cover cases reviewed and sanctioned by the commission. Because one person may be counted in multiple incidents, they do not represent the number of distinct victims. Even so, for two consecutive years, the amount of personal information exposed has approached the size of the country’s population. Most of the affected people were linked to private-sector organizations: 47.68 million, or 99% of the total, last year.

◆ Fewer incidents, more people affected

The number of cases sanctioned for personal information leaks fell each year, from 158 in 2023 to 119 in 2024 and 115 last year. There were 75 cases in the first half of this year. Yet the number of people affected increased sixfold, meaning each incident reached far more people.

The increase followed a series of major incidents affecting more than 10 million people. After last year’s leak of SK Telecom SIM-card information, data belonging to 37.5 million people was exposed at Coupang. In June, the commission imposed a record fine of 624.6 billion won on Coupang. Of the 1.115 trillion won in fines imposed during the commission’s first six years, 745.6 billion won was imposed between January and July this year. Penalties have become heavier, but leaks continue.

◆ TVING leak exposed information that cannot be changed

The TVING hack in May illustrates the pattern behind recent large-scale personal information leaks. An investigation by the Ministry of Science and ICT found that a total of 39.54 million accounts were exposed, including 7.26 million accounts registered directly with TVING, 8.63 million CJ ONE integrated-member accounts, 22.47 million accounts registered through social media services such as Naver, Kakao, Facebook, Apple and X, and 1.18 million other accounts. The total includes duplicate accounts.

The range of exposed information was also broad. It covered 70 types of data across 20 categories, including user IDs, one-way encrypted passwords, CJ ONE integrated IDs, names, mobile phone numbers, email addresses, dates of birth and connecting information (CI). The information exposed varied by account.

Rep. Kim warned that a succession of large-scale leaks is increasing the risk of secondary harm from combining or reconstructing leaked information. He cited voice phishing, identity theft and financial fraud as examples.

◆ “Leaks cannot be prevented through cleanup after the fact”

Rep. Kim said that even allowing for the possibility that one person’s information may be leaked multiple times, the exposure of information on a population-sized scale in a single year should not be taken lightly. Personal information is difficult to recover once exposed and can lead to secondary harm, he said, adding that it cannot be protected through a system that responds only after an incident occurs.

He called for two measures: strengthening companies’ responsibility to protect personal information, and establishing a government oversight and management system focused on preventing leaks rather than merely punishing them. Repeated incidents, he said, should not be viewed solely as the result of individual companies’ poor management.

Lawmakers from both the ruling and opposition parties have voiced similar concerns. On the 27th, Rep. Park Seong-hoon of the People Power Party said that 140 million pieces of personal information had been leaked in the six years since the commission was established, with hacking and operational errors accounting for nearly equal numbers of incidents—276 and 275, respectively. He called for a shift away from belated penalties imposed after an incident toward preventive oversight that prioritizes inspections of large, high-risk platforms.

Individuals also need to take precautions. If you use the same password on other websites as on a service affected by a leak, change it immediately. Using a different password for each site is a basic safeguard. Regularly check whether mobile phones or bank accounts have been opened in your name, and be especially cautious about calls or text messages from people who know personal details such as your name and date of birth.

Information such as CI, which users cannot readily change themselves, is particularly difficult to recover once exposed. Alongside preventing leaks in the first place, it is important to make a habit of checking for signs that exposed information is being used for secondary harm, such as identity theft or financial fraud.