'Ttareungi' users' personal data leaked; 4.62 million affected
Translated from Korean, summarized and contextualized by DistantNews.
At a glance
- Personal information of 4.62 million users of Seoul's public bicycle service 'Ttareungi' was leaked due to a cyberattack in June 2024.
- The Seoul Facilities Corporation will compensate affected members with a 30-day regular pass worth approximately 5,000 won.
- The leaked information includes user IDs, phone numbers, birthdates, and addresses, though no evidence of data transfer to third parties has been found yet.
Personal information of 4.62 million members of Seoul's public bicycle service 'Ttareungi' was leaked following a cyberattack in June 2024. The Seoul Facilities Corporation, which operates the service, announced that affected members will receive a 30-day regular pass valued at approximately 5,000 won as compensation.
The incident occurred between June 28-29, 2024, when unauthorized access was gained through security vulnerabilities in the Ttareungi server. The corporation stated on its website that while some personal information of members registered before June 30, 2024, was leaked, current investigations have not found evidence of the data being transferred or distributed to third parties.
The specific leaked information varies by user but includes member IDs, mobile phone numbers, birthdates, gender, weight, email addresses, postal codes, addresses, and guardian's mobile phone numbers, birthdates, and gender. Users can check their specific situation by visiting the 'Check Personal Information Leakage' section on the Ttareungi website or through SMS notifications, a call center, or email.
The compensation pass, offering one hour of use per day, will be distributed through the Ttareungi application and must be used within three months of issuance. Detailed information regarding the distribution schedule and usage will be announced on August 14. This incident follows a previous revelation in February where Seoul City confirmed that the Seoul Facilities Corporation failed to take prompt action after discovering the data breach during the cyberattack in June 2024.
Originally published by Hankyoreh in Korean. Translated, summarized, and contextualized by our editorial team with added local perspective. Read our editorial standards.