HD Hyundai Units Fined Over Employee Data Breach

Hackers Exploited Server Flaw to Enter Corporate System Data on 9,503 Employees and Contractor Staff Stolen

Technology|
|
By Lee Jin-seokljs@sedaily.com
||
Song Kyung-hee (center), chairperson of the Personal Information Protection Commission, presides over the commission's 17th plenary meeting at the Government Complex Seoul on Nov. 26. Photo courtesy of the PIPC - Seoul Economic Daily Technology News from South Korea
Song Kyung-hee (center), chairperson of the Personal Information Protection Commission, presides over the commission's 17th plenary meeting at the Government Complex Seoul on Nov. 26. Photo courtesy of the PIPC

Two HD Hyundai Group affiliates have been penalized for failing to take adequate security measures, allowing employee personal data to be leaked.

The Personal Information Protection Commission said on the 27th that it held a plenary meeting on the 26th and decided to impose a fine of 73.5 million won on HD Construction Equipment and an administrative penalty of 4.8 million won on HD Korea Shipbuilding & Offshore Engineering for violating personal data protection rules.

According to the commission's investigation, a hacker breached a mobile device management server operated by HD Korea Shipbuilding & Offshore Engineering in March 2024 by exploiting a vulnerability in the system. The hacker then accessed an internal business system at HD Construction Equipment, which was able to communicate with that server, and stole personal data including the names and employee numbers of 9,503 HD Construction Equipment employees and contractor staff.

The commission found that the mobile device management server at HD Korea Shipbuilding & Offshore Engineering had inadequate safeguards against a file upload vulnerability, which was exploited as the entry point for the hack. It also found that the two companies had not restricted access between their networks even though the systems did not need to be linked for business purposes, opening a path for the intrusion.

"Personal data handlers must regularly review security measures to prevent the leak or exposure of personal data through web vulnerabilities," a commission official said. "To block illegal access and security incidents, it is necessary to thoroughly cut off and control unnecessary system access through measures such as IP restrictions."

Companies in this story

Original reporting by Lee Jin-seok for Seoul Economic Daily.

AI-translated from Korean. Quotes from foreign sources are based on Korean-language reports and may not reflect exact original wording.

Watch · Seoul Economic Daily

More →
3:02

AI KEY

Preview
Korean Corporate Intelligence HubKOSPI · KOSDAQ · 12 sectors

A live, cap-weighted view of every KOSPI and KOSDAQ sector, with same-day Korean reporting distilled by company — built for foreign investors, correspondents and analysts who need to scan Korea before the next session.

Korea Company Atlas

Preview
Market Ontology · The Feedback LoopKFTC 2025 · 92 groups · 121,954 articles

An English ontology of the Korean market — how companies, the media, the government and the National Assembly move each other in a loop. Korea's named controlling persons and designated business groups are a mechanism, not a risk to be priced blind.

SIGNAL

Now live
English Edition · Capital MarketsM&A · IPO · PE · Fund Flows

SIGNAL English Edition is live — Korea's deal desk reporting in English. M&A, IPOs, private equity and fund flows, covered daily for global institutional investors. Browse free; subscriber-only scoops at the 50% intro rate.