Kakao Games corporate identity (CI) [Photo: Kakao Games]

The scope of Kakao Games' personal data leak has grown to 243 people from 140. No separate additional attack occurred. The company said it confirmed the additional exposure of personal data for 103 RINK users while investigating the scope of a previously identified security incident.

Kakao Games said on Sept. 22 that it additionally determined at 6:22 p.m. on Sept. 21 that personal data of 103 RINK users had been leaked externally. The newly confirmed leaked information is Kakao Games' own identification code and some country codes.

Kakao Games previously said it confirmed at 10:44 p.m. on Sept. 12 that abnormal external access occurred on the Partners and RINK services. It believes the attack took place between 10:44 p.m. on the same day and 7:37 p.m. on Sept. 13.

During the subsequent investigation, the company confirmed at 12:50 a.m. on Sept. 14 that personal data of 140 users of the two services had been leaked externally and reported it to the Personal Information Protection Commission and other relevant agencies. The company notified users of the matter on Sept. 16. With the additional confirmation of the leak involving 103 RINK users, the total number of people affected by the personal data leak identified so far has increased to 243.

The company determined the incident occurred when an external attacker gained abnormal access by exploiting vulnerabilities in the Partners and RINK systems.

So far, Partners is confirmed to have had a third-party identification code or third-party ID used for external service linkage leaked. For RINK, its own identification code and some country codes were leaked externally.

Kakao Games said the external linkage identification codes, its own identification codes and country codes are hard to use to identify an individual based on that information alone, so the risk of misuse is low. It also said that even for some users whose third-party IDs were leaked, passwords were not leaked.

The company said it blocked abnormal access routes and related accounts immediately after it became aware of the incident, and strengthened system access controls. It is securing related logs and evidence materials, while also conducting vulnerability checks and fixes, probing whether additional leaks occurred, and monitoring for abnormal signs.

Kakao Games said it reported the incident to the Personal Information Protection Commission and other relevant agencies, and is investigating the specific cause and scope of impact with an external security specialist institution. It plans to implement necessary protective measures and recurrence prevention steps based on the investigation results.

Kakao Games said, "We are taking this incident seriously, and we will prioritize implementing necessary protective measures and recurrence prevention measures so that customers do not suffer harm," and added, "If there are additional matters identified during the investigation process, we will provide guidance quickly and transparently."

Keyword

#Kakao Games #RINK #Partners #Personal Information Protection Commission
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.