Seoul public bikes Ttareungi leaks 4.62 million users' data; compensation sparks criticism
Translated from Korean, summarized and contextualized by DistantNews.
At a glance
- A large-scale personal data breach affected 4.62 million users of Seoul's public bicycle service, Ttareungi, with user IDs and phone numbers among the leaked information.
- The Seoul Facilities Management Corporation was criticized for a significant delay in detecting and reporting the hack, which occurred in June 2024 but was only publicly disclosed after a police notification 1.5 years later.
- Compensation for affected users will be a 30-day Ttareungi usage coupon, sparking public criticism over the adequacy of the compensation for the data breach.
Seoul's public bicycle service, Ttareungi, has suffered a massive personal data breach, exposing the information of 4.62 million users. The incident, which occurred between June 28-29, 2024, involved a minor exploiting a vulnerability in the Ttareungi server for self-aggrandizement. The leaked data includes user IDs, phone numbers, birthdates, genders, weights, emails, addresses, and guardian contact details. While payment information was not directly compromised, the sheer volume of exposed personal data has raised significant privacy concerns.
The personal information of 4.62 million members who signed up before June 30, 2024, was leaked.
The Seoul Facilities Management Corporation, which operates Ttareungi, faces severe criticism for its delayed response. The breach was reportedly discovered only after a police notification, approximately 1.5 years after the initial hack. The corporation initially mistook the breach for a simple system error when the app experienced disruptions. This "failure in initial response" has led to public outcry, with many questioning the security protocols and the corporation's handling of the incident.
The payment card information was not included in the leaked items, as it goes through a payment gateway (PG), so the possibility of additional payment damage is low.
As compensation, Ttareungi is offering affected members a 30-day usage coupon, valued at approximately 5,000 won. This offer has been met with backlash, with some critics deeming it insufficient for the scale of the data breach. The corporation claims no third-party distribution or actual damage has been confirmed yet, but the significant gap between the breach occurrence, its discovery, and user notification continues to fuel controversy. The incident also highlights a broader trend of frequent data breaches in South Korea, making it increasingly difficult for victims to identify and seek redress for damages.
We will provide a Ttareungi '30-day usage coupon (worth 5,000 won)' as compensation to affected members.
Originally published by Dong-A Ilbo in Korean. Translated, summarized, and contextualized by our editorial team with added local perspective. Read our editorial standards.