INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Korean Power Company's 20,000 Employees' Personal Info Leaked Internally
| 2026-10-06 15:13 MEDIUM LOW DATA BREACH
Executive Summary
AI-generated
On October 4, approximately twenty thousand four hundred employees' personal information was exposed on an external website of South Korea's power company KEPCO. The US-based cybersecurity intelligence firm Intel Threats confirmed that the data is related to KEPCO's internal security systems and provided materials including /[IOC HIDDEN • LOGIN REQUIRED], /[IOC HIDDEN • LOGIN REQUIRED], and /insadb.sql, which are believed to be related to KEPCO's internal systems. This incident affects approximately twenty thousand four hundred employees of KEPCO, whose names, positions, phone numbers, facial photos, and facial recognition information were exposed. The attack works by exploiting vulnerabilities in KEPCO's external security systems, allowing the attackers to access sensitive data. As a result of the breach, KEPCO has taken measures to block related internal system access and established an emergency comprehensive situation room to coordinate with related institutions; however, further investigation is needed to confirm whether the leaked information includes not only employee personal information but also internal security infrastructure information.
Technical Mitigations AI-generated
• Patch the /<a href="/auth/login?next=/detail/sOzlFKEBAhlSTKR_Cj9A" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN • LOGIN REQUIRED]</span></a> and /<a href="/auth/login?next=/detail/sOzlFKEBAhlSTKR_Cj9A" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN • LOGIN REQUIRED]</span></a> files to remove sensitive information, such as facial recognition features vector.
• Verify that insadb.sql does not contain any data related to access control systems or biometric information.
• Block IP addresses associated with Intel Threats' C2 analysis materials, including the ones linked to /<a href="/auth/login?next=/detail/sOzlFKEBAhlSTKR_Cj9A" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN • LOGIN REQUIRED]</span></a> and /<a href="/auth/login?next=/detail/sOzlFKEBAhlSTKR_Cj9A" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN • LOGIN REQUIRED]</span></a>.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
FA•••••.csv
bu•••••.csv
na•••••.csv
rt•••••.txt
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
energyenergy
Incident Timeline
October 4
Threat actors used an external website to expose the personal information of approximately twenty thousand four hundred KEPCO employees.
Click on any entity below to view its context and source!
target_region
Korea, Republic of
Exclusive: Korean Power Company's 20,0004 employees' personal information exposed, internal security information also leaked, thorough investigation of internal security infrastructure needed..
South Korean power company Korea Electric Power Corporation (KEPCO) has confirmed that the personal information of approximately twenty thousand four hundred employees was exposed on an external website…
organisation
Korean Power Company's
Exclusive: Korean Power Company's 20,0004 employees' personal information exposed, internal security information also leaked, thorough investigation of internal security infrastructure needed..
South Korean power company Korea Electric Power Corporation (KEPCO) has confirmed that the personal information of approximately twenty thousand four hundred employees was exposed on an external website…
organisation
Korea Electric Power Corporation
Exclusive: Korean Power Company's 20,0004 employees' personal information exposed, internal security information also leaked, thorough investigation of internal security infrastructure needed..
South Korean power company Korea Electric Power Corporation (KEPCO) has confirmed that the personal information of approximately twenty thousand four hundred employees was exposed on an external website…
organisation
KEPCO
Exclusive: Korean Power Company's 20,0004 employees' personal information exposed, internal security information also leaked, thorough investigation of internal security infrastructure needed..
South Korean power company Korea Electric Power Corporation (KEPCO) has confirmed that the personal information of approximately twenty thousand four hundred employees was exposed on an external website…
victims
20,0004 employees
Exclusive: Korean Power Company's 20,0004 employees' personal information exposed, internal security information also leaked, thorough investigation of internal security infrastructure needed..
South Korean power company Korea Electric Power Corporation (KEPCO) has confirmed that the personal information of approximately twenty thousand four hundred employees was exposed on an external website…
2026/10/06
Threat actors used US-based Intel Threats to target South Korea's KEPCO, exposing approximately 20,000 employees' personal information and internal security data.
Click on any entity below to view its context and source!
organisation
/insadb.sql
The US-based C2 analysis and threat intelligence company provided materials that include /busan_face_users.csv, /naju_access_users.csv, /insadb.sql, which are believed to be related to KEPCO's internal systems.
organisation
Current Exposure Information Reveals
South Korea's Current Exposure Information Reveals Approximately Twenty Thousand Employees' Names, Positions, and Phone Numbers
organisation
Phone Numbers
South Korea's Current Exposure Information Reveals Approximately Twenty Thousand Employees' Names, Positions, and Phone Numbers
organisation
Intel
The threat intelligence materials from the US-based Intel Threats include multiple files related to internal systems.
organisation
Naju Head Office
/naju_access_users.csv is also believed to be related to the access control system of Naju Head Office, and it includes the employee ID, name, department, position, phone number, facial photo path, and facial recognition features vector.
organisation
IP
External intelligence reports contain files such as FA_cam_ip_password.csv, rtsp_metadata.csv, rtsp.txt, and camera_site_summary.csv, which appear to include camera IP addresses, passwords, and video stream connection information.
organisation
ISG
However, the external threat intelligence data revealed a broader range of integrated security systems (ISG), video management systems (VMS), CCTV-related account information, access control data, employee facial photos and facial recognition information, personnel databases, remote management information, and more.
organisation
VMS
However, the external threat intelligence data revealed a broader range of integrated security systems (ISG), video management systems (VMS), CCTV-related account information, access control data, employee facial photos and facial recognition information, personnel databases, remote management information, and more.
organisation
CCTV
However, the external threat intelligence data revealed a broader range of integrated security systems (ISG), video management systems (VMS), CCTV-related account information, access control data, employee facial photos and facial recognition information, personnel databases, remote management information, and more.
organisation
the Human Resources
A database dump of personnel information, known as insadb.sql, has been analyzed, and it appears to include data from the Human Resources department and organizational information.
Tactical Metrics
Metrics
victims
200,004
Employees
Click for context!
Exclusive: Korean Power Company's 20,0004 employees' personal information exposed, internal security information also leaked, thorough investigation of internal security infrastructure needed..
South Korean power company Korea Electric Power Corporation (KEPCO) has confirmed that the personal information of approximately twenty thousand four hundred employees was exposed on an external website…
Intelligence Sources
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T09:20
Comprehensive Tactical Telemetry
Highly Correlated Entities
13x
organisation
Identified Entity
Current Exposure Information Reveals
entity
2x
target region
Target Country
United States
country
Contextual Telemetry
Context Block
4 METRICS
source region
Origin Country
United States
country
industry
Targeted Sector
Energy
sector
timeline
Temporal Reference
October 4
date
victims
Employees
200,004
employees
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.