LocknLock Fined 500 Million Won Over 1.3 Million-User Data Breach

LocknLock Leaks 1.3 Million Personal Records in Two Hacking Attacks Identical Admin Passwords Used, Known Vulnerabilities Left Unpatched

Technology|
|
By Lee Jin-seok
|
null - Seoul Economic Daily Technology News from South Korea

LocknLock, a plastic airtight container manufacturer, has been fined 503 million won plus an administrative fine of 5.4 million won over a data breach that exposed the personal information of 1.3 million people.

The Personal Information Protection Commission (PIPC) held a plenary meeting on the 8th and imposed a combined 701 million won in penalties and 5.4 million won in administrative fines on three companies — LocknLock, Ubase and Sunphoto — for violating the Personal Information Protection Act. The commission also ordered each company to publicly disclose the sanctions on its website.

LocknLock suffered two hacking attacks in May and November 2024, resulting in the leak of personal information belonging to approximately 1.3 million members as well as 1,111 records of employee personal data, the investigation found. The leaked information included members' names, mobile phone numbers and addresses, along with copies of employees' resident registration cards, driver's licenses and bank account documents.

The hacker exploited a vulnerability in the company's mail server to infiltrate internal systems and extract the member database, according to the findings. However, LocknLock failed to detect or respond to the abnormally large traffic generated during the exfiltration, and only became aware of the breach after receiving a blackmail email from the hacker.

The company also failed to apply patches for security vulnerabilities that had already been disclosed in 2022, used identical passwords for administrator accounts on key servers, and did not encrypt unique identification information, among multiple violations of its safety obligations, the investigation found. LocknLock was also found to have retained 49,466 records of employee personal data and purchaser information from closed stores without destroying them.

Ubase, which provides outsourced call center services for businesses, had the administrator account of its main website hacked in 2024. The hacker leaked the names, phone numbers, email addresses and company names of 1,852 users of its inquiry board, then posted the information on Telegram.

The investigation found that Ubase operated its administrator page to be accessible from outside without restricting access by internet protocol (IP) address, and left the page accessible with only an ID and password. The PIPC imposed a fine of 168 million won on Ubase and ordered it to disclose the sanction.

Sunphoto, a seller of photography and video equipment, also had its administrator account hacked in 2024, leading to the leak of personal information of approximately 170,000 members and 13 order records. The leaked items included names, user IDs, mobile phone numbers and gender. Notably, the hacker was confirmed to have used the leaked information to attempt voice phishing against one customer while impersonating a Sunphoto employee.

The PIPC determined that Sunphoto violated its safety obligations by failing to restrict administrator page access by IP address and failing to retain and manage access logs for its personal information processing system. The commission imposed a fine of 30 million won and ordered the company to disclose the sanction.

Original reporting by Lee Jin-seok for Seoul Economic Daily.

AI-translated from Korean. Quotes from foreign sources are based on Korean-language reports and may not reflect exact original wording.

Translated by AI on Jul 9, 2026View Korean originalTranslation Policy

Watch · Seoul Economic Daily

More →
5:23

AI KEY

Preview
Korean Corporate Intelligence HubKOSPI · KOSDAQ · 12 sectors

A live, cap-weighted view of every KOSPI and KOSDAQ sector, with same-day Korean reporting distilled by company — built for foreign investors, correspondents and analysts who need to scan Korea before the next session.

Korea Chaebol Tree

Preview
Families Behind the GroupsKFTC May 2026 · DART filings

An English-first interactive map of Samsung, SK, Hyundai, LG and Lotte — built for foreign investors, correspondents and analysts. Korea translates companies into English. We translate the families behind them.

SIGNAL

Pre-register
English Edition · Capital MarketsM&A · IPO · PE · Fund Flows

Pre-register for SIGNAL English Edition — a premium subscription bringing Korean capital markets coverage (M&A, IPOs, private equity, fund flows) to global institutional investors. First access to the 50% introductory rate.