Kakao Golf leak hits 34,000; data breach reports near annual record

by Kim Yeon-jae Posted : October 9, 2026, 10:10Updated : October 9, 2026, 10:10
Generated with ChatGPT
Generated with ChatGPT
SEOUL, October 9 (AJP) — Personal information belonging to about 34,000 Kakao Golf Reservation users was exposed in the latest breach to hit South Korea as reported data leaks approach last year’s annual record.

Kakao VX said it discovered on October 7 that an unauthorized outsider had accessed and removed customer information from the golf reservation service. The breach affected customers who booked domestic golf tour packages between January 2025 and October 2026.

The leaked information included names, phone numbers, reservation details and round dates. Accommodation information, payment amounts, order numbers and virtual account numbers were also exposed. Credit card numbers and resident registration numbers were not included, according to the company.

Official figures show the Kakao Golf incident came during a sharp increase in reported data breaches across South Korea.

The Personal Information Protection Commission (PIPC) received 432 personal-data breach reports in the first half of 2026, nearly matching the record 447 reports filed during all of 2025.

Cyber incidents also increased from a year earlier. The Korea Internet & Security Agency (KISA) received 1,236 incident reports in the first half, up 19.5 percent from 1,034 a year earlier, according to the Ministry of Science and ICT.
 
Kakao Golf Reservation displays a pop-up notice on October 8 2026 informing users of a personal data breach Screenshot from Kakao Golf Reservation
Kakao Golf Reservation displays a pop-up notice on October 8, 2026, informing users of a personal data breach. Screenshot from Kakao Golf Reservation
The latest breach also came as financial companies reported a series of cyber intrusions and information leaks.

Financial regulators began an on-site investigation after receiving a breach report from Shinhan Bank on September 30 and later confirmed additional attacks involving KB Kookmin Bank and other financial companies.

The Financial Services Commission (FSC) subsequently ordered financial companies to inspect externally connected systems and strengthen authentication and access controls.

A separate breach at streaming platform TVING illustrated the scale of personal-data exposure this year.

An earlier tally put the number of affected TVING users at about 19.53 million, while a subsequent government investigation found information from 39.54 million accounts had been compromised. The latter figure included duplicate accounts and therefore did not represent 39.54 million individual people, with the final number of affected TVING users yet to be determined.

The investigation found that an attacker stole an access key and penetrated TVING’s internal systems. Exposed data included names, birth dates, phone numbers and email addresses, as well as linked identification data.

The Kakao Golf Reservation incident added another consumer-facing service to a series of information leaks spanning digital platforms and financial institutions in 2026.

AJP Takeaways

- Kakao Golf Reservation said personal information belonging to about 34,000 customers was exposed after unauthorized access to its service.

- The PIPC received 432 personal-data breach reports in the first half of 2026, nearly matching the record 447 reports filed during all of 2025.

- KISA recorded 1,236 cyber incidents in the first half, up 19.5 percent from a year earlier, as breaches also spread across financial companies and major digital platforms.