Cyber & AI intelligence
Wasteland.
Briefs indexed3004
Issues30
Published Mondays07:30 CT
▣ Breach KEPCO-EMPLOYEE-DAT 2026-10-04

KEPCO: Personal Data of About 24,000 Employees Exposed on External Webpage

"Korea Electric Power Corporation (KEPCO), South Korea's state-owned power utility, said in a statement on Sunday, 4 October 2026, that personal information belonging to its employees had been posted on an external…"

Korea Electric Power Corporation (KEPCO), South Korea's state-owned power utility, said in a statement on Sunday, 4 October 2026, that personal information belonging to its employees had been posted on an external webpage. The exposed data included names, departments and phone numbers. Reported headcounts differ. The Herald Business and NoCut News say "more than 24,000", the Seoul Economic Daily and The Asia Business Daily say "about" or "approximately" 24,000, and SBS describes it as "all its employees, numbering over 20,000". KEPCO says no customer data and no resident registration numbers were exposed. The data stayed online for roughly 32 hours after the company learned of it. The cause has not been determined.

None of the sources provided is KEPCO's own statement, a regulator filing or a CERT advisory. Every detail below comes from Korean press reporting of the company's statement and should be read on that basis.

What Happened

All outlets agree on the following timeline, which comes from KEPCO's statement:

Accounts differ on how KEPCO found out. The Herald Business, the Seoul Economic Daily and NoCut News say only that KEPCO "became aware" of the exposure. The Asia Business Daily reports that the National Intelligence Service (NIS) found the posting first and notified KEPCO at 3:59 p.m. If that is correct, the utility did not detect the exposure itself. No other source provided confirms the NIS detection.

Reports also differ on who is investigating: - The Asia Business Daily says it is a joint investigation with the NIS and the Ministry of Climate, Energy, and Environment. - The Seoul Economic Daily says it is a joint investigation with law enforcement. - The Herald Business says only that KEPCO is "coordinating with relevant authorities".

KEPCO has set up an emergency response center. It has told affected employees by text message and email and warned them to be careful with unexpected calls, emails and texts. A company official said KEPCO would investigate any reported damage and "proceed with relief measures including compensation."

What Was Taken

Confirmed across all outlets: - Full names - Department or affiliation - Phone numbers

Reported by one outlet only: - Employee numbers. NoCut News lists these among the exposed fields. No other source does.

KEPCO says these were not exposed: - Resident registration numbers and other unique identifiers - Sensitive personal information - Customer data. A KEPCO official said customer data is "managed separately and securely in a dedicated system."

Volume: About 24,000 people. Both SBS and NoCut News describe this as effectively KEPCO's entire workforce.

Each record is not very sensitive on its own. Together they amount to a full staff directory of a critical-infrastructure operator, linking each person's name, organizational unit and direct phone number.

Why It Matters

This is a targeting list for a national grid operator. A complete directory that maps names to departments and phone numbers is what an attacker needs to plan spear-phishing, vishing (voice phishing) and pretexting. It lets them pick out staff in operations, IT, procurement or substation engineering and contact them directly. The absence of national ID numbers limits identity-fraud risk. It does little to reduce social-engineering risk. KEPCO appears to agree, since its warning to employees focused on suspicious calls, emails and texts.

Possible NIS involvement suggests national-security interest. If the Asia Business Daily account is accurate, the country's intelligence service found the data before the victim did. Defenders should assume this directory may already be held by actors other than the operator of the hosting page.

The data took 32 hours to remove. KEPCO acted within minutes on its own side but depended on a third-party operator to take the content down. Every outlet highlighted this delay.

Korean regulators are increasingly fining companies over employee data leaks. In August 2026 the Personal Information Protection Commission (PIPC) fined HD Construction Equipment 73.5 million won, and its affiliate HD Korea Shipbuilding and Offshore Engineering 4.8 million won, over a leak of 9,503 workers' names and employee ID numbers (Yonhap). The regulator found that the companies "did not restrict access between their systems even when such access was not needed." That case concerned employee records, not customer records, and the PIPC still acted. According to Korean Data Law Notes, Korean law sets separate 72-hour clocks for notifying data subjects and for reporting to the PIPC or KISA. Since 11 September 2026 there has also been a duty to notify when a leak is suspected but not yet confirmed. The sources do not say when KEPCO filed with the regulator.

The incident is part of a wider pattern. Every outlet places it within a recent run of personal-data breaches in the Korean financial sector.

The Attack Technique

Unknown. KEPCO says the exact cause is still under investigation.

What has been reported: - The Asia Business Daily says the webpage was not open to the general public and that there are so far no signs of external hacking attempts. - The same outlet says KEPCO believes the incident is unrelated to the recent AI-based hacking attacks in the financial sector. - KEPCO blocked access to its internal employee-data systems first. This suggests it believed the data came from those systems, but it does not show how the data got out.

These details fit several explanations: an insider leak, misconfigured sharing, a third-party or contractor upload, or a compromised account. Without a primary source or forensic findings, no explanation can be confirmed. Readers should also note that KEPCO's ICT subsidiary, KEPCO KDN, runs SCADA monitoring and internal platforms for the group (Noah Intelligence). No source links KDN to this incident.

What Organizations Should Do

  1. Treat your staff directory as sensitive data. Apply access controls and data-loss-prevention monitoring to HR and directory systems. Alert on bulk exports, especially exports that include phone numbers. Sources that look low-risk feed most targeting.
  2. Separate systems that do not need to talk to each other. The PIPC's HD Construction Equipment finding was about unnecessary access between systems. Audit which applications, affiliates and contractors can query employee records, and remove any access that is not required.
  3. Watch for your own data appearing outside. Monitor paste sites, file-sharing services, closed forums and leak sites for your domain, employee-number formats and internal department names. KEPCO may have learned of its exposure from a government agency. Aim to find yours first.
  4. Prepare takedown contacts before you need them. Draft takedown requests in advance, keep escalation contacts for common hosting providers, and set up legal and CERT channels. This shortens the time between discovery and removal.
  5. Brief exposed staff right away and focus on social engineering. Warn them about pretext calls and texts, enforce call-back verification for credential resets and payment changes, and give extra attention to OT, IT-admin and finance staff.
  6. Map your regulatory deadlines now. Under Korean law, both 72-hour clocks, and the newer duty to notify on suspicion, can start before you know the cause. Build these into your incident-response playbook rather than working them out during an incident.

Sources: Korea Electric Power Corporation exposes personal data of 24,000 em... | KEPCO Says Data of 24,000 Employees Exposed Online - Seoul Economic... | Personal Data of 24,000 KEPCO Employees Exposed... No Customer Info... | Korea Electric Power Corp. Exposes Personal Info of Entire Staff...... | Personal information of more than 24,000 KEPCO employees exposed…De... | HD Construction Equipment fined 73.5 mln won for employee data leak... | KEPCO KDN introduces pioneering AI tools to modernise South Korea’s... | Korea breach notification: the 72-hour clock, who to tell, and what...