ECONOMY

Korea Food Industry Association data breach exposes personal information of 113,000 users

by
Yu Dong-hyeon
Published : June 28, 2026 - 19:45:30
    • Copy Completed!

View Korean Original

Operator detects signs of unauthorized external access and creation of files containing personal data

[Korea Food Industry Association]
[Korea Food Industry Association]

Signs of a data breach affecting approximately 113,000 users have been detected in the online food hygiene education system — known as a learning management system — operated by the Korea Food Industry Association.

The association posted a notice on its website on June 26 and said Sunday it had also sent individual text messages to those affected.

The association is a special corporation established under Article 64 of the Food Sanitation Act, with a mission to promote food industry development, improve food hygiene, advance the mutual interests of food manufacturers and protect public health.

The system in question is operated by Mediopia Tech, an education technology company running the platform under a contract with the association.

Under the Food Sanitation Act, food business operators and workers must complete annual mandatory training through the system, covering areas such as food poisoning prevention and food safety management.

The association said Mediopia Tech discovered signs of the breach on June 24 during a routine system inspection, finding evidence of abnormal access suspected to be an external attack and the creation of files containing personal information.

Eight categories of personal data are believed to have been exposed: user IDs, encrypted passwords, names, genders, job titles, business phone numbers, mobile phone numbers and email addresses.

An association official said the breach appears to involve the personal information of 112,728 people who completed training in the first half of this year, and added that personal data is deleted one year after account registration.

The association said it has completed emergency security measures — including isolating the affected server, blocking the attacking IP addresses and reinforcing its firewall — and has reported the incident to the relevant authorities and is cooperating with their investigation.

"We are doing our utmost to block access routes and report to the relevant authorities to prevent further damage," the association said, and went on to say it was "deeply sorry that such an unfortunate incident occurred despite our obligation to protect your valuable personal information."

The association also urged those affected to be alert to smishing and phishing attempts via text messages, emails or phone calls from unidentified sources, and warned them not to comply with any demands for payment, money transfers or authentication codes made under the pretext of the incident.


dingdong@heraldcorp.com
This content was produced with the assistance of AI translation services.

MOST READ