2026 Day1Company (Fast Campus) — up to ~1M instructors/customers across 8 platforms
Data compromised
Instructor/customer PII; instructor RRN/account/card numbers for some; customer RRN/CI not held
Technical writeup
Day1Company, operator of Fast Campus and related edtech brands, confirmed a personal-data breach after abnormal intrusion into its IT management system on about 9 May 2026. Seoul Economic Daily (19 June 2026) reported eight platforms in scope—Fast Campus, Coloso, Zerobase, MyLight, Newspresso, Respeak, Shiny English, and Wannaspeak—with company estimates ranging from several hundred thousand up to about 1 million people. For some instructors, names, phone numbers, account numbers, resident registration numbers, and credit-card numbers were reportedly leaked; Day1Company said it does not hold customer RRNs/CI so those customer identifiers were not exposed. The firm said it learned of the breach on 8 June, reported to MSIT then PIPC, and is cooperating with police.
Root cause
Unauthorized intrusion into IT management systems