Invest2 publishersIndependently confirmed2 min readPublished
Kia union's 5,000-member data leak traces to a training vendor serving about 20 organizations
Malgnsoft, an online training vendor, lost data on about 5,000 Kia union members in a hack that reached about 20 of its client organizations. One of those clients is the defense ministry, so a car-plant union's risk depended on who else kept records with the same vendor.
The Investor · Invest desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- The contract was the union's: the Gwangmyeong plant union had outsourced management of its online education system and servers to Malgnsoft.
- According to Seoul Economic Daily, the attacker got in on Sept. 19, installed a backdoor and reached a database holding member records for Malgnsoft's client organizations.
- The union is investigating signs that data on some workers at Kia's Hwaseong and Gwangju plants was also exposed.
- Malgnsoft says it blocked the attack, reported it to the Korea Internet & Security Agency and the Personal Information Protection Commission, and faces further inspections.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- exposure A car-plant union's member records and defense ministry staff records fell to the same vendor intrusion, so neither client's own controls decided its exposure.
- cost The cleanup falls on the client. The union is drawing up security plans for a breach that happened on a server Malgnsoft ran.
- decision Organizations renting hosted training sites now have a question to put to vendors before signing: whether every client's records sit in one shared database.
Malgnsoft knew by Sept. 20, when it posted a notice on its website that said: "Unauthorized external access occurred to systems we manage for the operation of online education sites" [15]. The Kia union was told on Sept. 25 [8], six days after the attack and five days after that notice [18][19]. Seoul Economic Daily reported that the vendor first ran a full review, and that the union texted all members the following day [11]. The union's public statement came on Oct. 7, 18 days after the server was breached [13][20].
The 5,000 figure counts one client [1]. JoongAng Daily reported that employees at more than 20 organizations whose systems Malgnsoft managed were affected [7]. Seoul Economic Daily (which spells the vendor Malgunsoft) said about 20, and counted the Kia union among them [9][10]. Both reports name the Ministry of National Defense and the Anti-Corruption and Civil Rights Commission [7][10].
"Phone numbers and passwords were stored in encrypted form, so the actual numbers and passwords were not exposed," the union said in its text to members [5]. "The phone numbers were leaked in encrypted form, so it is unlikely that actual damage will occur," a union official told Seoul Economic Daily [12]. Names and employee ID numbers are not among the fields either statement describes as encrypted [3][5]. The union's text told members not to click links in messages from unidentified senders [11].
JoongAng Daily placed the leak after recent breaches at the banks KB Kookmin, Shinhan and Hana [6]. Seoul Economic Daily wrote that the case extends a run of hacking incidents centered on financial firms and public institutions to the industrial sector [14]. Neither report says how the bank breaches happened or how large Malgnsoft is.
Taken as an incident, the Kia case is small: phone numbers and passwords were encrypted and no further damage has been confirmed [5]. The vendor case is larger, with one backdoor and one member database serving about 20 clients [9][10]. The broadest claim, that outsourced vendors are the common route into Korean institutions, needs the bank cases to fit, and on the reporting they are tied to this one only by date. I think the concentration reading is right and the broadest one is unproven. Against that, if the encryption holds and no misuse follows, the cost of all that concentration was a round of text messages and reports to two agencies [16]. The concentration reading fails if the inspections find the attacker reached clients through separate weaknesses. Seoul Economic Daily's account describes a single database [9].
What to watch
- Whether any of Malgnsoft's other clients, the defense ministry included, publishes its own count of affected employees.
- Any confirmed misuse of the leaked names and employee ID numbers, such as phishing texts sent to union members.
- Whether investigators of the KB Kookmin, Shinhan and Hana breaches name an outside vendor as the way in.