News & Insights
Latest news and legal insights from HANBYOL LAW LLC.
Back to List
뉴스2015년 12월 1일
[보안뉴스]개인정보 유출 뽐뿌, 과징금 폭탄에다 손배 소송도 시...
Privacy leak Pumppu faces fine bomb, damages lawsuit
Privacy Breach Victims Launch Lawsuit Against Pumppu
[Security News Minseah] The first lawsuit for damages has been filed against Pumppu, an Internet community website that suffered a massive personal information leak.

On September 11, a hacker exploited a SQL injection vulnerability on the Pompu website to steal personal information of its members. The personal information of more than 1.95 million members was stolen, including usernames, one-way encrypted passwords, dates of birth, emails, nicknames, encrypted marketplace passwords, and registration dates.
Some members who were notified by email of the leak of personal information from Pumppu filed a lawsuit (Seoul Central District Court 2015 Suit No. 6891432) on November 13 against Pumppu Communication Co.
In traditional data breach claims, the victim of a data breach had to prove specific damages in court in order to recover. In reality, it was difficult for victims to receive compensation for personal information breaches.
However, the story changed on May 28, 2014, when the Act on Promotion of Information and Communications Network Utilization and Information Protection (hereinafter referred to as the Act on Authentic Networks) established a provision related to the statutory damages system. As a result, victims of personal information leaks can now claim damages of up to 3 million won without having to provide specific proof of the amount of damage.
Hanbyul Jung, an attorney at the firm, said, "The revised Orthodox Network Act, which contains provisions related to the statutory damages system, came into effect on November 29 last year. In this case, the newly established statutory damages system is naturally applicable."
According to Article 28 of the Information and Communication Network Act, when information and communication service providers handle personal information, they must take technical and administrative measures to prevent loss, theft, leakage, alteration, or damage to personal information.
Technical and administrative measures to prevent the loss, theft, leakage (disclosure), alteration or damage of personal information means the establishment and implementation of an internal management plan, as well as the installation and operation of access control devices to block external illegal access to personal information, and other protective measures necessary to ensure the safety of personal information.
Hanbyul, a law firm, said, "Personal information of members was leaked through a hacking attack method by SQL injection. The leakage of personal information by SQL injection means that the security of the website itself is very vulnerable." "Therefore, as an information and communication service provider, negligence for neglecting to diagnose and check the above vulnerabilities can be recognized."
"The plaintiffs' homepage ID, encrypted homepage password, date of birth, email address, homepage nickname, encrypted marketplace password, date of registration, and membership score constitute 'personal information' as defined in Article 2 (1) (6) of the Information and Communications Network Act," it added.
Depending on the outcome of the case and the amount of damages awarded, the implications for other companies that have suffered data breaches in the past or may do so in the future could be significant.
On the other hand, on November 20, Pumppu was fined 120 million won ($15 million) and ordered to establish and implement corrective measures to prevent recurrence due to the lack of technical and administrative protection measures for personal information by the Korea Communications Commission. [boan5@boannews.com)]
[Security News Minseah] The first lawsuit for damages has been filed against Pumppu, an Internet community website that suffered a massive personal information leak.

On September 11, a hacker exploited a SQL injection vulnerability on the Pompu website to steal personal information of its members. The personal information of more than 1.95 million members was stolen, including usernames, one-way encrypted passwords, dates of birth, emails, nicknames, encrypted marketplace passwords, and registration dates.
Some members who were notified by email of the leak of personal information from Pumppu filed a lawsuit (Seoul Central District Court 2015 Suit No. 6891432) on November 13 against Pumppu Communication Co.
In traditional data breach claims, the victim of a data breach had to prove specific damages in court in order to recover. In reality, it was difficult for victims to receive compensation for personal information breaches.
However, the story changed on May 28, 2014, when the Act on Promotion of Information and Communications Network Utilization and Information Protection (hereinafter referred to as the Act on Authentic Networks) established a provision related to the statutory damages system. As a result, victims of personal information leaks can now claim damages of up to 3 million won without having to provide specific proof of the amount of damage.
Hanbyul Jung, an attorney at the firm, said, "The revised Orthodox Network Act, which contains provisions related to the statutory damages system, came into effect on November 29 last year. In this case, the newly established statutory damages system is naturally applicable."
According to Article 28 of the Information and Communication Network Act, when information and communication service providers handle personal information, they must take technical and administrative measures to prevent loss, theft, leakage, alteration, or damage to personal information.
Technical and administrative measures to prevent the loss, theft, leakage (disclosure), alteration or damage of personal information means the establishment and implementation of an internal management plan, as well as the installation and operation of access control devices to block external illegal access to personal information, and other protective measures necessary to ensure the safety of personal information.
Hanbyul, a law firm, said, "Personal information of members was leaked through a hacking attack method by SQL injection. The leakage of personal information by SQL injection means that the security of the website itself is very vulnerable." "Therefore, as an information and communication service provider, negligence for neglecting to diagnose and check the above vulnerabilities can be recognized."
"The plaintiffs' homepage ID, encrypted homepage password, date of birth, email address, homepage nickname, encrypted marketplace password, date of registration, and membership score constitute 'personal information' as defined in Article 2 (1) (6) of the Information and Communications Network Act," it added.
Depending on the outcome of the case and the amount of damages awarded, the implications for other companies that have suffered data breaches in the past or may do so in the future could be significant.
On the other hand, on November 20, Pumppu was fined 120 million won ($15 million) and ordered to establish and implement corrective measures to prevent recurrence due to the lack of technical and administrative protection measures for personal information by the Korea Communications Commission. [boan5@boannews.com)]
▶ Law Firm (Limited) Hanbyul Pomppu Personal Information Leakage Class Action Cafe
http://cafe.naver.com/ppomppuclassaction
Source:보안뉴스

