Thoughts on the Recent Corporate Hacking Incidents in Korea
Following the recent server hacks at KT (a major Korean telecom) and Lotte Card, and earlier incidents at SKT and SBI Savings Bank, massive corporate data leaks just keep happening. What's terrifying is that these might not be the result of a one-off hack, but rather years of meticulous work. What on earth is the problem that keeps causing this to repeat?
Having worked at several companies, the common issue I've noticed is that "no company handles security properly." And by company, I don't just mean the executives or a specific department. I mean the "company itself," encompassing the board of directors, all employees, and even subcontractors and cleaning staff. Writing passwords on Post-its, sharing them over messengers, or using public Wi-Fi—the most basic security rules you're supposed to follow at work are often easily dismissed in reality with a simple, "I'm too busy, who has time for that?" I think Korean society today, and honestly every country in 2025, lacks the fundamental concept of IT security.
The government says it's encouraging investment in IT security, but this is a superficial idea that misses the core of the problem. Currently, security personnel receive the lowest salaries and have no real voice within the company. Compared to sales or development teams who "make" money, the security staff who "protect" the money aren't properly valued. Let's say an employee writes a password in their personal notebook or takes a picture of it. In the financial sector where security is crucial, this should be grounds for termination, but it's hard to imagine anyone actually being disciplined for it. If you compare it to how disciplinary action is taken for sexual harassment cases, it's clear how low our society's standards are regarding security issues.
I believe the only way to solve this, whether short-term or long-term, is through strong punitive damages. If these incidents had happened in the US, SKT would have had to pay trillions of KRW (approx. billions of USD) in fines and compensation. The KT and Lotte Card hacks could lead to fraudulent payments, making it a serious issue where courts should even consider shutting the companies down. From large conglomerates down to small and medium-sized enterprises or local merchants, they must be held strictly accountable when data leaks occur. Only then will our society finally recognize the importance of IT security and properly evaluate the worth of security personnel. Right now, we only invest in the people who bring in money, but moving forward, we need to realize the importance of the people who protect it.
Some might think this problem is isolated to the financial sector, but is it really? In the AI era, are we making a genuine effort to protect that crucial data? I suspect that banks, brokerages, crypto exchanges, and maybe even government infrastructure have already been breached. The best example we should look to is the security culture of large manufacturing conglomerates. They strictly prevent internal technology from being leaked by employees. If someone is caught walking out with blueprints, they are handed over to the police without exception, whether they are a managing director or an executive vice president. You could argue this is possible because manufacturing servers are isolated from the outside world, but ultimately, they respond so strongly because they know the "shock" of a leak is massive. Similarly, if our society truly realizes the shock and ripple effects of personal data leaks and strengthens punitive damages, IT security will no longer be pushed to the back burner.
I had Gemini edit this post, and it wrote it in a really cringey way. It's not my usual tone, so it feels very awkward.
