South Korea fines HD Construction Equipment ₩73.5 mn over 9,500-worker data breach
Synopsis
Key Takeaways
South Korea's Personal Information Protection Commission (PIPC) has fined machinery firm HD Construction Equipment 73.5 million won (approximately $53,200) after a cyberattack exposed the personal data of 9,503 workers, the regulator announced on Thursday, 27 August. The breach, traced to an unidentified hacker, is among the latest in a series of corporate data security failures now drawing regulatory action in South Korea.
How the Breach Occurred
According to the regulator's investigation, an unidentified hacker infiltrated the mobile equipment management server of HD Korea Shipbuilding and Offshore Engineering — an affiliate of HD Construction Equipment — in March 2024. The affiliate's system served as the access point, allowing the attacker to pivot laterally into HD Construction Equipment's network without restriction.
The stolen data included the names and employee identification numbers of 9,503 workers, covering both direct employees and contractor personnel. The regulator found that the two companies had failed to restrict inter-system access even in cases where such access was operationally unnecessary — a fundamental lapse in network segmentation.
Fines and Regulatory Action
The PIPC imposed a fine of 73.5 million won on HD Construction Equipment as the primary data controller. Its affiliate, HD Korea Shipbuilding and Offshore Engineering, was separately fined 4.8 million won for its role as the entry point of the breach. The combined penalty reflects the regulator's position that both entities bear accountability for the security failure.
The Broader Pattern: KT Corp Fined ₩53.9 Billion
The HD Construction Equipment action comes alongside a far larger penalty handed down in late July against wireless carrier KT Corp., which was fined 53.9 billion won (approximately $37.4 million) over a separate and significantly more severe breach. In that case, hackers accessed KT's wireless network using authentication certificates extracted from base stations the company had lost, operating undetected between 8 October 2024 and 5 September 2025.
The KT Corp. breach affected the phone numbers and mobile device identification numbers of 16,647 users. Malicious actors used the stolen data to carry out unauthorised transactions, resulting in total losses of 240 million won across 368 victims. Notably, the company only became aware of the breach after receiving a user complaint — not through its own monitoring systems. The PIPC has also ordered KT to implement corrective measures.
What This Signals for Corporate Data Security
The twin enforcement actions underscore the PIPC's increasingly assertive posture on corporate data protection. Both cases share a common thread: companies failed to implement basic access controls and breach-detection mechanisms, allowing attackers to operate unimpeded for extended periods. Critics argue that financial penalties alone may be insufficient deterrents for large conglomerates, and that mandatory security audits should accompany fines.
As South Korea tightens enforcement of its personal data protection framework, companies with interconnected affiliate networks face heightened scrutiny over how access privileges are managed across entities. Further regulatory guidance on inter-system access controls is expected in the coming months.