Skip to main content

Company intelligence

Kakao cybersecurity incidents and threat signals

kakao.com

Kakao logo

This company page brings together public reporting currently associated with Kakao. It reflects signals published by Shadow Tier and should not be read as a complete incident history.

1

Published signals

currently linked to this company

0

Last 28 days

recent published signals

0

Last 90 days

recent published signals

1

High or critical

confidence classifications

August 5, 2026

Latest report

most recent published signal

Explore related intelligence

Explore this reporting from another angle

Based on all published signals currently linked to Kakao. Affected countries come from victim data; the company country above remains a separate profile fact. Counts describe this reporting set, not overall incident prevalence.

Company signals

All published signals involving Kakao

Kakao logoUse of stolen credentials or exploit
High

KakaoTalk Open Chat Data Leak Affects Over 65,000 Users Due to Unencrypted Serial Numbers

In March 2023, media reports surfaced indicating that personal information of KakaoTalk open chat users was being illegally traded online, prompting an investigation by South Korea's Personal Information Protection Commission (PIPC). The investigation concluded that hackers exploited a vulnerability in KakaoTalk's open chat service, specifically due to Kakao's failure to encrypt certain serial numbers used in open chat rooms before August 2020. This oversight allowed attackers to link temporary open chat IDs to users' permanent serial numbers, real names, and phone numbers, thereby compromising user anonymity. The PIPC confirmed that at least 65,710 users had their personal information accessed, with data from 696 users reportedly being sold on various websites. Kakao was subsequently fined 15.1 billion won ($11.1 million) in May 2024 for negligence in implementing security measures and failing to promptly report the incident. Kakao disputed the findings, arguing that the serial numbers did not constitute personal information and were not legally required to be encrypted. However, a Seoul administrative court upheld the PIPC's decision in January 2026, affirming Kakao's responsibility for the data leak and its failure to adequately safeguard user information and report the breach.

Kakao

FAQ

Questions about Kakao cybersecurity reporting

What does the Kakao page include?

It combines a reviewed organization profile with all current published Shadow Tier signals explicitly linked to Kakao.

Does every mention of Kakao appear here?

No. A signal must contain a reliable company connection and meet the publication criteria; incidental or ambiguous mentions are excluded.

Why can the incident count change?

The page follows current published reporting. Counts change as new evidence is added, classifications are reviewed, or older signals leave the reporting window.