[비즈한국] While companies slapped with massive fines following the amendment of the Personal Information Protection Act are filing lawsuits in succession, the court has issued its first ruling regarding a sanction under the strengthened standards. Regarding the personal information leak at the online lecture site "Daesung MyMac," the court ruled that the 600 million won fine imposed by the Personal Information Protection Commission (PIPC) was lawful. The court determined that the operator, Digital Daesung068930, failed to fulfill its safety measure obligations, thereby providing the opportunity for the unauthorized theft of personal information belonging to approximately 95,000 users. Attention is now focused on whether similar conclusions will be reached for other companies that have filed similar lawsuits.

95,000 Member Records Leaked
It has been confirmed that Digital Daesung, an affiliate of Daesung Academy, recently lost an administrative lawsuit it filed to challenge the sanctions imposed by the PIPC following a large-scale personal information leak that occurred early last year. On the 14th, the Seoul Administrative Court (Division 14, Presiding Judge Lee Sang-deok) ruled against the plaintiff in the case filed by Digital Daesung against the PIPC to cancel the fine.
The court stated, "It is difficult to view that the company fulfilled the safety measures reasonably expected by social consensus, such as detecting and responding to attempted leaks by analyzing IP addresses or taking measures on the personal information processing system to prevent leaks," and added, "The plaintiff's claim is dismissed."
In January, Daesung MyMac suffered a breach where the personal information of approximately 95,000 members was stolen due to "credential stuffing" attacks and "Cross-Site Scripting (XSS)—a method of stealing information by executing malicious commands when viewing posts—on the website's bulletin board.
Credential stuffing is an attack technique that uses large lists of already leaked IDs and passwords, utilizing automated programs to randomly attempt logins on a target site. This year alone, companies like GS Retail007070 and T-money have been breached by such attacks. After successfully logging in using credentials gained through stuffing, the hacker wrote posts containing XSS commands on a specific page within the Daesung MyMac site. When an employee viewed these posts, the employee's session information was stolen, leading to the leak of personal data for 95,171 members, including IDs, partially masked names, phone numbers, and email addresses.

The PIPC, which launched an investigation following Digital Daesung's report, concluded two months later in March that the company had violated obligations under the Personal Information Protection Act, including safety measures and the duty to notify users of leaks, resulting in a fine of 613 million won, a penalty of 3.3 million won, and a public disclosure order. It was noted that as the site is primarily used by students preparing for university entrance exams, they should have paid special attention to data protection, yet management was negligent. At the time, the total amount of personal data collected and held by Digital Daesung reached 1.138 million records (as of the end of January last year).
“Hacking Prevention Measures Were Insufficient”
Digital Daesung's argument that it had sufficiently installed and operated systems to detect and block outside intrusions was not accepted. XSS attacks are one of the most common hacking techniques frequently attempted online. If input values are validated for malicious commands, they can be prevented to a certain degree, and the court pointed this out. Daesung MyMac, which obtained Information Security Management System (ISMS) certification from the Korea Internet & Security Agency (KISA), had installed and operated anti-DDoS, Unified Threat Management (UTM), web firewalls, and DB access control solutions, and received security monitoring services from SK Broadband. After detecting the XSS attack through AhnLab, they did take measures such as blocking the hacker's IP.
Guides from the PIPC also mention measures such as validating input values from the post-creation stage to prevent malicious commands from being registered. However, it was revealed that at the time of the incident, the bulletin board lacked policies to automatically block XSS attacks and failed to implement policies to detect or block the 4,026 abnormal login attempts that occurred over a five-minute period.
The court ruled, "Even if the company took measures like blocking IPs after detecting the attack, these were merely retroactive responses to a hack that had already occurred; they cannot be considered sufficient safety measures to prevent or block XSS attacks themselves."
Regarding the company's claim that input validation processes were impractical due to potential errors given the nature of the site, the court pointed out, "One could assume a compromise where the person in charge could appropriately manage an XSS auto-block policy by quickly setting exceptions for blocks."
Companies Hit by Large Fines File Lawsuits
The Daesung MyMac case is the first instance where new standards were applied following the implementation of the revised Personal Information Protection Act, which increased the burden of fines. Previously, fines for violating the act were based on "up to 3% of revenue related to the illegal act," but since September 2023, this has been expanded to "3% of total revenue." While revenue unrelated to the violation is to be excluded, the burden of proof lies with the company.
Although large-scale leaks occurred at companies such as Golfzon215000 (7.5 billion won) and SK Stoas (1.4 billion won) in November of the same year, the PIPC's administrative decisions were made in May of last year and January of this year, respectively. Similar to Digital Daesung, Golfzon suffered from a credential stuffing attack, while SK Stoas was hit by ransomware.

For Daesung MyMac, the PIPC calculated a baseline amount of 730 million won by excluding revenue unrelated to the violation from the average annual revenue of the past three years and applying a 0.68% rate. After adjustments, such as adding half the amount due to the violation period exceeding two years and a reduction for cooperation with the investigation, a fine of 600 million won was determined.
The court judged that the PIPC's basis for calculating the fine and its application were mostly appropriate. It also ruled that the revenue items Digital Daesung claimed were unrelated to site safety, such as "revenue from textbooks written by instructors," "revenue from external sales like EBS textbooks," and "bundled product revenue," were indeed included in the scope of online lecture services.
Last month, another personal information leak occurred at the Daesung Institute for Academic Development, an affiliate of Daesung Academy that provides textbooks. Regarding the 1st instance ruling and inquiries about measures to prevent recurrence, Digital Daesung stated, "We are doing our best to prevent recurrence regarding the personal information leak."
Amidst the recent series of personal information leaks across all sectors, this ruling clarifies that installing security systems or taking formal measures alone does not fulfill the requirement for safety measures. Most importantly, it is significant that the court judged the revenue exclusion items claimed by the company conservatively and limitedly acknowledged the room for revenue to be considered unrelated to illegal acts. Operations, management, responses, and methods before and after security incidents were reflected as grounds for determining illegality and as factors in the penalty.
Hwang Seok-jin, a professor at Dongguk University's Graduate School of Information Security, stated, "An increasing number of companies are opting to let the court decide based on clear grounds rather than accepting the fines determined by the PIPC. It is expected that such administrative litigation will continue, and many cases will likely go all the way to the Supreme Court."