Personal data breaches are occurring one after another at small and midsize corporations and startups. Recently, customer data leaks occurred at the well-known language academy JLS, the early-childhood education matching platform Jaranda, and the delivery agency platform Fly.
In particular, these corporations handle sensitive information beyond customers' contact details, including children's information, addresses, bank account information, and common entrance passwords, raising concerns about secondary damage.
According to small and midsize corporations and the security industry on the 24th, the operator of Jeongsang Language Academy, JLS(040420), said it detected and blocked abnormal mass external access to member information on the 17th, reported the incident on the 21st, and confirmed a personal data leak on the 18th during the subsequent investigation. The leaked information includes name, date of birth, gender, phone number, email, address, school, grade, ID, and encrypted password.
The company said it does not collect resident registration numbers or other unique identifiers. The exact scale of the leak and the access route are under investigation, and it filed reports with the relevant agencies and requested an investigation by law enforcement.
Signs of personal data theft were also confirmed at the early-childhood education matching platform Jaranda. Jaranda said on the 21st that an outsider accessed the visit log DB and it confirmed indications that some information was stolen. The leaked information includes subscribers' mobile phone numbers and the names of children in lessons, visit date and time, subjects, and photos.
Jaranda said it blocked external access, inspected and removed remaining access routes of the same type, and established a monitoring system for abnormal overseas transmissions.
At the delivery agency platform Fly, personal data of administrators, riders, stores, and ordering customers was leaked. For administrators and riders, names, contact information, addresses, bank account information, and resident registration numbers were found to have been leaked. For stores, names, dates of birth, business names, contact information, business registration numbers, and addresses were leaked, while ordering customers had addresses, contact information, and some common entrance passwords exposed.
Fly said that after recognizing the incident on the 18th, it blocked abnormal access routes and began security inspections and cause analysis. It also reported the incident to relevant agencies, including the Korea Internet & Security Agency (KISA), the Personal Information Protection Commission, and the Cyber Investigation Unit of the Korean National Police Agency. The exact cause of the incident and the scope of the leak is under investigation.
Experts note that small and midsize corporations and startups may face blind spots in security management because they lack the personnel and resources for personal data protection compared with large corporations. Many corporations have IT or security staff double as personal data protection officers rather than appointing a dedicated person, making access control to personal data and anomaly monitoring relatively vulnerable.
Education and delivery platforms, in particular, can be attractive targets for attackers. Education companies hold personal data of guardians and children, lesson schedules, and photos, while delivery platforms handle not only addresses, contact information, and bank account information but even common entrance passwords. It is also difficult to rule out the possibility that leaked information will be misused for secondary crimes such as phishing or impersonation.
Kim Yong-dae, a professor in the School of Electrical Engineering at KAIST, said, "Large corporations have the capacity to invest in their own security personnel and systems, but small and midsize corporations face limits in security management due to a lack of specialized personnel and resources," adding, "Policies are needed for the government to support basic security solutions and remote monitoring services so small and midsize corporations can establish at least a minimal security framework."