Privacy Breach Reports Surge 2.7 Times in Three Years Amid Staffing Challenges

By BAEK SEO HYUN Posted : September 16, 2026, 19:36 Updated : September 16, 2026, 19:36

As large-scale data breaches involving companies like Coupang, SK Telecom, and KT continue to rise, the workload for the Personal Information Protection Commission (PIPC) has also increased. However, the number of specialized investigators handling these cases remains critically low. There are calls for collaboration with external experts, similar to practices in other countries.


According to the PIPC, the number of reported data breaches has escalated from 167 in 2022 to 318 in 2023, 307 in 2024, and 447 in 2025. In the first half of this year alone, 432 reports were received, nearly matching last year's total.


In contrast, the number of investigators responsible for these inquiries has only grown from 31 in 2022 to 43 at the end of last year, and 47 as of August this year. Among the newly added staff, 11 are focused on compliance checks and preventive measures, leaving only six specialized investigators. A total of 37 investigators are tasked with examining all hacking incidents that occur domestically.


In 2022, each investigator was responsible for an average of 5.4 data breach cases annually. By 2025, this number is expected to rise to 10. This year, investigators have been assigned an average of 9 cases in just the first half, indicating that the limited number of specialized staff are handling more than two cases each month.


A PIPC official noted that the complexity of investigations has increased. With the evolving information technology landscape, cases now require not only verification of data breaches but also an examination of breach pathways, data flows, outsourcing relationships, and behavioral data processing. Consequently, the number of investigators and the duration of investigations for each case have lengthened.


When a major hacking incident occurs, it inevitably delays the investigation schedule for other cases. For instance, during the SK Telecom incident, the PIPC had to augment its team with personnel from the Korea Internet & Security Agency (KISA) to form a dedicated task force. As resources are concentrated on larger incidents, smaller cases inevitably face longer investigation times.


The investigation into the data breach at SK Shieldus, which occurred last September, has yet to yield results. The prioritization of limited investigative resources for major incidents has prolonged the investigation timelines for other cases.


Recruiting new specialized personnel is also challenging. Any increase in the number of public servants requires approval from the Ministry of the Interior and Safety, and even once positions are secured, actual hiring takes additional time. Finding and hiring experts who understand both data protection and IT technology is difficult. While the PIPC is striving to enhance the efficiency of its limited workforce, the task remains daunting.


In other countries, external experts are utilized to supplement the expertise of regulatory agencies. The European Union's European Data Protection Board (EDPB) operates a pool of technical experts to assist national data protection authorities with investigations and enforcement in areas such as digital forensics, cloud computing, and cryptography.


However, the PIPC explains that directly applying foreign systems domestically is not straightforward. A PIPC official stated, “The PIPC is an organization that issues sanctions, so we are cautious about seeking external assistance.” They emphasized that involving external experts in the investigation process raises concerns about information security, potential conflicts of interest, and the independence of sanction decisions.





* This article has been translated by AI.

Copyright ⓒ Aju Press All rights reserved.