Pedestrians walk past the BGF Retail headquarters in Gangnam-gu, Seoul. (Yoon Chang-bin/The Korea Herald)
Pedestrians walk past the BGF Retail headquarters in Gangnam-gu, Seoul. (Yoon Chang-bin/The Korea Herald)

A cyberattack on CU's parcel delivery service has exposed customers' personal information, including names, addresses and mobile phone numbers. The full scale of the breach has yet to be confirmed.

BGF Networks said Saturday it had confirmed that a hacker attack on Wednesday compromised customer data. The company did not disclose the number of affected customers but said the breach involved IDs, passwords, names, dates of birth, gender, addresses, email addresses and mobile phone numbers.

BGF Networks posted a notice on the CU POST website, saying it "sincerely apologizes." The company said it detected and responded to signs of unauthorized system access by an unidentified hacker at around 3:30 p.m. Wednesday, during which personal information was exfiltrated.

The company immediately blocked the attacking IP address, completed remediation measures and activated its incident response team as part of a broader security policy overhaul. It has also filed reports with the Personal Information Protection Commission and the Korea Internet & Security Agency.

BGF Networks said passwords are encrypted and therefore safe, but urged customers who use the same password on other websites to change it as a precaution.

In a text message sent to customers, the company said the scope of the leak was limited to information belonging to registered online members and did not include third-party details, such as recipients' information entered at the time of shipment.


choijh@heraldcorp.com