Skip to menu Skip to content

Korean e-government homepage mark This site is the official e-Government website of the Republic of Korea.

zoom
100%

Notice / Press Release

Notice Detail
Title PIPC Sanctions National Court Administration for Data Breaches and Non-Compliance Associated with Duty of Safeguards
Department Date 2025.01.10
Attachment press release PIPC Sanctions National Court Administration for Data Breaches and Non-Compliance Associated with Duty of Safeguards.pdf
Page URL https://pipc.go.kr/eng/user/ltn/new/noticeDetail.do?bbsId=BBSMSTR_000000000001&nttId=2761
Contents

Press Release

PIPC Sanctions National Court Administration for Data Breaches and Non-Compliance Associated with Duty of Safeguards

- PIPC imposes a penalty surcharge of KRW 207 million and an administrative fine of KRW 6 million on the National Court Administration along with publication of sanction results and correction orders

 

January 9, 2025

(This is an unofficial translation of a press release, originally prepared in Korean.)

 

The Personal Information Protection Commission (PIPC) held its first plenary meeting and resolved to sanction the National Court Administration for non-compliance with the Personal Information Protection Act (PIPA). The PIPC imposed KRW 207 million and KRW 6 million as a penalty surcharge and administrative fine, respectively, on the agency for judicial administrative affairs along with recommendations to overhaul its safety measures and establish plans to improve them.

 

Detailed violations by the National Court Administration and imposed administrative sanctions as a result of the investigations upon its report of data breaches are as follows: 

 

The public agency opened and operated a port, a virtual point where network connections start and end, to allow mutual access between internal and external networks in order to facilitate user convenience. However, hackers used this port to get access to an electronic litigation server located in the internal network. As a result, a whopping 1,014 gigabytes of documents associated with litigation, such as written statements, marriage relation certificates, diagnostic certificates, etc. got leaked.

 

 

Restoring most of the data leaked by the hackers failed, but police’s investigations found out that personal information of 17,998 individuals, such as name, resident registration numbers (RRNs), birthdate, phone number, age, and gender, was included in 4.7 gigabytes of files restored from the data breaches.

 

Investigations by the PIPC showed that the National Court Administration failed to encrypt litigation-related documents that include RRNs when retaining and storing them in the Electronic Litigation Server. 

 

The National Court Administration used an initial password that was easy to infer when logging into administrator accounts and handler accounts for an Internet Active Directory (AD) server and virtual PCs for Internet access without getting it changed. The administrative agency also failed to install antimalware and other security programs in its Virtual Web Server for Internet Access located in the internal network. In short, its duty of putting in place baseline safeguards for the sake of security was insufficient. On a side note, the practice implemented by the National Court Administration allows its staff to access the Internet while staying in the internal network by virtually converting the environment without having to implement physical network separation. 

 

To make matters worse, the administrative agency started its internal investigations into the incident after detecting malicious files in February 2023, and became aware of data breaches in April 2023. The administrative agency was supposed to report the incident and notify affected data subjects of data breaches without undue delay as prescribed in the PIPA; however, it failed to do so. It reported the incident and posted an announcement regarding data breaches on December 7, 2023.

 

Given the National Court Administration’s aforementioned non-compliance with the PIPA, the PIPC resolved to slap KRW 207 million and KRW 6 million on the agency as a penalty surcharge and administrative fine, respectively, and publish the resolved sanctions against it. The data protection supervisory authority recommended the administrative agency overhaul its safeguards implemented over the security framework and lay out plans to improve privacy-safeguarding measures. 

 

Violations:

● Limitations to the Processing of PII (Article 24-3) 

● Limitations to the processing of RRNs (Article 24-2(2)) 

● Duty of Safeguards (Article 29) 

● Data Breach Notification (Article 34-1, 34-3)

 

Administrative Sanctions:

● Penalty surcharge of KRW 207 million 

● Administrative fine of KRW 6 million 

● Publication of the sanction results 

● Recommendations for disciplinary actions 

● Recommendations for improvement

 

Public institutions that process vast amounts of personal information are required to fulfill duties associated with putting in place safeguarding measures, such as the installation and operation of security programs and security updates for operating systems (OS). Moreover, they shall take extra care to monitor illegal access attempts by malicious adversaries on a permanent basis.

 

* A PDF file, formatted for better readability, is attached.  

Previous
PIPC’s Project to Support Young Adults to Exercise Their Digital “Right to be Forgotten” Shows a Meaningful Uptick in the Number of Successful Cases
Next
PIPC’s Policy Vision and Tasks for 2025: Trustworthy AI Era Backed by Safe Use of Personal Information