Newsletter

Golfzon Faces Record Fine for Massive Data Breach: What Went Wrong?

Golfzon, Korea’s No. 1 screen golf company, leaked the personal information of 2.21 million people and was fined 7.5 billion won, the largest fine ever among domestic companies.

The Personal Information Protection Committee held a general meeting on the 9th and announced that it decided to impose a fine of 7.54 billion won and a fine of 5.4 million won on Golf Zone for violating personal information protection laws.

In November last year, a hacker stole the account information of Golfzon employees’ virtual private network, remotely accessed the file server within the business network, and leaked the files stored there to the outside world. As a result, the personal information of approximately 2.21 million service users and executives and employees was leaked, including their names, phone numbers, emails, dates of birth, and identification numbers. Among them, the resident registration numbers of 5,831 people and the account numbers of 1,647 people were leaked.

Golfzon neglected general monitoring and control while hastily rolling out a new virtual private network as the number of people working from home increased due to COVID-19. Personal information was stored unencrypted, and the obligation to destroy unnecessary personal information was also breached.

Kang Dae-hyun, head of the 1st investigation department of the Personal Information Commission, said, “With the application of the amended law, offline businesses were added to the fines subjects, and the upper limit of the fines was also increased Golf Zone Case, a heavy fine was imposed because both are given at the same time. “

#Koreas #screen #golf #company #Golf #Zone #fined #leaking #personal #information #million #people