Kakao Games reported a data breach exposing identification codes and IDs for 140 customers after external attackers exploited system vulnerabilities between September 12 and 13, 2026. The company stated the leaked data carries a low misuse risk, confirmed passwords remain uncompromised, and noted that regulatory authorities have been notified.
A security breach compromised the personal data of 140 customers at Kakao Games after unauthorized external actors gained entry through system vulnerabilities, according to company disclosures reported across multiple outlets. The breach affected two company platforms, designated as Partners and RINK, triggering a 26-hour investigative window before the company formally verified that information had escaped internal perimeters.
Attack Timeline and Vulnerability Discovery at Partners and RINK
Abnormal external access began on September 12, 2026, at 10:44 p.m. and continued until September 13 at 7:37 p.m., Chosun detailed in its coverage. System monitors and subsequent log analysis allowed the company to confirm the breach at 12:50 a.m. on September 14, roughly 26 hours after the initial incursion started. Attackers targeted system flaws within the Partners and RINK services to penetrate the network.
Upon detecting the abnormal traffic, Kakao Games severed the unauthorized access routes, quarantined related accounts, and secured system logs for forensic review. Technical teams applied emergency patches, strengthened security monitoring protocols, and restricted additional access to the affected servers.
Exposed Data Elements and Risk Assessment
The exposed datasets varied by platform. The Partners service leak involved third-party identification codes or external connection IDs, while the RINK service exposure involved internal identification codes and some country codes. Company statements emphasized that the leaked information consists of internal identification values, and no leak involving highly sensitive personal information has been confirmed.

Kakao Games explained that the external connection codes, internal identification codes, and country codes are personal information with a low risk of misuse because they make it difficult to identify specific individuals.
Corporate representatives added that even where external connection IDs were compromised, user passwords remained secure and untouched according to financial news reports. Because the compromised codes operate as random numerical sequences designed to separate accounts and assets on external platforms rather than revealing human identities, direct malicious exploitation remains difficult.
Regulatory Reporting and Expert Security Analysis
Kakao Games filed formal notifications regarding the incident with the Personal Information Protection Commission and the Korea Internet & Security Agency within the 24-hour statutory window required by South Korea’s Personal Information Protection Act. Under Article 39-4 of the legislation, online service providers must report covered breaches promptly to avoid administrative fines reaching up to 30 million won.

External security specialists evaluated the firm’s defensive posture following the disclosure. Youm Heung-youl, a professor in the Department of Information Security Engineering at Soonchunhyang University, noted that contemporary firms increasingly rely on automated tools capable of blocking unauthorized traffic before data loss occurs.
User Precautions and Ongoing Investigations
Joint investigations involving external cybersecurity firms and regulatory investigators remain active to determine the complete scope of the breach as noted by industry reporting. Corporate officials issued public warnings advising customers to remain vigilant against phishing messages, smishing texts, and voice scams capitalizing on the incident.
Users were specifically urged to inspect accounts for unrequested password changes or login notifications and to avoid opening unverified URLs or attachments sent via email or text according to Hankyung reporting. Kakao Games established dedicated customer service channels to handle inquiries and assist affected individuals through dispute resolution procedures.
Kakao Games announced that it is taking measures to prevent additional damage and is actively cooperating with investigations by relevant authorities. The company stated it will provide user guidance and protection measures once the exact extent of the damage is confirmed, and apologized for the concern caused to its users.
Продолжение темы

