First, see what leaked
If you received a breach notice or heard about it in the news, first check which items leaked. A leak of only your name and phone number is very different, in both risk and response, from a leak of passwords, resident registration numbers, or account and card details. In South Korea, companies must notify users once a leak is confirmed, so check the notice or announcement for the leaked items, timing, the company's measures and a contact point. Scam texts also imitate such notices, so instead of tapping links, go directly to the company's official site or app.
If passwords were included
If passwords or account details leaked, change that service's password immediately. If you used the same password elsewhere, change those too, because attackers commonly try leaked ID and password pairs on many sites. Turn on two-step verification wherever possible and check recent login history for unfamiliar devices or locations.
- Change the password of the breached service at once
- Change it on other services where you used the same or similar one
- Change your email account password first of all
- Turn on two-step verification and review login history
If ID numbers or ID cards were included
If your resident registration number or a copy of your ID leaks, someone may use your identity to open phone lines or take out loans. Look into an identity theft prevention service that lets you see your mobile subscriptions and block new ones, and a system for registering with financial institutions that your data was exposed so they check transactions in your name more strictly. If you lost your ID card, report it lost. Korea also has a system for changing a resident registration number, but its requirements are strict, so check the official guidance.
If card or account details were included
If card numbers or account details leaked, contact your card company and bank immediately, explain the situation and ask whether reissuing the card or restricting transactions is needed. Turn on payment alerts and check statements and account history more often than usual for a while. If you see an unknown payment or transfer, reporting it to the financial institution right away is the fastest way to limit the damage. If money has already gone, report it to the police as well.
Watch for follow-up scams
Right after a breach, scams using it as a pretext increase. They send links or call asking you to claim compensation, check whether you were affected or run a security check, and then ask for your details again. Remember the rule: companies and public agencies do not ask for passwords, verification codes or card PINs by text or phone.
- Don't tap links in texts; visit the official site directly
- Never give verification codes or passwords over the phone
- Be suspicious if asked to install an app
- Warn your family about the same tricks
Where to report and get advice
Counseling and reports on privacy infringement are handled by the personal information infringement report center run by the Korea Internet and Security Agency. If you're unhappy with the company's response or want compensation, you can apply for mediation with the Personal Information Dispute Mediation Committee. When many people are affected by the same incident, collective mediation may take place. If money was actually lost or your identity was misused, reporting to the police comes first.
Keep a record
Save the breach notice text or email, the company's announcement screen and the dates of the steps you took. Noting when you changed passwords, which financial institutions you contacted and when, and whether you got suspicious messages gives you a basis for explaining the history later when you seek relief or mediation. If you suffered actual losses, keep the statements and receipts that show them. This article is not legal advice. For your specific situation, consult a lawyer or a public legal aid service such as the Korea Legal Aid Corporation.
Habits that limit the damage
You often can't prevent a leak yourself, but everyday habits can shrink the damage. Use a different password for each service, and close accounts on sites you no longer use to reduce where your data sits. Don't enter information that isn't required when signing up, and when sending a copy of your ID, you can write its intended purpose on it. See also the guides on password management and two-step verification.
🌍 Search the web for this
Each button runs this keyword on that search engine