Home chevron_right Security chevron_right Article

서울시, 따릉이 개인정보 유출 사건 형법·개인정보 보호법 위반 조사

서울시 공공자전거 서비스 '따릉이' 이용자의 개인정보 유출 사실이 확인된 가운데 관리기관인 서울시설공단이 이를 사전에 인지하고도 고의로 은폐했는지에 대한 조사가 본격화하고 있다. 공단이 개인정보 유출 사실을 사전에 알고도 알리지 않았다면 직무유기 등 형법을 비롯해 개인

이정원기자

Feb 08, 2026 • 1 min read

Seoul Facilities Management Corporation is under investigation for allegedly withholding information about a data breach involving users of the public bike-sharing service 'Ddareungi'.

It is suspected that the corporation knew about the data breach, which occurred in July 2024, but did not disclose it for about 1 year and 6 months. The breach was reportedly caused by a DDoS attack, potentially exposing the personal information of up to 4.55 million users.

The leaked information may include IDs, phone numbers, and optional details such as email, date of birth, gender, and weight. The corporation claims that names and addresses were not part of the leaked data.

If it is found that the corporation intentionally withheld information about the breach, they could face legal consequences under criminal laws and the Personal Information Protection Act. The breach should have been reported to relevant authorities within 72 hours, according to the Act.

The Personal Information Protection Commission plans to impose severe administrative penalties, including heavy fines, if the corporation is found guilty of concealing the breach. They emphasized conducting a thorough investigation and holding those responsible legally accountable.

#security #technology

에이테크뉴스 이정원기자(ethegarden@nolm.kr)