← Gabia

2026 Gabia (Korea) — web-service request-validation flaw; 2,998 customers’ PII

2026 3.0K records affected Share on X

Data compromised

Per Gabia: names, user IDs, email addresses, and mobile phone numbers for 2,998 customers (as of Sep 23 3pm KST). Passwords not confirmed leaked; count/fields may change with investigation. Reported to PIPC and KISA; notifying customers by email/SMS.

Technical writeup

Verified company notice — Gabia (Sep 23, 2026): external unauthorized access on Sep 21 ~11:45; detected 13:05 same day. Attacker used inadequate external-request validation in certain web-service features to access internal systems and exfiltrate customer PII. Confirmed: 2,998 customers — names, IDs, emails, mobile numbers; passwords not confirmed leaked. Path/accounts blocked; logs preserved; PIPC/KISA notified. recordsAffected 2998; companyConfirmed true.

Root cause

External attacker exploited insufficient validation of external requests in some Gabia web-service functions to reach internal systems (company notice Sep 23, 2026)

References