
LocknLock, a plastic airtight container manufacturer, has been fined 503 million won plus an administrative fine of 5.4 million won over a data breach that exposed the personal information of 1.3 million people.
The Personal Information Protection Commission (PIPC) held a plenary meeting on the 8th and imposed a combined 701 million won in penalties and 5.4 million won in administrative fines on three companies — LocknLock, Ubase and Sunphoto — for violating the Personal Information Protection Act. The commission also ordered each company to publicly disclose the sanctions on its website.
LocknLock suffered two hacking attacks in May and November 2024, resulting in the leak of personal information belonging to approximately 1.3 million members as well as 1,111 records of employee personal data, the investigation found. The leaked information included members' names, mobile phone numbers and addresses, along with copies of employees' resident registration cards, driver's licenses and bank account documents.
The hacker exploited a vulnerability in the company's mail server to infiltrate internal systems and extract the member database, according to the findings. However, LocknLock failed to detect or respond to the abnormally large traffic generated during the exfiltration, and only became aware of the breach after receiving a blackmail email from the hacker.
The company also failed to apply patches for security vulnerabilities that had already been disclosed in 2022, used identical passwords for administrator accounts on key servers, and did not encrypt unique identification information, among multiple violations of its safety obligations, the investigation found. LocknLock was also found to have retained 49,466 records of employee personal data and purchaser information from closed stores without destroying them.
Ubase, which provides outsourced call center services for businesses, had the administrator account of its main website hacked in 2024. The hacker leaked the names, phone numbers, email addresses and company names of 1,852 users of its inquiry board, then posted the information on Telegram.
The investigation found that Ubase operated its administrator page to be accessible from outside without restricting access by internet protocol (IP) address, and left the page accessible with only an ID and password. The PIPC imposed a fine of 168 million won on Ubase and ordered it to disclose the sanction.
Sunphoto, a seller of photography and video equipment, also had its administrator account hacked in 2024, leading to the leak of personal information of approximately 170,000 members and 13 order records. The leaked items included names, user IDs, mobile phone numbers and gender. Notably, the hacker was confirmed to have used the leaked information to attempt voice phishing against one customer while impersonating a Sunphoto employee.
The PIPC determined that Sunphoto violated its safety obligations by failing to restrict administrator page access by IP address and failing to retain and manage access logs for its personal information processing system. The commission imposed a fine of 30 million won and ordered the company to disclose the sanction.






