[비즈한국] The former CEO of ‘Modu-ui Jiin,’ a marriage agency, has been sentenced to prison in an appellate trial for commissioning a hacker to steal approximately 300,000 member records from a competitor for business purposes. The court also upheld the conviction for unauthorized access to a competitor’s customer management system to acquire member data. With recent large-scale data breaches highlighting the critical need for information security within the marriage agency industry, the discovery of a CEO actively targeting competitor data for business growth has sparked concerns regarding personal information management practices in the sector.
On the 18th of last month, the Seoul Central District Court Criminal Division 8-3 (Presiding Judge Choi Jin-sook) sentenced Mr. Shin, the former CEO of Techie Inc., to 10 months in prison for violating the Personal Information Protection Act. The company’s fine was maintained at 7 million KRW, consistent with the first trial. Although the first trial previously sentenced Mr. Shin to two years in prison, suspended for three years, and 160 hours of community service, the appellate court overturned the original ruling and redetermined the sentence.

Commissioned hacker multiple times over a year via Telegram
In September 2020, Mr. Shin commissioned a professional hacker via Telegram to breach the web servers of a competing marriage agency and a blind-date app, receiving customer data files from the hacker in return. The court concluded that Mr. Shin had decided to acquire competitor customer databases by purchasing them or hacking into their servers as he pursued his marriage agency business around June of the same year.
Following the purchase of customer data from two competitors, Mr. Shin further requested the hacker to breach the servers of Marriage Agency A and dating app B. These criminal acts continued until December 2021. The total number of competitor member records acquired by Mr. Shin through hacking or purchase amounted to 306,117. These records contained not only names and contact information but also details such as age, educational background, and occupation. According to the court verdict, Mr. Shin paid the hacker approximately 10 million KRW for these criminal acts.
The court also upheld the charge regarding the unauthorized acquisition of data prior to hiring the hacker. On July 7, 2020, at a cafe in Gangnam-gu, Seoul, a person named Seong, then affiliated with a competitor and discussing a startup venture with Mr. Shin, accessed the customer management system on Mr. Shin’s laptop. When it was discovered that the laptop could access the system without separate authentication, Mr. Shin used it to gain unauthorized access and captured screenshots containing the names, ages, contact information, and occupations of 116 members. Seong, who later became a co-CEO of Modu-ui Jiin, was investigated but was not indicted due to a lack of evidence.
Modu-ui Jiin is a marriage platform that has established a presence in an industry dominated by existing giants like Duo and Gayeon, leveraging YouTube content marketing and Artificial Intelligence (AI) matching. The operator, Techie, entered the market in July 2020 by adding marriage information services to its business objectives. Around the same time, influencer Seong, known as a couple-matching manager, garnered attention by joining as a co-CEO. Although current CEO Seong was investigated regarding this case, the investigation concluded that the crimes were committed solely by Mr. Shin.

Marriage agencies handling sensitive data are practically ‘defenseless’ against hacking
Member data held by marriage agencies is considered more sensitive and closely tied to private life than standard service data; if leaked, it can lead to privacy violations far beyond simple identity theft or spam. This is because these agencies accumulate not only basic personal details but also marriage history, family relations, academic background, occupation, physical conditions, and individual tendencies. Critics argue that since the market grows based on a membership base, the responsibility of operators to securely manage customer data is increasing.
In fact, at Duo, a major domestic marriage agency, an employee’s work PC was hacked in January of last year, leading to the leak of personal information for 427,464 full members. The leaked data included not only names, contact numbers, and addresses but also religion, academic history, workplace names, health information, and marital history such as divorce and remarriage. The incident only came to light about three months later through an announcement by the Personal Information Protection Commission (PIPC).
The PIPC imposed a fine of 1.197 billion KRW and a penalty of 13.2 million KRW on Duo, stating that the company’s post-incident response was insufficient, including failure to notify members after identifying the leak. Currently, about 1,000 victimized members have initiated a class-action lawsuit for damages.
Regarding the Modu-ui Jiin case, the appellate court noted that the compromised data included private details such as gender, age, education, and occupation, and that the victims have not received any fair compensation. The court did take into account that Mr. Shin was a first-time offender and showed remorse.
According to corporate registration, Mr. Shin took office as CEO in February 2020 and held the positions of CEO and internal director until recently, resigning this past June.
Modu-ui Jiin did not provide a response when asked about plans for compensating victimized members, remedial measures, and strategies to prevent future recurrences.