Netmarble told members on 27 November 2025 that a hacking incident discovered on 22 November exposed personal data for 6,110,000 PC game portal users—including dormant accounts. Names, birthdates, and encrypted passwords were in the confirmed set. Resident registration numbers were not, the company said.
That headline number was not the whole dump. Netmarble also described more than 31 million IDs with encrypted passwords where names and birthdates had already been stripped, plus tens of thousands of PC-cafe franchisee and employee records.
What happened
Attackers reached Netmarble’s PC portal systems. Chosun Ilbo reported the company took nearly 72 hours to report the personal-data leak to authorities after detection—inside the privacy-law window for data leaks, Netmarble argued, but still slow enough to draw political criticism.
What was exposed
- 6.11M members: names, dates of birth, encrypted passwords
- 31M+ non-identifying ID/password rows (PII already deleted)
- ~66k historical PC-cafe franchisee contacts
- ~17k current/former employee name/DOB/email rows
What was not exposed
Netmarble said unique identifiers such as resident registration numbers and other sensitive identity documents were not compromised in the member set.
Action items
- Change Netmarble and related game-launcher passwords; enable MFA everywhere reuse is likely.
- Treat “Netmarble security” emails and DMs as phishing until verified in-app.
- Franchisees and staff named in notices should watch business-email compromise.
Canonical record
https://breachhistory.com/netmarble/netmarble-pc-portal2025 — reporting via Chosun Ilbo.