The logo of the Institute of Information & Communications Technology Planning & Evaluation (IITP). [Photo: IITP]

A security incident at the Institute of Information & Communications Technology Planning & Evaluation (IITP), an agency under the Ministry of Science and ICT, has been confirmed to have leaked personal information of users of connected systems.

According to IITP on Thursday, the incident occurred after an external access port was left open for an extended period while IITP was strengthening security for a system managing personal data access logs.

The external port was open for about 26 days, from 3:57 p.m. on June 10 to 4:05 p.m. on July 6. During that period, abnormal external access occurred and some data were found to have been leaked and deleted. The affected personal information covers users of five systems operated by IITP: e-Jiwon, e-Jimatching, ITFIND, the e-Evaluation System and the Loan Management System.

The leaked information is reported to include names, mobile phone numbers, emails, affiliated organisations, department names, job titles, workplace addresses, dates of birth, gender, user IDs, passwords, phone numbers, home addresses, national researcher numbers, career information and education information. The specific items of personal information leaked may differ by victim.

After recognising the incident, IITP blocked the port and isolated the system. It is now restoring deleted data and investigating the exact scope of the personal data leak. It is also providing a service on its website to check the leak.

IITP urged people to be wary of messages, emails and phone calls impersonating the agency, and not to click internet links or attachments from unclear sources. It also advised people not to respond to demands for money, app installation requests or requests for remote control or authentication information, and to strengthen personal information management by changing key passwords.

IITP manages a national ICT research and development budget worth 1.9 trillion won this year. Those who suffered damage from the leak can apply for dispute mediation through the Personal Information Dispute Mediation Committee.

IITP said it would thoroughly investigate the cause and scope of the incident and provide swift updates on additional details. It said it again offered its deep apologies.

Keyword

#IITP #Ministry of Science and ICT #ITFIND #e-Jiwon #Personal Information Dispute Mediation Committee
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.