Six categories of data leaked, including home addresses and phone numbers; breach went undetected from July 2025 to June 2026

An apology posted on the Cultural Heritage Administration's website [Screenshot from the Cultural Heritage Administration website]
An apology posted on the Cultural Heritage Administration's website [Screenshot from the Cultural Heritage Administration website]

South Korea's Cultural Heritage Administration inadvertently exposed the personal information of 909 people working in the cultural heritage trading industry while publishing heritage-related data online. Six categories of personal data were leaked in total, including home addresses and mobile phone numbers.

The agency disclosed the breach in an apology posted June 6 on its official website, saying it had confirmed that a file containing personal information had been attached to a public disclosure document titled "2024 Cultural Heritage Trading License Status."

The leaked data covered six fields for each of the 909 individuals — who work in the cultural heritage trading sector, including antique dealers — comprising home addresses, mobile phone numbers, dates of birth, whether trading status reports had been submitted, whether ledger seals had been obtained, and whether the individuals held concurrent businesses.

The file had been publicly accessible on the agency's website since July 18, 2025. The agency removed the post after one of the affected individuals filed a complaint on June 4, around 10 a.m., upon discovering the contents of the file.

"We offer our deepest apologies," the agency said in its statement. "Upon confirming the facts, we immediately blocked access to the file and deleted the post, and are now conducting an inspection to determine the circumstances of the leak and assess any damage."

The agency said it is also notifying affected individuals directly. "We are carrying out necessary measures, including individual notifications to data subjects in accordance with relevant laws," it said, adding that it would "comprehensively review posting and inspection procedures, strengthen personal data protection education and internal management systems, and do our utmost to prevent a recurrence."


terry@heraldcorp.com