South Korea data breach exposes adoptee records, drawing global criticism

May 10, 2026(5 months ago)|
Neutralkoreatimes

News Briefing

AI Summary

Key Point

A security flaw in a newly launched South Korean government portal exposed the personal records of adoptees worldwide for three days beginning April 30, prompting sharp criticism from overseas Korean advocacy groups.

What Happened

The breach affects adoptees worldwide who have sought access to their records through South Korea's child-rights system, including Korean-Americans in Southern California pursuing their origins. The incident renews debate over whether the agency meets the data-protection expectations of the global Korean adoptee diaspora.

A security flaw in a newly launched South Korean government portal exposed the personal records of adoptees worldwide for three days beginning April 30, prompting sharp criticism from overseas Korean advocacy groups.

The breach affects adoptees worldwide who have sought access to their records through South Korea's child-rights system, including Korean-Americans in Southern California pursuing their origins. The incident renews debate over whether the agency meets the data-protection expectations of the global Korean adoptee diaspora.

The National Center for the Rights of the Child launched its online application-tracking system April 30 but failed to restrict user access, allowing prospective adoptive parents who logged in to check their own status to view other applicants' records, according to The Korea Times. Exposed data included names, dates of birth, photographs, adoption records, passport information and adoptive family details. The agency notified affected individuals May 3, one day after the exposure window closed.

David Castlen, director of IT and cybersecurity at the United States Korean Rights Group, said he was among those who received breach notices. "What concerns me most is the combination of identity data with adoption-related records," Castlen told The Korea Times. "My notice was numbered 43, which suggests that at least dozens of individuals may have been affected." Castlen, who is seeking to restore his Korean citizenship, said he has since noticed a rise in calls from unfamiliar numbers.

Anja Kold, a lawyer and representative of the Danish Korean Rights Group, drew a pointed contrast with European Union standards in a statement cited by The Korea Times. "In Denmark and the EU, data protection is considered a fundamental right, and repeated breaches trigger significant sanctions, extensive regulatory oversight and immediate corrective action," Kold said.

The incident is not the NCRC's first data-handling controversy. The agency faced criticism in 2024 over its handling of sensitive records linked to missing children and adoptees. Kold said the pattern has cost the agency credibility. "NCRC has repeatedly spoken about trust, yet it has instead deepened mistrust among those whose lives and identities depend on these records," she said. "We expect the NCRC to take responsibility and align its data protection practices with both law and international standards."

Castlen framed the breach in broader terms. "For me, and for many adoptees, privacy is not just about security — it is about dignity and control over our own story," he said.

This article was written by OC LifeHub staff with AI assistance, based on reporting by The Korea Times, and fact-checked against the source.

Article Facts

Source

The Korea Times

koreatimes

Category

Community

Published

May 10, 2026

5 months ago

Tone

Neutral

Open the original article for full context

Go to The Korea Times to read the complete story, quotes, and full reporting context.

Read More
#korean-adoptees#data-breach#south-korea#adoptee-rights#overseas-koreans#privacy

OC Korean weekly — every Friday morning

Curated restaurants, upcoming events, and fresh listings — in one email.