South Korean police charged two teenagers (identified as Persons A and B) for allegedly breaching Seoul’s public bike hire service Ttareungyi and exfiltrating user data. Authorities say the intrusion occurred in June 2024 and resulted in the exposure of data on 4.62 million individuals—about 90% of the service’s roughly 5 million registered users—making it one of the larger recent consumer data thefts disclosed in South Korea.
According to the Seoul Metropolitan Police Agency’s Cyber Investigation Unit, Person A allegedly performed the access that enabled the theft, while Person B allegedly encouraged downloading the dataset; the two reportedly met on Telegram and bonded over an interest in information security. The stolen data reportedly included user IDs, phone numbers, home addresses, email addresses, dates of birth, genders, and weights; the teens were arrested on suspicion of violating South Korea’s Information and Communications Network Act and referred to prosecutors, with detention requests reportedly denied due to their age.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
On or before February 24, 2026, the Seoul Metropolitan Police Agency said the two teenagers were charged and referred to prosecutors for allegedly breaching Ttareungyi. Police said there was no evidence the stolen data had been leaked or sold, and prosecutors reportedly rejected arrest warrant requests because the suspects were juveniles.
After the private mobility company filed a complaint, police investigated the earlier DDoS case, seized devices, and conducted forensic analysis. Investigators said they found files containing Ttareungyi user data, which connected the two teens to the bike service breach.
Between June 28 and 29, 2024, the two teens allegedly accessed a Ttareungyi server operated by the Seoul Facilities Corporation and exfiltrated a database affecting 4.62 million users. The stolen data reportedly included user IDs, contact details, home addresses, and demographic information.
In April 2024, one of the South Korean teen suspects allegedly sent about 470,000 mass signals to overwhelm a private mobility rental company's servers. During that activity, investigators say he identified vulnerabilities in Seoul's Ttareungyi bike service system and shared them with the other suspect.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
go.theregister.com
Open sourcedatabreaches.net
Open sourcehelpnetsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.