
Seoul Facilities Corporation, the operator of the South Korean capital’s Ttareungi public bike-sharing service, will provide free monthly bicycle passes to more than 4.6 million people whose personal information was exposed in a 2024 data breach.
The corporation said it will issue a 30-day pass worth 5,000 won, or about $3.40, that lets recipients ride a bike for up to one hour each day. The coupons will become available through the Ttareungi app in August and must be used within three months of issuance. Users who currently hold an active pass will be able to apply the new coupon after their existing pass runs out.
The breach dates back to June 2024, when two teenagers allegedly exploited security flaws in the Ttareungi system’s authentication process to break into the service’s server. South Korea’s National Police Agency’s Cyber Investigation Division determined that the intrusion lasted two days, beginning June 28, 2024. The two individuals were referred to prosecutors in February.
Data stolen in the attack included users’ account IDs, mobile phone numbers, dates of birth, gender, body weight, email addresses, home addresses and, in some cases, a guardian’s phone number.
Seoul Facilities Corporation reported the breach to the National Police Agency and the Personal Information Protection Commission soon after discovering it and notified affected customers the following day. After working with those two agencies to determine exactly which data points were exposed for each user, the corporation began sending individual text messages this week to the roughly 4.62 million people affected, with about 1.2 million messages going out daily. Each message specifies what information of that user’s was leaked, explains how the breach happened and offers guidance for avoiding potential harm.
Some users may not receive the notification if they have since changed their phone numbers or previously opted out of text alerts. The corporation said those individuals can reach out to its customer service center or contact it by email to find out what data of theirs was compromised.
Following the breach, Seoul Facilities Corporation formed a joint emergency response team with the Seoul Metropolitan Government to repair the vulnerability behind the intrusion and to increase monitoring for unusual access attempts.
The corporation said that, as of now, it has not identified any instance in which the leaked data was passed to third parties or used to cause further harm to victims since the breach occurred.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543