Foreign Ministry faces criticism for five-month delay in reporting major data breach
Translated from Korean, summarized and contextualized by DistantNews.
At a glance
- The Ministry of Foreign Affairs (MOFA) is criticized for a five-month delay in reporting a hacking incident at the National Diplomatic Academy, which exposed personal information of up to 10,000 public officials.
- In contrast, other government agencies typically report such breaches to the Personal Information Protection Commission (PIPC) within two days and notify victims within three days.
- MOFA cites national security reasons for the delay, but critics argue that such justifications may not fully excuse the prolonged non-disclosure, especially concerning individuals' privacy rights.
South Korea's Ministry of Foreign Affairs (MOFA) faces criticism for a significant delay in reporting a major hacking incident that compromised the personal data of up to 10,000 public officials. The breach, which occurred at the National Diplomatic Academy's online education system in February, was only reported to the Personal Information Protection Commission (PIPC) and victims last month, a full five months after MOFA became aware of the incident.
There were matters that required urgent response from a security perspective among the hacked information, so we had to respond, and it took several months, so we could not disclose it immediately.
This delayed response starkly contrasts with the practices of other government agencies. According to data obtained by lawmaker Kim Jun-hwan, central administrative bodies typically report personal information leaks to the PIPC within an average of two days and notify affected individuals within approximately three days. Some cases have seen notifications take up to ten days, but MOFA's five-month lag is exceptionally long.
MOFA has attributed the delay to national security concerns, suggesting that urgent matters requiring immediate attention related to the compromised information necessitated a prolonged period before external disclosure. However, the ministry has not provided specific details about these security-related issues. This justification is being scrutinized, particularly in light of the Personal Information Protection Act, which mandates reporting within 72 hours unless specific, unavoidable circumstances, such as natural disasters, prevent it.
Whether the uniform non-notification (of affected individuals) for national security reasons can be justified requires further judgment.
Legal experts question whether national security concerns can universally justify such extended delays in notifying individuals about data breaches. While acknowledging the potential need for exceptions, they emphasize that the primary purpose of reporting and notification is to protect the rights of data subjects. The PIPC is currently investigating the circumstances of MOFA's delayed reporting and notification to determine if violations of the Personal Information Protection Act occurred. The incident raises broader questions about government agencies' data security protocols and their transparency in handling breaches.
We are currently verifying the facts, including the process of MOFA's delayed notification and reporting of the leak and whether it constitutes a violation of the Personal Information Protection Act.
Originally published by Hankyoreh in Korean. Translated, summarized, and contextualized by our editorial team with added local perspective. Read our editorial standards.