Sogang University in Seoul, South Korea, has disclosed a major cybersecurity incident involving the personal information of nearly 180,000 current and former members of its community. The affected database included students, employees, and alumni, significantly extending the impact beyond people currently studying or working at the institution.
The university announced the breach in a public apology, explaining that unidentified attackers had obtained information associated with its integrated login accounts. The compromised records contained names, university identification numbers, affiliations, email addresses, mobile phone numbers, and encrypted passwords used for the institution’s integrated authentication system.
Sogang University said more sensitive categories of information were not included in the compromised data. South Korean resident registration numbers were not exposed, and the university reported that financial account information was also unaffected.
The intrusion began on August 11, when unauthorized access originating from outside South Korea reached the university’s systems. The activity was discovered three days later, on August 14. Once administrators identified the intrusion, they blocked the malicious IP address, restricted the affected service, and isolated the relevant network environment to contain the incident.
The university subsequently began examining its internal servers for security weaknesses and brought in outside cybersecurity specialists. Additional monitoring and security measures are being developed while investigators continue examining the circumstances surrounding the attack.
Because encrypted passwords were among the information exposed, Sogang University has advised students, employees and alumni to replace their passwords. Anyone who reused the same password for services outside the university would also have reason to replace those credentials as a precaution.
The combination of names, email addresses, telephone numbers, university affiliations and identification information could also make convincing impersonation attempts easier. The university has therefore warned affected people to be particularly cautious about unexpected emails, text messages and telephone calls following the breach.
One prominent former student reportedly caught up in the incident is former South Korean President Park Geun-hye. Park entered Sogang University’s electronics engineering program in 1970 and graduated in 1974. Local reporting cited in coverage of the breach says that entering her name and student identification number into the university’s breach-checking service produced a notification indicating that personal information associated with the account had been leaked.
Her reported inclusion illustrates the unusually long historical reach of the compromised records. The incident does not appear to have been limited to active university accounts, meaning information associated with people who left Sogang decades ago may have remained within the affected system.
The university has sent apology notices to students and employees and said additional instructions will be provided as its response continues. It has also pledged to review and strengthen its security systems following the incident.
Several important questions remain unanswered publicly. The identity of the attackers has not been established, and the university has not disclosed the specific method used to gain initial access. There is also no confirmed information in the university’s announcement establishing what the attackers intended to do with the stolen records.
For now, the confirmed impact centers on personal and integrated-login information associated with almost 180,000 people. The university says its immediate containment measures have been completed while internal vulnerability checks, external security assistance, and additional monitoring continue.