
Telecommunications companies, OTT (online video service) providers, and platform operators—including LG Uplus, TVING, Gangnam Eonni, Duo, Baemin, and Toss Payments—once again expressed their apologies following customer personal data breach incidents. While company representatives repeatedly apologized for questions from the National Assembly regarding the circumstances of the data leaks and suspicions of investigation cover-ups, they did not disclose specific stances on additional damage compensation measures.
During the afternoon questioning session at the Ministry of Science and ICT / Korea Communications Commission audit held at the Seoul Yeouido National Assembly building on the 6th, lawmakers questioned company representatives involved in recent customer personal data breach incidents.
Democratic Party of Korea lawmaker Lee Jung-heon called to the front Choe Ju-hee, CEO of TVING; Kim Jung-hoon, CISO (Chief Information Security Officer) of Woowa Brothers; Im Han-wook, CEO of Toss Payments; Hong Seung-il, CEO of Healing Paper (Gangnam Eonni); and Park Soo-kyung, CEO of Duo. Lee (Rep.) asked about the TVING account data breach, Baemin customer information leak, failure to detect anomalies in Toss Payments, leakage of sensitive user information on Gangnam Eonni, and the exposure of member profiles on Duo, respectively.
In response, Choi Ju-hui (CEO) apologized, stating, "I have fully realized our negligence regarding security," while CISO Kim Jung-hoon replied, "I deeply feel a sense of responsibility." Lim Han-uk (CEO) and Hong Seung-il (CEO) also bowed their heads, saying, "There were shortcomings" and "We will expand our personal information protection personnel and security investments." Park Su-gyeong (CEO) stated, "I apologize for failing to properly protect the information."
Questioning directed at Hong Gwan-hee, Senior Executive Vice President and Head of the Information Security Center at LG Uplus, focused on suspicions of cover-up that arose during the investigation of last year's LG Uplus personal data infringement incident, as well as the company's policy on waiving early termination fees.
Han Jun-ho (Rep.), the ruling party’s floor leader in the Science and ICT Committee, pointed out to Senior Executive Vice President Hong, "There are aspects of LG Uplus's incident response that I simply cannot understand," noting, "The Korea Internet & Security Agency (KISA) notified us of the circumstances of the infringement incident on July 19 last year, and an operating system (OS) reinstallation was carried out on the problematic server on August 12."
Han (Rep.) stated, "If it is a server, the original state should be preserved before reinstalling the OS," and pointed out, "They claim to have submitted a server image (copy) before reinstallation, so why did the government's joint civil-military investigation team officially announce that 'the traces of infringement and attack paths cannot be verified due to the OS reinstallation'?" In response, Senior Executive Vice President Hong replied, "It is difficult to answer as it is an ongoing criminal investigation."
Fellow party member Lee Hun-gi (Rep.) also addressed Senior Executive Vice President Hong, stating, "On December 9 last year, the Ministry of Science and ICT requested a criminal investigation on suspicion of obstructing the performance of official duties by deception," and explained, "The decision to request an investigation was made because it was difficult to confirm isolation from leakage due to server disposal and other factors in personal data on July 29 last year, and the investigation is currently underway." He continued, "If it constitutes intentional cover-up or destruction of evidence, I believe they have abandoned their responsibility for user protection," and argued, "If it falls under the company's fault, early termination fees (for device contract rates, etc.) are waived according to the terms of service."
Meanwhile, on this day, committee members demanded additional damage compensation measures from the representatives of these personal data breach companies. Democratic Party lawmaker Hwang Jung-a questioned Hong Seong-il (CEO), Park Su-yeong (CEO), and Choi Ju-hui (CEO) regarding the sensitivity and severity of the leaked personal information and the circumstances of the leaks, stating that the company's compensation was insufficient compared to the severity of the personal data breach. Hwang (Rep.) criticized, saying, "Gangnam Eonni's entire compensation is 50,000 points, and Duo said 'uniform compensation is difficult,'" adding, "TVING is refusing to submit documents citing an ongoing investigation, despite it being the largest-scale personal data theft in history."
In response, Hong Seung-il (CEO) replied, "We are trying to fulfill our responsibility without avoiding methods we can take and tasks we must do," and stated, "We will provide damage compensation or related legal support for secondary damages caused by the leakage of sensitive information." Park Su-yeong (CEO) said, "I urgently acknowledge my mistake regarding the fact that valuable information was not properly protected," adding, "The compensation members desire is to receive the best possible marriage information service and find a good partner. Our employees will truly strive to reform themselves completely."