Cloud service provider Gabia has confirmed a data breach affecting the personal information of 2,998 customers. An external attacker exploited insufficient verification of external requests in certain functions of the web service to gain access to internal systems.
As of 3 p.m. on September 23, Gabia announced that the exposed information includes names, IDs, email addresses, and phone numbers. Passwords were not part of the leaked data.
The breach occurred at 11:45 a.m. on September 21. Gabia first detected the incident at 1:05 p.m. the same day and took immediate action to block the external access routes and related accounts to prevent further data loss.
The attacker accessed Gabia's internal systems by taking advantage of the inadequate verification of external requests in some web service functions. During this process, customer personal information was transmitted externally.
Immediately after detecting the incident, Gabia preserved logs and evidence while strengthening access controls for the affected systems. The company is also addressing the vulnerabilities that led to the breach and conducting a comprehensive review for similar vulnerabilities. Investigations and monitoring for unusual activity have been intensified to confirm any additional data leaks.
Gabia has reported the incident to the Korea Internet & Security Agency (KISA) and the Personal Information Protection Commission regarding the data breach. The company is currently working with relevant authorities to investigate the exact cause of the incident and assess any further damage.
Gabia stated that the number of affected customers and the specific personal information involved may change as investigations continue. The company plans to notify affected customers individually via email or text message.
To prevent secondary damage from the data breach, Gabia is advising customers to change their account passwords. Although passwords were not leaked, accounts with exposed IDs could be targeted for login attempts using passwords leaked from other sources. Customers using the same password on other sites as they do on Gabia are also encouraged to change those passwords.
* This article has been translated by AI.
Copyright ⓒ Aju Press All rights reserved.