Sogang University latest to report data breach in Korea

by Seo Hye Seung Posted : August 15, 2026, 13:39Updated : August 15, 2026, 13:39
Posting on the Sogang University website alerting students of data breach on Aug14 2026 Screen caption
Posting on the Sogang University website, alerting students of data breach on Aug.14, 2026. Screen caption.

SEOUL, August 15 (AJP) -Sogang University has become the latest South Korean institution to report a data breach, adding to a series of cyber incidents that have exposed vulnerabilities across the country's corporate, government and education systems.

The private elite university in Seoul said an external attacker gained unauthorized access to its integrated login system on Aug. 11 through a brute-force attack, in which large numbers of password combinations are tried until access is obtained. 

Potentially exposed data include student or employee identification numbers, names, affiliations, email addresses, mobile phone numbers and encrypted passwords for the university's integrated login system, Sogang said in a notice.

The university said government-issued unique identification information and other sensitive personal data were not included in the breach. 

Sogang detected abnormal activity and blocked the unauthorized access on Aug. 14, three days after the intrusion occurred, according to a notice posted by the university. 

Sogang has reported the incident to the Personal Information Protection Commission and the Ministry of Education and urged users to immediately change passwords for SAINT, its academic and administrative portal.  
 

The country received 447 data-leak reports in 2025, up 45.6 percent from 307 a year earlier, according to an analysis by the privacy commission and the Korea Internet & Security Agency. Hacking accounted for 276 cases, or 62 percent of the total, rising from 171 in 2024. 

Regulators said increasingly sophisticated external attacks, including ransomware, malware and attacks exploiting web vulnerabilities, were behind much of the increase. They have urged institutions to tighten access controls, encrypt databases, apply security updates more quickly and maintain secure backup systems. 

The breaches have spread across sectors. 

SK Telecom suffered a massive compromise affecting about 23 million users in 2025, the largest leak among cases investigated and sanctioned by the privacy regulator that year. 

Coupang disclosed another breach late last year that ultimately affected data associated with more than 30 million accounts. An investigation found that a former employee had obtained a security key that allowed unauthorized access, turning the episode into the largest breach involving a domestic e-commerce platform. 

Government networks have also proved vulnerable. In July, the Foreign Ministry disclosed that hackers had penetrated an online training system operated by the Korea National Diplomatic Academy, potentially exposing information associated with around 10,000 current and former diplomats and officials. The attackers are believed to have had access to the system for months before the intrusion was detected. 

The rising number of breaches has prompted Seoul to toughen its regulatory response. From Sept. 11, organizations responsible for large-scale leaks caused intentionally or through gross negligence can face penalties of as much as 10 percent of total revenue, according to the privacy commission.

AJP Takeaways: 

 
       Sogang detected and blocked a brute-force cyberattack that may have exposed names, IDs, contact details and encrypted portal passwords; the number of affected accounts has not been disclosed.

  • Korea's data-breach problem is accelerating: reported leaks jumped 45.6 percent to 447 in 2025, with hacking accounting for nearly two-thirds.
  • The latest incident follows major breaches across telecom, e-commerce and government networks, increasing pressure on institutions to strengthen authentication, access controls and monitoring.