2026 Government24 — Interior Ministry PIPC fine ₩273M (1,233 people)
Data compromised
School records, tax certificates, names/affiliations, unique identifiers in issued documents
Technical writeup
South Korea’s Personal Information Protection Commission resolved in May 2026 to fine the Ministry of the Interior and Safety ₩273 million (plus smaller administrative penalties) after personal-data leaks through Government24 (정부24) and related systems affected 1,233 individuals. Seoul Economic Daily summarized PIPC findings: source-code errors in civil-document issuance flows (NEIS school records and tax certificates) in April 2024 wrongly exposed other people’s documents; a May 2025 authentication-module flaw allowed looking up others’ resident-registration-card issuance status; and work-board files on the Gongyunuri system were indexed by Google. Notification to affected parties after the April 2024 recognition exceeded the statutory 72-hour window. Separate contractor Misotech NAS issues were fined in the same plenary package but are distinct from the Government24 portal failures.
Root cause
Government portal development errors and authentication/security mismanagement (per PIPC)