
Personal information belonging to about 5,000 union members at Kia (000270), including employee numbers and phone numbers, was leaked through an outside online training vendor. The breach puts corporate security under fresh scrutiny, extending a run of hacking incidents that has centered on financial firms and public institutions to the industrial sector.
The data on union members at Kia's Gwangmyeong plant was exposed during a hack of Malgunsoft on the 19th of last month, the Kia labor union said on the 7th. The union at the Gwangmyeong plant had outsourced system and server management for its online training to Malgunsoft, and an outside hacker broke into the vendor's server, where the members' personal data was stored.
The estimated scope of the damage covers personal information on roughly 5,000 union members at the Gwangmyeong plant. Their names, employee numbers and phone numbers were leaked. The union is also investigating indications that data on some workers at the Hwaseong and Gwangju plants was exposed.
Malgunsoft, which manages outsourced online training, confirmed that an outside party gained abnormal access to its internal server on the 19th of last month and installed a backdoor, a type of malicious program. The attacker reached a database holding member records, leaking personal information on employees of Malgunsoft's client organizations. About 20 organizations had data exposed in the breach, including the Anti-Corruption and Civil Rights Commission, the Ministry of National Defense and the Kia union.
After a full review, Malgunsoft confirmed that data on members of the Kia Gwangmyeong union had also been leaked and notified the union on the 25th of last month. The following day, the union sent a text message to all members confirming the breach and advised them not to click links in texts or messages from unidentified senders.
No actual harm from the hacking has been identified so far. "The phone numbers were leaked in encrypted form, so it is unlikely that actual damage will occur," a Kia union official said. "The union is also carrying out follow-up measures, including drawing up security plans."
Industry observers say the Kia case should prompt companies to strengthen oversight of outside contractors as well as their own security systems. Even companies that do not hold the data themselves can face large-scale leaks if a supplier or a vendor handling the information has a security gap.






