Seoul is offering free one-month bike-sharing passes to more than 4.6 million people whose personal information was exposed in a cyberattack against its Ttareungi public bicycle rental service. The compensation follows a 2024 data breach that affected millions of registered users and prompted an investigation by South Korean authorities.
The Seoul Facilities Corporation, which operates the service, said eligible users will receive a 30-day pass that allows one hour of free bike use each day. According to local media, the coupons will be distributed through the Ttareungi mobile app in August and must be redeemed within three months. Existing subscribers will be able to activate the benefit after their current pass expires.
The breach occurred in June 2024 when two teenagers gained unauthorized access to Ttareungi’s servers and extracted personal information belonging to about 4.62 million users. Authorities said the stolen data included names, phone numbers, dates of birth, account IDs, gender information, and body weight.
Depending on the information users had provided when registering, some affected records also contained email addresses, postal codes, home addresses, or guardian details. Officials have not said that every affected account contained all of these data fields.
After discovering the intrusion, the Seoul Facilities Corporation reported the incident to the National Police Agency and the Personal Information Protection Commission. The organization also notified affected users shortly after identifying the breach.
An emergency task force was established with the Seoul Metropolitan Government to investigate the weaknesses that allowed the attackers to compromise the service. Officials said the review focused on vulnerabilities in the application’s authentication system.
The corporation also strengthened security controls after the incident. According to officials, the vulnerable system was patched, monitoring capabilities were improved, and additional security testing was introduced to reduce the risk of similar attacks.
Authorities said they examined the compromised databases to determine what information had been exposed for individual users. Notifications explained which categories of personal data may have been affected and advised customers to remain alert for potential scams.
Although exposed personal information can be used in phishing campaigns or identity fraud, Seoul officials said they have not confirmed any cases in which the stolen Ttareungi data has been misused. They also said they have not found evidence that the information has been distributed for criminal purposes.
Following the breach, Seoul Facilities Corporation President Han Kook-young apologized to users and pledged to strengthen the service’s security. He said the organization would overhaul its protection measures so residents could continue using Ttareungi without concerns about their personal information.
The operator also advised users to be cautious of unsolicited phone calls or text messages claiming to come from the bike-sharing service. Customers were urged not to open suspicious links or install unknown applications that could be used in phishing attacks.
According to South Korean media, the two teenagers suspected of carrying out the intrusion have been referred to prosecutors. The legal proceedings are ongoing, while authorities continue monitoring for any confirmed misuse of the data stolen during the 2024 breach.