In the wake of recent data breaches in the financial sector, Korea Electric Power Corporation (KEPCO) has reported that the personal information of over 24,000 employees was exposed externally. It took approximately 32 hours for the company to completely delete the exposed data after becoming aware of the incident.
On October 4, KEPCO stated that it became aware of the data exposure at 3:59 p.m. on October 1.
The exposed information included the names, affiliations, and phone numbers of more than 24,000 employees. However, KEPCO clarified that sensitive information, such as resident registration numbers, was not included in the breach.
Immediately after discovering the breach, KEPCO blocked access to its internal systems related to employee data and requested the deletion of the exposed information from the webpage's operator.
The actual deletion of the data occurred around midnight on October 2, resulting in a total of about 32 hours from the time KEPCO identified the breach to when the data was removed.
KEPCO has established an emergency response situation room and is coordinating with relevant agencies. The company has communicated with affected employees via text messages and emails to explain the circumstances of the breach and to provide guidance on measures to prevent further harm.
KEPCO plans to implement remedial procedures if actual harm occurs or is anticipated as a result of the breach.
A KEPCO official stated, “If any damage occurs or is expected, we will conduct necessary investigations and proceed with compensation procedures.” The official also emphasized that the cause of the exposure will be thoroughly investigated to implement measures to prevent recurrence.
It has been confirmed that customer information was not included in this data breach.
The KEPCO official added, “Customer information, aside from that of employees, is securely managed in a separate dedicated system.”
* This article has been translated by AI.
Copyright ⓒ Aju Press All rights reserved.