For many South Koreans who grew up online, the losses follow a familiar timeline. A KakaoTalk account hijacked in high school, a Facebook account in college, and later a profile photo resurfacing on a stranger’s Instagram, attached to a life that is not yours.
Deleting old accounts does little. Whatever remains tied to your personal information, including the sensitive ones, keeps getting compromised with a regularity that now feels routine. Some people quit online games not because they lost interest but because their accounts were stolen and never recovered.
About 34,000 users of Kakao Golf Reservation joined that list this week, after an unauthorized outsider took their names, phone numbers and booking details.
Kakao VX said it discovered the breach on Oct. 7.
A week earlier, a breach report from Shinhan Bank led regulators to attacks on KB Kookmin Bank, Hana Bank, BNK Busan Bank and other lenders. Before that came Tving, where a government investigation found 39.54 million accounts compromised, a count that includes duplicates.
Coupang disclosed the exposure of 33.7 million accounts in November 2025. SK Telecom lost USIM data tied to about 23 million subscribers that year. Rogue femtocells siphoned information from 22,227 KT users, and Lotte Card leaked credit data on 2.97 million customers.
The Personal Information Protection Commission received 432 breach reports in the first half of 2026, nearly matching the record 447 filed in all of 2025. South Korea markets itself as an IT powerhouse and an aspiring AI leader.
The bank attacks have been widely described as the arrival of AI hacking. Investigators found traces of ARTEX, an open-source AI penetration-testing platform, on suspected attack servers, and the campaign’s speed and breadth fit automation.
How much of the work AI actually did remains unconfirmed.
What regulators did confirm is more mundane. One lookup service displayed loan-application data without verifying identity. A staff system lacked controls over access from mobile devices. In another case, attackers used a known web vulnerability to plant malware.
South Korea once ran one of the most demanding online security regimes in the world. Banking meant a government-accredited digital certificate, a numbered security card, sometimes an OTP device, and a stack of plug-ins that made every transaction a small ordeal.
People hated it, with good reason.
The accredited certificate lost its exclusive legal status in December 2020, and simple authentication took its place. PASS, Kakao and Naver logins, fingerprints and face scans now settle a payment in a second.
Security experts contacted by AJP this week said that convenience came at a price. Much of the country’s verification still runs through text messages and a handful of universal apps, so a single weak point can open many doors.
Most users have taken the seatbelt off. Reused passwords let attackers test credentials stolen from one service against every other, a process that can be automated without any AI at all. Yet after Coupang, after the carriers and after TVING, few people seem to have changed theirs.
When a site forces a change, the usual fix is to keep the same base and shuffle the digits at the end.
The logic is hard to argue with. If everything has already leaked, why bother?
Companies seem to have reached a similar conclusion. Tving Chief Executive Choi Joo-hee apologized on Sept. 3 and unveiled a compensation package of one-year hacking and phishing insurance, a premium viewing upgrade, 5,000 won in Tving points and an entertainment coupon.
The apology arrived as an invitation to keep watching. Compensation has become a line item, and loyalty the expected return.
One expert offered advice that sounded half like a joke: the safest place for a password, he told AJP, may now be a paper notebook kept in a drawer. No AI agent can scan a page that never touches the internet.
It is a bleak irony for a country racing to build sovereign AI models and data centers. After years of digital upgrades, the most reliable lock may be the oldest one there is.
Blaming AI is convenient for everyone. It lets institutions describe basic failures as a new and unstoppable threat, and it lets users keep the passwords they set a decade ago.
The leaks will continue as long as losing data costs less than protecting it. Until that changes, the notebook in the drawer may be the best defense on offer.
*The author is a business reporter at AJP.
Copyright ⓒ Aju Press All rights reserved.

