Another Leak From Korea's Police Database: The Insider Problem

What happened
Gyeonggi Bukbu (Northern Gyeonggi) Provincial Police announced on September 12 that it had arrested a serving officer, identified only as "A," the previous day on charges of violating Korea's Personal Information Protection Act. In July, acting on an outside request, the officer allegedly looked up personal data on the police internal network, passed it to a third party, and accepted money in return.
Investigators are still establishing how many times the officer ran searches and how much cash changed hands. The person who paid for the lookups is expected to be summoned for questioning. Korean outlets have reported the officer's rank inconsistently — some as gyeonggam (superintendent), others as gyeongsa (assistant inspector) — so the identifying details are not yet settled.
What makes this more than a one-off: the same provincial police agency arrested another officer in late August, this one from South Gyeongsang Province, for handing internal-network data to a private detective. Two nearly identical cases surfaced within roughly a month.
Why it matters: legitimate access is the hardest breach to stop
Insider threat is the category security teams consistently rank as the hardest to defend against. External hacking can be filtered to some degree by perimeter controls — firewalls, intrusion detection, anomaly signatures. An insider uses credentials the organization granted them, so in the logs the abuse looks indistinguishable from routine work.
And a police database is not an ordinary corporate customer table. Korea's police internal network aggregates resident registration details, addresses, family relationships, vehicle records, and criminal and investigative history — enough to reconstruct a person's entire life. When that flows to a private investigator or a paying client, the downstream uses are stalking, aggressive debt collection, and surveillance of ex-partners. One leaked record here carries a different order of harm than a leaked shopping account.
Why it keeps happening
The structure of both recent cases is the same: an officer receives a request, runs the query, takes payment, and is caught only afterward. The system relies on detection after the fact, not prevention at the point of access.
The technical countermeasures are well understood. Purpose-bound access control that forces the officer to log a case number and reason before querying. User and entity behavior analytics (UEBA) that flags searches unrelated to an officer's assigned cases, or run at odd hours. Dual authorization for bulk lookups. Korean banks already apply versions of this to customer-record access. The real tension is operational: the tighter the control, the slower a live investigation moves — and where to set that line is the actual policy question, not whether the technology exists.
What it means for ordinary citizens
There is essentially nothing an individual can do to prevent this kind of exposure. The data was never voluntarily handed over, and the lookup happens through a channel the subject never consented to. Under Korean privacy law, once a leak is confirmed the data subject must be notified — so whether you receive that notice is the practical starting point for any response. If stalking or intimidation follows, the leak pathway itself is worth pushing investigators to treat as part of the case.
The deeper fix is transparency of the access log. If citizens could review who queried their records, when, and under what stated purpose, the cost of an improper lookup rises sharply. With two cases in about a month now public, the argument that this needs addressing at the system level — rather than through individual disciplinary action — becomes harder to dismiss.
Sources
- [속보] 경찰 내부망 개인정보 유출하고 금품 받은 현직 경찰관 검거 — kwnews.co.kr
- 돈 받고 개인정보 유출한 현직 경찰관 체포 — news.sbs.co.kr
- 경찰 내부망 개인정보 또 유출‥30대 현직 경찰관 체포 — imnews.imbc.com
- 개인정보 외부 유출하고 돈 받은 현직 경찰관 — news1.kr
- '개인정보 유출·금품 수수 혐의' 경기북부지역 경찰관 검거 — newsis.com