In a recent data breach involving Tiv-ing, 19.04 million linked information (CI) identifiers, generated during verification processes through external portals like Google and Naver, were leaked, raising new security concerns.
Current laws do not provide a procedure for invalidating or replacing leaked CIs. The Broadcasting and Communications Commission (BCC) is reportedly working on measures to address this issue.
On September 7, a BCC official stated, "We are comprehensively reviewing whether we can invalidate or replace the leaked CIs at a practical level. While we have not finalized specific methods or targets for changes, we expect to have results soon."
The CI data from the Tiv-ing incident was used to estimate the number of actual victims. According to a report released by a joint public-private investigation team on September 3, the number of accounts with leaked CIs was 19.04 million. After removing duplicate accounts, the actual number of users affected was approximately 13.24 million.
However, about 20.4 million accounts without CIs make it difficult to confirm whether the same individual holds multiple accounts, leaving the total number of victims undetermined.
Although the leaked CI values cannot be used by hackers to steal accounts or conduct financial transactions, the issue arises from multiple businesses using the same CI. If an attacker possesses a leaked database that includes the same CI as other data they hold, they can combine scattered information such as names, contact details, and services subscribed to identify individuals.
Choi Kyung-jin, a professor at Gachon University, noted, "While the CI itself is not inherently dangerous, it can be used to identify individuals when combined with other data for malicious purposes. The risk increases when multiple datasets are merged."
In the system, each individual is assigned a single CI value. Even if a new verification process is undertaken, the same value will be assigned. However, there is currently no procedure to stop or replace leaked values, unlike credit card numbers or passwords.
Professor Choi explained that CIs are not technically unchangeable. He emphasized, "While the system has operated without changing CIs until now, it is permissible to change them. We should restore the function of temporary identifiers as originally intended and implement expiration dates for the currently permanent CIs."
Issuing new values when the expiration date is reached or a breach occurs could reduce the risk of existing CIs being used as long-term links between various datasets, he added.
Professor Choi also mentioned that since the BCC currently generates and provides CIs through designated verification institutions, revising related regulations could facilitate the introduction of expiration dates and replacement systems.
In June, the BCC initiated an urgent inspection of Tiv-ing to verify the purpose of CI processing, the encryption of storage and transmission processes, and the response plans for security incidents. The implementation date for the mandatory separation of resident registration numbers and CIs is also being pushed forward from May to January of next year.
A BCC official stated, "While the schedule for discussions has not yet been set, there is little time left for discussions related to the regulatory revisions, and they are expected to take place within this month."
* This article has been translated by AI.
Copyright ⓒ Aju Press All rights reserved.