Ttareungi. /Courtesy of Chosun DB

Twenty-three users who suffered personal information leaks from Seoul's public bicycle service "Ttareungi" filed a damages lawsuit against Seoul Facilities Corporation.

According to legal sources on the 24th, MIBYUN-Lawyers for a Democratic Society submitted a complaint to the Seoul Central District Court on the 22nd on behalf of 23 Ttareungi users. The claim amount is 300,000 won in consolation money per user.

The representatives from the Digital Information Committee of MIBYUN-Lawyers for a Democratic Society argued that Seoul Facilities Corporation violated the duty to take safety measures under Article 29 of the Personal Information Protection Act by leaving the system such that personal information could be accessed without an authentication token. They also noted that the corporation violated the notification duty under Article 34 of the same law by concealing signs of the personal information leak for nearly two years.

MIBYUN-Lawyers for a Democratic Society plans to consider follow-up lawsuits once other victims' intent to participate is confirmed.

According to police, the Ttareungi app was hacked by two teenagers who were middle school students in June 2024. The personal information of 4.62 million subscribers, who make up the majority of users, was leaked. The leaked data includes IDs, mobile phone numbers, email accounts, addresses, dates of birth, gender, and weight. Names and resident registration numbers were not included.

The personal information leak came to light in January when police were investigating another case related to a DDoS (distributed denial-of-service) attack. The Seoul city government asked police to investigate, saying the corporation recognized the leak but took no initial response for nearly two years.

A, who hacked the Ttareungi app, said the act was driven by "curiosity and a desire to show off." B, the ringleader, exercised the right to remain silent.

※ This article has been translated by AI. Share your feedback here.