[비즈한국] It has been confirmed that the hackers who infiltrated Seoul's public bicycle service, 'Ttareungyi,' and leaked a massive amount of user personal information were teenagers. While one of the suspects reportedly stated they did it to “show off their skills,” this incident leaves points that are difficult to dismiss as merely the deviant act of ‘juvenile hackers.’ This is because rather than employing high-level infiltration techniques, they exploited vulnerabilities in the server structure that allowed information to be queried without subscriber authentication.
The investigation has now expanded to include the accountability of the Seoul Facilities Corporation, the current operating entity, and a preliminary investigation is underway. Experts point out that instead of pinning this on individual negligence, the overall security design and inspection systems of public platforms must be re-examined.

According to the Seoul Metropolitan Police Agency, the suspects are accused of infiltrating the Ttareungyi server for two days starting on June 28, 2024, when they were middle school students, and downloading information for approximately 4.62 million subscriber accounts. The leaked items include IDs, mobile phone numbers, email addresses, addresses, dates of birth, gender, and weight, but do not include names or resident registration numbers.
At the time, a DDoS attack targeting the Ttareungyi app server occurred, and when the app went down for about 80 minutes, the Seoul Metropolitan Government reported the disruption to the Ministry of the Interior and Safety. As of now, no evidence has been found that the personal information has been redistributed or used for financial gain.
The two individuals met through online communities and social media and are said to have never met in person. Telegram conversations secured during the investigation reportedly contain evidence of them plotting the crime. It was discovered that after identifying the server's vulnerabilities, one suspect suggested, “Let's download everything,” and they divided tasks to collect the information. They stated that they usually had an interest in the field of information security and had taught themselves related techniques.
This case was uncovered not through internal monitoring, but during an investigation into cyberattacks targeting other shared mobility companies. The investigation expanded when a large file of member information was identified during a forensic analysis of the suspects' electronic devices. One suspect was apprehended in October 2024, and the accomplice was identified and apprehended in January of this year through methods such as tracing Telegram accounts.
The police applied for arrest warrants twice for the suspect deemed to have played a leading role, but the prosecution did not request them, considering factors such as the fact that they were juvenile offenders.
The infiltration method confirmed during the investigation was less about using high-level technology and more about exploiting server settings that allowed information queries without subscriber authentication or separate permission verification.
The investigation found that relatively simple structural vulnerabilities were used for the infiltration. Given that millions of pieces of information were exfiltrated over two days, it is being suggested that the mechanisms controlling mass queries and the monitoring systems for early detection of abnormal signs were insufficient.

An investigation into the Seoul Facilities Corporation, the operating entity, is also ongoing. The corporation is being criticized for not taking any action despite being aware of the hacking in 2024. According to the Seoul Metropolitan Government, after the incident occurred, the cloud server management contractor delivered a report containing evidence of the personal information leak to the Seoul Facilities Corporation in July of that year; however, it was found that the corporation ignored the report without following legal requirements such as reporting to the Personal Information Protection Commission or notifying citizens. The police are conducting a preliminary investigation into the relevant personnel, focusing on potential violations of the Personal Information Protection Act.
The direct entity responsible for managing the Ttareungyi app's personal information is the Seoul Facilities Corporation, while the Seoul Metropolitan Government is the supervisory body. Since this process involves determining whether the access control, authorization management, and breach response systems of public platforms were institutionally appropriate rather than just pinning it on individual employee negligence, it may lead to discussions on systemic improvement.
The Personal Information Protection Commission also began its own investigation after receiving a report of the leak from the police on the 30th of last month. The investigation is expected to clarify the exact circumstances of the incident, whether personal information was indeed leaked, potential legal violations, and the specific scope of the technical flaws.
Although this incident occurred about 1 year and 8 months ago, it was made public when the police, who were investigating a different cyberattack, found the member information files while analyzing the items seized from the suspects. After being notified by the Seoul Metropolitan Police Agency on the 27th of last month about the suspected leak, the Seoul Metropolitan Government conducted an internal investigation and confirmed that initial responses had been inadequate.
Han Jung-hoon, the Seoul Metropolitan Government's Transportation Operations Officer, held a briefing on the 6th and stated, “During the investigation, we confirmed that the corporation did not take appropriate measures despite being aware of the personal information leak in July 2024. Depending on the results of the investigation, we will clarify the accountability of the relevant corporation officials and review follow-up measures such as exclusion from duties if necessary.”
Ttareungyi is a public bicycle service introduced by the Seoul Metropolitan Government in 2015, with rental stations installed across Seoul to serve as a short-distance transportation method for citizens. Since its launch, it has surpassed 250 million cumulative uses, and the number of uses in 2024 was recorded at 43.85 million. Compared to 10 years ago, the scale of usage has increased by about 400 times.