South Korea’s Kakao Games Apologizes After Hack Exposes Data of 140 Users — BigGo Finance | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


South Korea’s Kakao Games has issued a formal apology after an external hacking attack exposed the personal data of 140 users. While the leaked information was confirmed to consist primarily of identification codes that are difficult to use to identify individuals, the company said it is treating the incident with the utmost seriousness and will conduct a comprehensive review of its security framework.

On September 17, Kakao Games announced: “We are taking measures to prevent further damage while actively cooperating with relevant authorities in their investigation. Once the exact scope of the damage is finalized, we will proceed with necessary user notifications and protective measures in accordance with relevant procedures.”

The company posted a notice titled “Personal Data Breach Notification and Preventive Measures” on its website the previous day. According to the notice, the company first detected abnormal external access to the Partners and RINK services at 10:44 p.m. on September 12, and confirmed two days later, at 12:50 a.m. on September 14, that the personal data of 140 customers had been leaked externally.

The estimated attack window spans from 10:44 p.m. on September 12 to 7:37 p.m. on September 13. External attackers are believed to have exploited vulnerabilities in the two service systems to gain unauthorized access.

The leaked information varies by service. From Partners, third-party identification codes or third-party account IDs used for external integrations were exposed. From RINK, the company’s own identification codes and some country codes were leaked.

Kakao Games assessed the risk level of the leaked data as low. The company explained that external integration identification codes, its own identification codes, and country codes are difficult to use to identify specific individuals. Even in cases where third-party account IDs were leaked, the company drew a clear line that passwords were not included.

The company also confirmed that sensitive information that could directly expose identities—such as names or contact details—was not part of the breach.

Incident response measures were implemented immediately. Kakao Games blocked the abnormal external access routes and related accounts, and enforced security enhancements to prevent further access to the affected systems. Follow-up actions included securing incident logs and evidence, inspecting and patching vulnerabilities, investigating whether additional data was leaked, and strengthening anomaly monitoring. The company has completed its report to the Personal Information Protection Commission and other relevant authorities.

Relevant authorities and security specialists are currently conducting a joint investigation into the specific cause and scope of the incident.

The notice also included guidance for user protection. The company urged users to watch for unsolicited password change requests and to verify login and payment notifications, given the possibility that the leaked data could be exploited for phishing, smishing, voice phishing, or account takeover. It also advised users not to open URLs or attachments in emails or text messages from unverified sources.

The company added that users should exercise particular caution with any contact impersonating Kakao Games or relevant authorities requesting passwords, verification codes, or account information.

“We are treating this incident with the utmost seriousness,” the company stated, pledging to prioritize protective measures for users and recurrence prevention. Any additional findings from the investigation will also be communicated to users.

Incident Overview

Key details of the personal data breach are summarized below.

CategoryDetails
First detectedSeptember 12, 2026, 10:44 p.m.
Breach confirmedSeptember 14, 2026, 12:50 a.m.
Affected users140
Services affectedPartners, RINK
Leaked informationThird-party identification codes, third-party account IDs, company identification codes, some country codes
Estimated attack windowSeptember 12, 10:44 p.m. – September 13, 7:37 p.m.

Note: Passwords, names, contact information, and other sensitive data were confirmed not to be included in the breach.

Security Risks in South Korea’s Gaming Industry Resurface

The incident is expected to heighten awareness of personal data protection frameworks across South Korean game companies. Kakao Games, a gaming affiliate of Kakao, operates multiple popular titles including “Odin: Valhalla Rising” and “ArcheAge War.” Partners and RINK are known to be game publishing and community-related services.

Given that the leaked information consists primarily of identification codes, analysts assess the potential for direct secondary damage as limited. However, the fact that external attackers successfully exploited system vulnerabilities itself exposes gaps in the security framework, and the possibility of similar attacks spreading to other game companies cannot be ruled out.

Attention is also focused on whether the Personal Information Protection Commission’s investigation will result in administrative penalties such as fines. South Korea’s Personal Information Protection Act stipulates that administrative fines and penalties may be imposed when a data breach occurs because a personal data processor failed to implement necessary security measures.

Kakao Games has stated its intention to strengthen measures necessary for recurrence prevention through a thorough investigation of the incident’s cause and a comprehensive review of its security framework. A company representative said: “We deeply apologize for causing concern to our users,” adding, “We will devise thorough recurrence prevention measures through further investigation.”



Click Here For The Original Source.

——————————————————–

..........

.

.