South Korea’s Institute for Basic Science confirmed that 1,894 administrative and research cases related to the Raon heavy-ion accelerator were transferred outside the organization around 2022 — and that the Heavy Ion Accelerator Research Institute did not learn of the leak until August 11, 2026. Materials submitted to the National Assembly’s science committee and reported September 18 describe a suspected insider: a former device-management team leader who left in July 2022.
That four-year detection gap is the story. A national science facility built with a reported state budget on the order of 1.5 trillion won discovered that nearly two thousand administrative and research cases had already left — years after the suspected transfer.
This is a verified IBS Raon insider data breach via parliamentary materials and Chosun reporting — not a dark-web rumor. Canonical record: https://breachhistory.com/ibs-raon/ibs-raon-insider2026. Primary English report: Chosun. Indexing: DataBreaches.net.
What happened
Raon is Korea’s Korean-type heavy ion accelerator project — a flagship rare-isotope science facility under IBS. IBS told lawmakers that data estimated to be administrative and research materials related to Raon left the institute externally. Detection came more than four years after the suspected transfer window.
The suspect named in reporting is a former team leader responsible for device management in the construction/establishment business unit who departed in July 2022. Public English coverage does not detail the exact exfiltration channel — USB, cloud sync, email, or otherwise — in the summaries used for this catalog.
What this is not: a ransomware encryption event or a credential-stuffing campaign against a consumer app. It is an insider-threat and governance failure around privileged scientific and administrative records.
Timeline
- ~2022 / July 2022: Estimated leak window; suspect leaves IBS.
- August 11, 2026: Heavy Ion Accelerator Research Institute confirms external transfer of ~1,894 cases.
- September 18, 2026: National Assembly materials / Chosun and DataBreaches coverage make the count public.
How the leak worked
This is an insider-threat case. The failure mode is classic: privileged access retained or abused around departure, combined with detection gaps that allowed years of silent exposure. Research institutes holding dual-use scientific and administrative files need departure checklists that revoke VPN, storage, and device-admin rights the same day employment ends — and that hunt for anomalous exports retrospectively.
Four years of undetected external transfer also implies weak or absent data-loss prevention on bulk exports, incomplete logging of privileged file access, or both. Even without naming the channel, the outcome tells security teams where to look: device-management shares, project document repositories, and accounts of departed staff with lingering rights.
Parliamentary oversight is how the number entered public view. That matters for other national labs: if your only detection path is a legislative inquiry, your DLP program is theater.
What data was exposed
1,894 cases described as administrative and research materials related to Raon. Public English reporting does not equate that figure to a person census of citizens; treat it as a file/case count of institutional records until IBS publishes a finer inventory.
Possible contents of such case files — without inventing a confirmed field list — commonly include vendor contracts, equipment inventories, project schedules, badge or access metadata, and experimental notes. Dual-use technical documents may require classification review beyond consumer phishing advice. Collaborators named in project administration should ask IBS whether their institution’s documents appear in the set.
Who is at risk
IBS staff and contractors whose admin records sat in the leaked set — watch for spear-phishing that cites Raon project codes or vendor invoices.
Research collaborators named in Raon project files — coordinate with your own research-security offices.
National security and dual-use reviewers who must assess whether technical documents require classification review.
IBS alumni who left around 2022 — rotate any passwords reused from institute systems; enable MFA everywhere.
Industry context
Large science facilities accumulate decades of vendor contracts, badge data, and experimental notes. An undetected four-year lag between leak and discovery is the headline governance failure. Compare operationally to other insider research leaks: detection debt often exceeds encryption strength.
Korea’s investment in Raon makes this a political as well as technical story. Lawmakers will ask how a device-management team leader could move 1,894 cases without triggering alarms. Other IBS centers and peer facilities should treat the public materials as a tabletop exercise: can you detect a similar export today?
Earlier controversies around improper use of Raon-related internal data in academic papers show that external transfer of institute materials has been a recurring governance friction — the September 2026 disclosure is a larger-scale confirmation that controls lagged the risk.
What IBS and lawmakers said
IBS submitted materials acknowledging the August 11 confirmation and the 1,894-case estimate. Legislative oversight via the science committee is how the figure entered public view. Further forensic or criminal outcomes were not detailed in the September 18 English coverage used here.
Until IBS publishes a finer inventory, do not invent Social Security–style identity theft narratives. The confirmed harm is unauthorized external transfer of institutional cases plus years of undetected exposure.
Was I affected?
If you were an IBS Raon employee, contractor, or collaborator with files in device-management or project administration systems before mid-2022, assume elevated risk until IBS says otherwise. If you only read Raon papers as an outside scientist with no admin relationship, you are not automatically in the 1,894 cases.
What you should do
- IBS alumni: rotate any passwords reused from institute systems; enable MFA everywhere.
- Watch for spear-phishing that cites Raon project codes, accelerator subsystems, or vendor invoices.
- Collaborators: ask IBS security whether your institution’s documents appear in the 1,894 cases.
- Research admins: audit privileged accounts of departed staff back to 2022.
- Enable DLP alerts on bulk exports from scientific file shares.
- Preserve evidence if you receive extortion referencing Raon documents.
- Report suspected misuse of research data through official IBS and national channels.
- Do not circulate unverified “full dump” links claiming Raon blueprints.
- Legal and research-security teams: inventory dual-use documents that may have left.
- Peer labs: run a tabletop on departed-privileged-user exports this quarter.
Canonical record and sources
IBS Raon insider leak catalog entry
Evidence-folder note 1 for IBS Raon: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 2 for IBS Raon: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 3 for IBS Raon: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 4 for IBS Raon: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 5 for IBS Raon: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 6 for IBS Raon: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 7 for IBS Raon: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 8 for IBS Raon: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 9 for IBS Raon: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 10 for IBS Raon: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 11 for IBS Raon: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 12 for IBS Raon: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 13 for IBS Raon: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 14 for IBS Raon: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 15 for IBS Raon: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 16 for IBS Raon: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 17 for IBS Raon: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 18 for IBS Raon: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 19 for IBS Raon: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 20 for IBS Raon: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 21 for IBS Raon: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 22 for IBS Raon: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 23 for IBS Raon: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 24 for IBS Raon: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 25 for IBS Raon: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 26 for IBS Raon: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 27 for IBS Raon: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 28 for IBS Raon: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 29 for IBS Raon: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 30 for IBS Raon: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 31 for IBS Raon: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.
Evidence-folder note 32 for IBS Raon: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.