South Korea data breach exposes adoptee records, drawing global criticism
News Briefing
AI SummaryKey Point
A security flaw in a newly launched South Korean government portal exposed the personal records of adoptees worldwide for three days beginning April 30, prompting sharp criticism from overseas Korean advocacy groups.
What Happened
The breach affects adoptees worldwide who have sought access to their records through South Korea's child-rights system, including Korean-Americans in Southern California pursuing their origins. The incident renews debate over whether the agency meets the data-protection expectations of the global Korean adoptee diaspora.
A security flaw in a newly launched South Korean government portal exposed the personal records of adoptees worldwide for three days beginning April 30, prompting sharp criticism from overseas Korean advocacy groups.
The breach affects adoptees worldwide who have sought access to their records through South Korea's child-rights system, including Korean-Americans in Southern California pursuing their origins. The incident renews debate over whether the agency meets the data-protection expectations of the global Korean adoptee diaspora.
The National Center for the Rights of the Child launched its online application-tracking system April 30 but failed to restrict user access, allowing prospective adoptive parents who logged in to check their own status to view other applicants' records, according to The Korea Times. Exposed data included names, dates of birth, photographs, adoption records, passport information and adoptive family details. The agency notified affected individuals May 3, one day after the exposure window closed.
David Castlen, director of IT and cybersecurity at the United States Korean Rights Group, said he was among those who received breach notices. "What concerns me most is the combination of identity data with adoption-related records," Castlen told The Korea Times. "My notice was numbered 43, which suggests that at least dozens of individuals may have been affected." Castlen, who is seeking to restore his Korean citizenship, said he has since noticed a rise in calls from unfamiliar numbers.
Anja Kold, a lawyer and representative of the Danish Korean Rights Group, drew a pointed contrast with European Union standards in a statement cited by The Korea Times. "In Denmark and the EU, data protection is considered a fundamental right, and repeated breaches trigger significant sanctions, extensive regulatory oversight and immediate corrective action," Kold said.
The incident is not the NCRC's first data-handling controversy. The agency faced criticism in 2024 over its handling of sensitive records linked to missing children and adoptees. Kold said the pattern has cost the agency credibility. "NCRC has repeatedly spoken about trust, yet it has instead deepened mistrust among those whose lives and identities depend on these records," she said. "We expect the NCRC to take responsibility and align its data protection practices with both law and international standards."
Castlen framed the breach in broader terms. "For me, and for many adoptees, privacy is not just about security — it is about dignity and control over our own story," he said.
This article was written by OC LifeHub staff with AI assistance, based on reporting by The Korea Times, and fact-checked against the source.
Article Facts
The Korea Times
koreatimes
Community
May 10, 2026
5 months ago
Neutral
Open the original article for full context
Go to The Korea Times to read the complete story, quotes, and full reporting context.





