Yonhap News: “Personal Information of Adoptees and Missing Children on CDs and External Hard Drives Lost…Data on 1.17 Million People Leaked.”
Originally published in Korean to Yonhap News: August 27, 2026 (Korea date).
ChatGPT English translation posted to Paperslip on August 26th, 2026 (US date).
BOLDS and blue highlighting ours.
Yonhap News Agency
Personal Information of Adoptees and Missing Children on CDs and External Hard Drives Lost… Data on 1.17 Million People Leaked
Reporter: Cha Min-ji
Published: August 27, 2026, 11:00 a.m.
Updated: August 27, 2026, 11:00 a.m.
“National Center for the Rights of the Child fined KRW 860 million, the largest-ever fine imposed on a single public institution
Personal information of 47 adoptees and prospective adoptive parents also leaked through the Adoption Information Disclosure Request System
[Plaque of the Personal Information Protection Commission]
[Provided by the Personal Information Protection Commission]
SEOUL (Yonhap) — The National Center for the Rights of the Child has been fined nearly KRW 900 million after more than 1.17 million records containing personal information of missing children, adoptees, and others were leaked, and the agency failed to properly notify authorities and affected individuals of the breaches.
The fine is the largest ever imposed on a public institution.
For public institutions that have no revenue or for which it is difficult to calculate revenue, the Personal Information Protection Commission imposes a fixed-amount fine.
The Personal Information Protection Commission announced on the 27th that, at a plenary meeting held on the 26th, it decided to impose an administrative fine of KRW 863 million and a penalty of KRW 22.2 million on the National Center for the Rights of the Child for violating the Personal Information Protection Act in connection with three personal-information breach incidents involving missing children and adoptees.
The commission also ordered corrective measures, recommended disciplinary action and improvements, and ordered the results of the sanctions to be made public. It additionally recommended that the Ministry of Health and Welfare, the supervising ministry, strengthen its oversight of the National Center's overall personal-information management system.
[Provided by the Personal Information Protection Commission]
From 2013 to 2022, the National Center carried out a digitization project to convert adoption records and admission cards for missing children into Excel files and scanned documents.
During this process, a contractor delivered the digitized materials to the National Center on removable storage devices, including external hard drives, USB memory sticks, and CDs.
The National Center discovered only later that some of the removable storage devices had gone missing, while conducting an internal inspection into allegations of inadequate management of its adoption-record digitization project.
The investigation found that the National Center had stored the devices in office cabinets or drawers without properly implementing security measures such as designating personnel responsible for managing them or maintaining logs recording when the devices were taken out or returned. It also failed to encrypt removable storage devices containing resident registration numbers.
As a result, the agency was unable even to determine exactly when or how the personal information had been leaked.
Due to this poor management, one CD containing digitized adoption records from 2013 to 2018 was leaked. The breach exposed approximately 1.14 million pieces of personal information, including about 300,000 resident registration numbers, as well as adoptees' names, addresses, contact information, and other data.
One external hard drive containing digitized admission-card records for missing children from 2020 was also lost, exposing approximately 30,000 pieces of personal information, including about 15,000 resident registration numbers, along with names and the dates, times, and locations of incidents involving missing children.
The total scale of the leak therefore exceeded 1.17 million records.
The investigation found that, even after becoming aware of the breaches, the National Center failed to notify affected parties and report the incidents within 72 hours, as required.
The Personal Information Protection Commission also found that, during the digitization process, National Center employees shared their system-access accounts with the contractor and that the National Center had failed to properly manage and supervise the contractor.
In connection with this breach, the commission therefore decided to impose a fine of KRW 810.5 million and a penalty of KRW 22.2 million on the National Center, while also ordering corrective measures, recommending disciplinary action, and requiring publication of the sanction results.
[National Center for the Rights of the Child]
[Photo by Lee Chung-won]
Separately, another personal-information breach occurred in the Adoption Information Disclosure Request System operated by the National Center.
The National Center established the system and, from March through April, sequentially launched four application functions for adoptees and prospective adoptive parents.
During this process, documents submitted by adoptees applying for certificates confirming their adoption status and documents submitted by prospective adoptive parents were stored in the same database table. At the same time, application numbers for the two functions were each assigned sequentially starting from “1,” but the system was not adequately tested for security and data integrity.
As a result, adoptees and prospective adoptive parents who had the same serial number were able to view documents submitted by one another. Personal information belonging to 47 people — 37 adoptees and 10 prospective adoptive parents — including their names, dates of birth, and sex, was exposed.
For this incident as well, the Personal Information Protection Commission imposed a fine of KRW 52.5 million on the National Center for violating its obligation to implement security measures and decided to make the sanction results public.
The Personal Information Protection Commission emphasized, “In the case of public institutions, public interest in and expectations regarding personal-information protection are even higher, and the meaning and value of the personal information they process are even greater. They must therefore make every effort to protect personal information.”
The commission also said it would take strict action, including recommending disciplinary measures, against institutions that delay or fail to carry out breach notifications.”
Cha Min-ji (chacha@yna.co.kr)