2026 Duo (South Korea) — matchmaking data leak (~430k); PIPC fine ~₩1.2B (~$830k)
Data compromised
Account credentials, PII, and sensitive self-reported matchmaking attributes per Reuters and Yonhap summaries
Technical writeup
South Korea’s major marriage-brokerage brand Duo (operated in the matchmaking / wedding sector) was the subject of a January 2025 unauthorized intrusion via an employee computer that exposed a large set of members’ and former members’ personal data—in reports on the order of ~430,000 people—including credentials, contact details, and sensitive matchmaking profile fields. In April 2026, the Personal Information Protection Commission (PIPC) issued a large administrative fine (about 1.2 billion KRW, roughly US$800–830k in contemporaneous press conversions) and corrective orders, citing weak access controls, delayed notification, and over-retention. Regulatory reporting treated the episode as a serious PIPA enforcement story rather than a new technical intrusion in 2026.
Root cause
Unauthorized database access through employee environment; inadequate access controls and governance per PIPC