An incident involving unauthorised external access at some services operated by Kakao Games led to the leakage of personal information of 140 users. The company said it blocked the intrusion route and inspected related systems immediately after detecting unusual signs. It said it is cooperating with investigations by relevant authorities and is examining the cause and the exact scope of impact with an external security firm.
Kakao Games said on Wednesday the services confirmed to have suffered the leak were Partners and Link (RINK). Partners is a programme that collaborates on content production with creators and users to promote games, while RINK is a service that supports sending Kakao Games titles running on a PC to a smartphone for remote control.
Kakao Games said it detected unusual signs at some services at 10:44 p.m. on Sept. 12 and began an emergency response. It said it blocked the intrusion route and inspected related systems immediately after recognising the incident.
The company estimated the external attack occurred from 10:44 p.m. on Sept. 12 to 7:37 p.m. on Sept. 13. It said an external attacker gained abnormal access by exploiting vulnerabilities in the Partners and RINK systems, and personal information was confirmed to have been leaked in the process. Kakao Games said it confirmed the leak of personal information of 140 users at 12:50 a.m. on Sept. 14.
The leaked personal information differs by service. At Partners, a third-party identification code for external linkage or a third-party ID was leaked. At RINK, an in-house identification code and some country codes were leaked.
Kakao Games said the external linkage identification code, the in-house identification code and the country code are personal information with a low risk of misuse because it is difficult to identify an individual. It said passwords were not leaked even in some cases where third-party IDs for external linkage were exposed. The company said it has so far not confirmed any leak of highly important personal information, excluding internal identifiers such as PID.
Kakao Games said it secured logs and evidence related to the incident and inspected and supplemented system vulnerabilities. It said it blocked related accounts, strengthened system security and also strengthened monitoring for unusual signs. After reporting the incident to relevant authorities including the Personal Information Protection Commission, it is investigating the cause and impact with an external security firm.
It said it individually notified users whose personal information was leaked, and also set up a page where users can check whether their personal information was compromised.
A Kakao Games official said, "We are taking measures to prevent additional damage and are also actively cooperating with investigations by relevant authorities." The official added, "Once the exact scope of damage is finally confirmed, we plan to proceed with necessary user guidance and protective measures in accordance with the relevant procedures."
The official also said, "We apologise for causing concern to users," and added, "We will strengthen measures needed to prevent a recurrence through an investigation into the cause of the incident and a comprehensive reinspection of the overall security system."