← Blog

Fast Campus Breach: Day1Company Flags Up to 1M

Share on X

South Korean edtech operator Day1Company—best known for Fast Campus—disclosed a personal-data breach after attackers hit its IT management systems around 9 May 2026. Seoul Economic Daily reported company estimates ranging from several hundred thousand people up to about 1 million.

Eight platforms were named: Fast Campus, Coloso, Zerobase, MyLight, Newspresso, Respeak, Shiny English, and Wannaspeak.

What was exposed

For some instructors, press accounts said names, phone numbers, bank account numbers, resident registration numbers, and credit-card numbers were taken. Day1Company said it does not store customer resident registration numbers or connecting information (CI), so those customer identifiers were not part of the leak.

Timeline

The company said it became aware on 8 June 2026, reported to the Ministry of Science and ICT, then followed up with PIPC on 11 June, and is cooperating with police.

Who is at risk

Instructors on the eight platforms face the highest financial-identity risk if RRN and card data were in their rows. Students and other customers should still assume contact details and account credentials may be abused for phishing.

Action items

  1. Change passwords on every Day1Company brand you use; turn on MFA.
  2. Instructors: monitor bank and card accounts used for payouts; consider a credit freeze if RRN was on file.
  3. Ignore “refund” or “security review” messages that demand OTPs.

Canonical record

https://breachhistory.com/day1company/fast-campus-day1company2026Seoul Economic Daily.