
The Personal Information Protection Commission announced on the 27th that it held a plenary meeting and decided to impose a fine of 73.5 million won and an administrative penalty of 4.8 million won on two business entities under HD Hyundai Group.
According to the Personal Information Protection Commission, unidentified hackers exploited a vulnerability in the mobile device management server operated by HD Hyundai Heavy Industries Co., Ltd. around March 2024, uploaded a web shell file, and then accessed the internal work system of HD Construction Machinery Co., Ltd., which was capable of communicating with that server. This resulted in the leakage of personal information belonging to 9,503 individuals, including names and employee IDs of employees and cooperative company staff at HD Construction Machinery Co., Ltd.
Investigations revealed that the mobile device management server of HD Hyundai Heavy Industries Co., Ltd. lacked adequate safety measures against file upload vulnerabilities, which were exploited as a channel for the data leak.
Furthermore, it was confirmed that while there was no business necessity for a connection between the mobile device management server of HD Hyundai Heavy Industries Co., Ltd. and the internal work system of HD Construction Machinery Co., Ltd., access restrictions between the two companies' systems were not implemented, allowing hackers to access the personal information processing system of HD Construction Machinery Co., Ltd. through that of HD Hyundai Heavy Industries Co., Ltd.
The Personal Information Protection Commission imposed a fine of 73.5 million won on HD Construction Machinery Co., Ltd., where employees' and staff members' personal information was leaked, and an administrative penalty of 4.8 million won on HD Hyundai Heavy Industries Co., Ltd., whose system was used as the channel for the leak.
This data breach occurred because the personal information processor neglected measures regarding vulnerabilities in its personal information processing system and failed to implement access control measures for servers that did not require business connections.
The Personal Information Protection Commission urged personal information processors to regularly review security measures to prevent personal information from being leaked or exposed through web vulnerabilities and to restrict access rights to personal information processing systems via IP addresses, among other methods, to block and control unnecessary access in order to prevent illegal access and security incidents.