2024 Ttareungyi (Ddareungi) — 4.62M Seoul bike-share riders (2026 charges/follow-up)
Data compromised
Rider PII
Technical writeup
Seoul’s public bike-sharing service Ttareungyi / Ddareungi (따릉이), operated with Seoul Facilities Corporation, suffered a large personal-data breach affecting about 4.62 million riders (trade press also cited ~4.5M). Leaked fields reported in Korean coverage included rider identity and contact attributes typical of membership systems. In January–February 2026, Korean outlets and UPI/Yonhap amplified the case again as prosecutors charged teenagers and as reporting alleged the city had known about the 2024 compromise earlier than the public narrative suggested. Catalogued as the 2024 intrusion with 2026 enforcement/publicity follow-up—not a separate new breach.
Root cause
Unauthorized access
References
- https://www.claimdepot.com/data-breach/ttareungyi-2026
- https://www.upi.com/Top_News/World-News/2026/01/30/korea-Seoul-data-breach-bike-sharing-service-45-million-users/5221769765922/
- https://www.koreaherald.com/article/10681464
- https://www.helpnetsecurity.com/2026/02/24/south-korean-teens-bike-service-cyberattack-charges/