Summary: Dozens of login IDs, passwords and social security numbers were exposed in a Government24 hack on August 17, 2026. An apology and notice posted on August 20 confirmed the breach and estimated roughly 100 affected cases, but the notice was removed after 30 days under South Korea's data-protection rules. Social posts in late September labeled screenshots of the notice and related reporting "fake news" because the notice was no longer visible; experts call for legal reform and a permanent public breach archive to improve transparency.
Government24 Hack Confirmed After Social Posts Call Official Notice 'Fake News'

Dozens of login IDs, passwords and social security numbers were exposed in a cyberattack on South Korea's government portal, Government24, on August 17, 2026. The portal published an apology and notice on August 20 confirming the breach, but that notice was later removed after 30 days under the country's personal data protection rules — prompting some social media users in late September to declare screenshots of the apology and related reporting "fake news."
What Happened
Government records and an interior ministry spokesperson confirm that the portal experienced illegal access on August 17. An apology posted on August 20 stated that "a thorough investigation is underway" and noted it was difficult to precisely assess the scale of the leak, estimating "about 100 cases" affected while urging anyone who suspected their information had been compromised to contact authorities.
Apology excerpt (Aug 20): "A thorough investigation is underway, but it is difficult to assess the precise scale of the data leak and the number of those affected (estimated to be about 100 cases)."
Why Some Called It 'Fake News'
In late September, several Korean-language posts on X (formerly Twitter) labeled screenshots of the apology and reporting as "fake news," pointing out that the notice was no longer visible in Government24's public "notices" section. The interior ministry explained the notice had been removed from public view after 30 days in line with South Korea's personal data protection rules and was accessible only via an internal link. The August 20 notice is nevertheless preserved in an archived snapshot on the Wayback Machine.
Scope And Context
Data provided by the interior ministry to a local lawmaker on September 29 said the breach involved "dozens" of login IDs, passwords and social security numbers, though the full extent remains unknown. Government24 had faced fines for private data leaks in 2024 and 2025; officials say this incident appears to be the first time confidential portal data was accessed through hacking.
Private-sector breaches have been widespread in South Korea: state figures indicate more than 43 million people — nearly 90% of the country's population — had personal information reported leaked in the first half of 2026, and in June 2026 e-commerce giant Coupang was fined $408 million over a 2025 breach affecting more than 30 million customers.
Reactions And Calls For Reform
Seoul-based outlet Edaily reported on the Government24 breach; after the story circulated, some users attacked the reporting and the journalist as purveyors of "fake news." Edaily and the reporter declined to comment when contacted by AFP.
Pang Hyo-chang, policy chief at the Citizens' Coalition for Economic Justice and a tech policy expert, said current personal data protection laws should be reformed to give citizens clearer, timelier rights to know whether their data has been exposed. He urged authorities to establish a public, permanently archived online platform for breach notifications to improve transparency about how personal data is handled.
Why This Matters
The episode highlights two related risks: the real, recurring threat of large-scale data breaches in a hyper-connected society, and the potential for legitimate official notices to be mischaracterized as misinformation when routine data-protection practices (such as removing a public notice after a statutory posting period) reduce the visibility of the original statement. Experts argue better public notification systems would reduce both harms.
Help us improve.


































