Han Byung-do, acting leader and floor leader of the Democratic Party of Korea, delivers opening remarks at a floor strategy meeting at the National Assembly in Yeouido, Seoul, on Monday. (Lee Sang-sub)
Han Byung-do, acting leader and floor leader of the Democratic Party of Korea, delivers opening remarks at a floor strategy meeting at the National Assembly in Yeouido, Seoul, on Monday. (Lee Sang-sub)

Han Byung-do, acting leader and floor leader of the Democratic Party of Korea, issued a formal apology Monday over a personal data breach that struck the party's member community platform, Bluwave.

Speaking at a floor strategy meeting at the National Assembly, Han said he was "sincerely sorry for causing concern to party members" over the recently disclosed breach of personal data from the Bluwave member community.

He said he had immediately directed the party's secretary-general to launch a full investigation upon learning of the incident, and that work was already underway to determine the cause, assess the scale of the breach and establish measures to prevent a recurrence.

The Democratic Party reported the breach to the Korean National Police Agency and the Personal Information Protection Commission, and asked the Korea Internet & Security Agency to conduct a security audit. Han said the party would "actively cooperate with investigations and inspections by the relevant authorities" and would review all of its computer systems to prevent further damage.

He added that the party would conduct a comprehensive overhaul of its information security framework to ensure the incident would never be repeated.

The party announced the breach on its Bluwave homepage on Friday, saying personal data belonging to some members had been exposed through an external cyberattack and that a relevant agency had alerted it to the incident. The party said it became aware of the breach on Thursday, with the estimated date of the original attack being Sept. 2 last year.

Bluwave operates as a members-only platform requiring party membership verification to create an account. It allows users to post on message boards and take online courses through the party's "Minju e-Academy" education program. The compromised data covers 17,088 Bluwave members and includes their usernames, encrypted passwords, full names and email addresses.


thanks@heraldcorp.com