Invest2 publishers3 min readPublished
KEPCO Discloses Leak of 24,000 Employee Records, Says Incident Unrelated to Recent Bank Hacks
Korea Electric Power Corp. said names, affiliations and phone numbers of about 24,000 employees appeared on an outside website. What it costs the state-run utility, and anyone pricing governance at state-linked firms, turns on a cause still under joint investigation with law enforcement.
The Investor · Invest desk

What happened
- The utility notified affected employees and finished deleting the leaked information at around midnight Friday, according to Yonhap.
- KEPCO set up an emergency response center and is running a joint investigation with law enforcement into how the data got out.
- Customer information, which KEPCO keeps in a system separate from employee records, was not part of the exposure.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- exposure The near-term risk sits with the 24,000 staff, whose names and numbers can be used for phishing calls, emails and texts, the channels KEPCO itself warned them about.
- contradiction Timing groups this with the Hana, KB Kookmin and Shinhan leaks, but KEPCO says it appears unrelated, so any wider discount on state-linked firms rests on a link the evidence has not established.
- decision Investors pricing Korean state-linked firms have to wait on the cause: a finding that data came out of the internal employee systems KEPCO locked down would turn an HR incident into a controls question.
"If damage occurs or is expected and is reported to us, we will conduct the necessary investigation and proceed with remedies including compensation," a KEPCO official said [10]. The pledge is the only part of the utility's response with money attached, and it pays per reported case. The roughly 24,000 people on the exposed list [1] set the maximum number of claimants. The bill depends on how many of them file and what they can show.
What the file contained keeps that number low. It held names, affiliations and phone numbers, and no unique identifiers such as resident registration numbers [2]. Contact details are still enough to start a phishing attempt, and KEPCO has told affected staff to be careful with incoming phone calls, emails and text messages [9]. The likeliest losses fall on employees who answer one.
The case for repricing state-linked Korean firms rests on contagion. KEPCO's disclosure follows what Yonhap described as back-to-back leaks of customer data in hacking attacks at Hana Bank, KB Kookmin Bank and Shinhan Bank [12]. A state-run power company on the same list invites a wider governance discount. The evidence so far does not connect the cases. A KEPCO official said the company is still verifying the exact cause and that the leak appears unrelated to the AI-related hacking attacks at financial firms [13].
The investigation can end three ways. If an employee or a vendor posted a page by mistake, this stays an HR-data incident with phishing risk attached. If the file was pulled from the internal systems that hold employee records, the finding is about access controls at a state utility. The company's first step suggests it took that second possibility seriously: "As soon as we became aware of the situation, we blocked access to internal systems containing employee personal information," the official said [5]. A trail back to the bank attackers would overturn the company's early read [13] and strengthen the repricing case.
I think the first outcome is the one to price until investigators say otherwise. That means costs limited to the response itself and whatever employee claims arrive. The counter-case is serious. A list pairing 24,000 names with affiliations and phone numbers tells an attacker whom to call in which part of the company [1][2]. Evidence of an intrusion, or staff reporting a run of targeted calls, would prove the contained-cost view wrong.
KEPCO's response so far is an emergency response center and a joint investigation with law enforcement [8]. It has no customer notice to run, because customer information sits in a separate system and was not compromised [11]. Its compensation offer waits for claims [10]. It also asked the outside site's operator to take the material down: "We also asked the operator of the external website to delete the exposed information, and it has been removed," the official said [6]. Yonhap reported that deletion was completed around midnight Friday [7]. The public statement came on Sunday, three days after detection at about 3:59 p.m. on Thursday [1].
What to watch
- KEPCO's recurrence-prevention measures once the cause is identified, and whether they extend to systems beyond employee records.
- The number of employee damage reports and compensation claims filed under the utility's conditional pledge.
- Whether Korean authorities apply the breach-response demands placed on financial firms to state-run utilities and other public companies.