Seoul's 'Hackers' Exposed: The Perils of Public Data, or a Convenient Diversion?

Same playbook, different decade: The Seoul Metropolitan Police Agency announced two high school students, then middle schoolers, had been referred to prosecutors without detention for allegedly hacking the Ttareungyi public bike server. They purportedly stole personal information belonging to 4.62 million members, including phone numbers, email addresses, and home addresses, over two days in June

2024. The official narrative suggests a simple case of teenage digital delinquency, perhaps aiming to sell the data, yet no evidence of such sales has surfaced. This convenient conclusion begs scrutiny. Consider the history of government entities, globally, deflecting responsibility for cybersecurity lapses. In 2015, the US Office of Personnel Management suffered a breach compromising the data of

21.5 million federal employees, including highly sensitive background investigation materials. Initial reports heavily implied foreign state actors were responsible, a claim that allowed the agency to frame itself as a victim of sophisticated espionage rather than the perpetrator of woefully inadequate security protocols. In both scenarios, the blame was neatly outsourced: to teenagers in Seoul,

to rival nations in Washington. Such narratives conveniently sidestep questions regarding inadequate data protection infrastructure or budgetary shortfalls in securing public services. The sheer volume of data compromised suggests significant vulnerabilities, not just clever kids with keyboards. Over 4.6 million records for a bike-sharing service is an astonishing breach volume, implying systemic

Read the full story on The Piaz