Page title background (PC version)Page title background (mobile version)

Case Analysis / Legal Updates

Daeryun Law LLC, with expertise across practice areas,
provides analysis of court rulings and legal issues.

Administrative Litigation | Company I, Subject to a Penalty Surcharge for a Personal Information Leak, Loses Its Revocation Lawsuit

This is a case of Company I, a recruitment information company, which received a decision dismissing its administrative litigation. It filed an administrative lawsuit seeking revocation of the penalty surcharge against the Personal Information Protection Commission, but the claim was dismissed.

CONTENTS
  • 1. Company I, Which Filed the Administrative Litigation, and the Background of the Penalty Surcharge Disposition
    • - The Arguments of Company I, Which Filed the Administrative Litigation Seeking Revocation of the Penalty Surcharge
  • 2. Company I, Which Filed the Administrative Litigation, and the Court That Dismissed the Claim
    • - Company I, a Recurrence of a Personal Information Leak in 2025 as Well
  • 3. The Administrative Litigation, and Daeryun's Strategy

1. Company I, Which Filed the Administrative Litigation, and the Background of the Penalty Surcharge Disposition

Prevailing in administrative litigation against the Personal Information Protection Commission

Company I, which filed the administrative litigation, received a penalty surcharge imposition of approximately 70 million won from the Personal Information Protection Commission (hereinafter the defendant) on August 30, 2023.

The plaintiff, Company I, is an information and communications service provider and a personal information controller that operates a recruitment information website.

Between September 29 and 30, 2020, a hacker attempted a credential stuffing attack, randomly entering IDs and passwords that had been unlawfully obtained through the dark web and other sources.

As a result, of the more than two million login attempts, about 36,000 succeeded, and the personal information of 35,076 individuals, including their resumes, was accessed.

Company I recognized this on the day of the incident and reported it to the relevant authorities. After an investigation in 2022, the defendant imposed a penalty surcharge of 70,609,000 won and an administrative fine of 3.6 million won on August 30, 2023.

In response, Company I filed an administrative lawsuit seeking revocation of the disposition.

The Arguments of Company I, Which Filed the Administrative Litigation Seeking Revocation of the Penalty Surcharge

The arguments of Company I, which filed the 🔗administrative litigation seeking revocation of the penalty surcharge, are as follows.

1. Absence of Grounds for the Disposition

Company I argues that it had already established and operated an IDS (intrusion detection system), an IPS (intrusion prevention system), and its own monitoring system.

It also stated that it had carried out all the measures set out in the "Commentary on Protective Measures" published by the Personal Information Protection Commission and the Korea Internet & Security Agency, and that it had implemented the security measures that could reasonably be expected.

In other words, it emphasized that the incident arose from users' carelessness, such as using the same password elsewhere, and was not the fault of the company.


2. Deviation from and Abuse of Discretionary Power

Company I stated that it was improper to calculate the period of the violation as beginning in 2018.

Its argument is that, at that time, equipment with an HTTPS decryption function was not yet mandatorily required.

Company I emphasized that, compared with other similar cases, the defendant required additional authentication only of the company and failed to consider users' carelessness, and that this amounted to a violation of the principles of equality and proportionality.

2. Company I, Which Filed the Administrative Litigation, and the Court That Dismissed the Claim

The court that heard the administrative litigation dismissed Company I's claim.


The court pointed out that there had been deficiencies in the operation of the system and that there were problems with the timing and manner of Company I's response measures, and it held that the defendant's calculation of the penalty surcharge was proper.

1. Deficiencies in the Operation of the System

The court pointed out that Company I used an IDS without an HTTPS decryption function. This was because such an IDS cannot detect encrypted hacking.

In addition, some of the IPS's detection policies were set to "Allow," so the credential stuffing attack was not detected.

In fact, Company I failed to detect more than two million abnormal login attempts.

The court pointed out that, in reality, the users' reports were received before the breach was detected, and it emphasized that there were clearly deficiencies in the operation of the system.


2. The Timing and Manner of the Response Measures

The court pointed out that, although the hacker's attack began on September 29, Company I's firewall blocking was carried out on the morning of September 30.

In addition, subsequent supplementary measures, such as blocking 30 or more logins within one hour, introducing a CAPTCHA, and applying two-factor authentication, were all implemented only after the incident.

The court pointed out that the above supplementary measures were feasible with the technology available at the time and did not involve significant cost, and it emphasized that they could have been introduced before the incident, stressing that Company I's response measures had not been active.


3. The Propriety of the Calculation of the Penalty Surcharge

The court determined that the period of Company I's violation, running from around the time of its establishment (around 2018) to the 2020 incident, exceeded two years and was to be regarded as a long-term violation.

In addition, the defendant reduced the base amount of 88,261,000 won by 20 percent on grounds such as the voluntary report and cooperation, arriving at a final amount of 70,609,000 won.

The court stated that grounds for reduction or exemption are discretionary matters under the public notice and that this did not constitute a deviation from discretion, and it held that the defendant's calculation of the penalty surcharge was proper.

Company I, a Recurrence of a Personal Information Leak in 2025 as Well

However, it was reported that Company I experienced yet another personal information leak in March 2025.

It was confirmed that there were indications that some customer information had been leaked due to an external attack.

Company I explained that, following the incident, it had completed measures such as blocking the relevant IP addresses, inspecting and supplementing system vulnerabilities, and strengthening system monitoring. Given the repeated personal information leaks, however, the Personal Information Protection Commission's imposition of a penalty surcharge and its corrective order are expected to become stricter.

3. The Administrative Litigation, and Daeryun's Strategy

Regarding the administrative litigation, the court determined that Company I had not fully implemented the technical and managerial measures required by law and had lacked effective operation.

This administrative litigation served as a case reaffirming that the mere installation of a formal security system cannot be regarded as fulfilling one's legal obligations, and that the speed and manner of the response after a security incident, as well as whether preventive measures were in place, are all reflected as factors in determining the penalty surcharge.

Under Article 29 of the Personal Information Protection Act, a personal information controller must take the technical, managerial, and physical measures necessary to ensure safety, such as establishing an internal management plan and retaining access records, so that personal information is not lost, stolen, leaked, forged, altered, or damaged.

In addition, Supreme Court precedent specifies that the determination is made by considering, on the whole, "whether the controller took the protective measures reasonably expected under generally accepted social norms, in light of the level of technology at the time of the hacking, the scale of the company's business, the cost of security, and the likelihood of harm."

Accordingly, a company should, taking into account the scale of its business and the sensitivity of the personal information it holds, actively build a security system at a realistically achievable level and carry out regular inspections and supplementary measures.

Whether the technical measures were sufficient is a matter that goes beyond a mere IT issue; it is a matter that must be legally proven, namely whether the controller took the protective measures that could be expected under the generally accepted social norms at the time.

This past April, Company S, a telecommunications company, also received a report of hacking damage after USIM personal information was leaked, and the Cyber Investigation Unit of the Seoul Metropolitan Police Agency launched an investigation.

The Personal Information Protection Commission does not impose a disposition merely because personal information has been leaked.

Whether appropriate safety measures were taken against information leaks caused by malicious code attacks becomes an important issue.


At Daeryun Law Firm LLP, a team of attorneys experienced in numerous personal information matters comprehensively analyzes the effectiveness of the security system, its manner of operation, and the appropriateness of the incident response, and proposes solutions.

Background

Daeryun's Key Strengths

Daeryun's exclusive AI · IT
litigation strategies
Over 240
key members
1,200+ cases
handled monthly

* January 2026 Bar Association Transit Permit Issuance Criteria

*Complies with Korean Bar Association Advertising Regulations Article 4 Paragraph 1

Attorney
Legal consultation booking

All consultations are conducted by specialized lawyers after reviewing the case. It is carried out on a reservation basis to ensure a professional process.We encourage you to make an early reservation for consultation, and request adherence to the scheduled time. We will do our best to provide a satisfying consultation.

Phone
consultation 1800-7905

Available 24/7, 365 days
for consultation requests

Phone booking

KakaoTalk
consultation

KakaoTalk channel

Daeryun Law Firm Attorneys

KakaoTalk booking

Online
consultation

We provide tailored
legal services.

Online booking
Related Information
Quick Menu

KakaoTalk