| Title | The PIPC Sanctions Incruit over Data Breach | ||
|---|---|---|---|
| Department | Date | 2025.10.24 | |
| Attachment | press release The PIPC Sanctions Incruit over Data Breach.pdf | ||
| Page URL | https://pipc.go.kr/eng/user/ltn/new/noticeDetail.do?bbsId=BBSMSTR_000000000001&nttId=2896 | ||
| Contents |
Press Release The PIPC Sanctions Incruit over Data Breach - A massive data leak of 7.3 million job seekers, including their resumes - The recurrence of a data breach after the sanction in July 2023 - Correction orders: Designation of a dedicated CPO and submitting a concrete plan within sixty days to prevent future data breaches, including the support of redress and remedies for data subjects - The PIPC will conduct compliance monitoring to eradicate recurring data breaches and establish a plan to improve the penalty system by enabling punitive measures
October 23, 2025
The Personal Information Protection Commission (PIPC) held its 22nd plenary meeting of 2025 and resolved to sanction Incruit Corporation (Incruit) for violations of the Personal Information Protection Act (PIPA) on October 22, 2025. The administrative sanctions imposed are as follows:
● A penalty for violations (Gwajinggeum) of KRW 463 million ● Correction orders: Designation of a dedicated Chief Privacy Officer (CPO); Establishment a concrete plan to prevent recurring data breaches, including redress and remedies for data subjects
Incruit, an online employment website, had a data breach affecting approximately 7.3 million users in February 2025, due to an attack by unidentified hackers. After Incruit reported its data breach, the PIPC initiated an investigation. The investigation results showed that Incruit failed to comply with the requirement to put safeguards in place as stipulated in the PIPA. This incident marks a recurrence of a data breach, as Incruit was sanctioned by the PIPC in July 2023 for insufficient access control measures. The following explains found as a result of the PIPC’s investigations.
1. Violations and Sanctions
Unidentified hackers accessed Incruit’s online network, injecting malicious code into the PCs of personal data handlers in January 2025. Then the hackers hijacked an account to gain access to its internal system. This intrusion led to a month-long data leak of 7.3 million users, including names, addresses, phone numbers, educational backgrounds, work histories, resumes or cover letters, certificate copies, disabilities, military service information, employment subsidies, and other employment-related files that amount to a total of 438 gigabytes from January 19, 2025, to February 23, 2025.
The investigation results unveiled that anomalous database access records outside business hours and unusually high traffic were generated as clear indicators of a data breach. However, Incruit failed to take access control measures and only became aware of the data breach two months later after receiving a blackmail note from the hackers. The company also failed to take access control measures for the Internet access networks of personal data handlers’ PCs.
2. Sanctions
Incruit’s failure to comply with the PIPA took place again within three years after the sanction in July 2023. Repeated non-compliance associated with guardrails was the main cause of this year’s data breach. The PIPC deemed Incruit’s failure severe complacency and decided to strictly sanction the business, imposing KRW 463 million. The PIPC also issued an order to publish or announce the sanction results on Incruit’s website.
As correction orders, the PIPC asked Incruit to designate a dedicated Chief Privacy Officer (CPO) to clarify his/her roles and responsibilities and submit a detailed plan within sixty days to prevent recurring data breaches, including redress and remedies for data subjects.
3. Key Takeaways
A job search engine inevitably retains job seekers’ personal information, ranging from basic personal information to educational backgrounds, work history, disabilities, military services, and others. In this sense, Incruit should have taken extra care to put sufficient safeguards in place for its personal data processing system, but it failed to do so, resulting in the data breach in question. The PIPC reviewed this incident and imposed strict sanctions on Incruit within the current legal framework.
Additionally, the PIPC is coming up with a plan to improve its penalty system by enabling punitive measures against businesses that compromise privacy safeguards, leading to recurring data breaches. This will help promote the effectiveness of future sanctions.
* A PDF file, formatted for better readability, is attached.
|
||