
Personal information belonging to nearly 3,000 customers was leaked from Gabia (079940.KQ), a South Korean groupware software developer.
Gabia said in a notice on its website on the 23rd that the breach occurred on the 21st. As of 3 p.m. on the 23rd, 2,998 customers had been confirmed as affected. The exposed data included names, user IDs, email addresses and mobile phone numbers. The company said no account passwords had been leaked so far.
According to Gabia, the breach was carried out by an external attack. The attacker gained access to internal systems by exploiting parts of the company's web service that did not adequately verify external requests. Customer data was transmitted externally in the process. The company said it has blocked the access route and the accounts used in the attack, and has preserved logs and other evidence for analysis.
Gabia first detected the data theft at 1:05 p.m. on the 21st. It then reported the incident to the Personal Information Protection Commission and the Korea Internet & Security Agency (KISA). The company is now investigating the cause of the breach and whether additional data was exposed, working alongside the relevant authorities.
Gabia said it will notify affected customers individually by email or text message. "As a company responsible for keeping customer information safe, we take this incident very seriously," the company said. "We will fundamentally review our security systems and make every effort to prevent a recurrence."







