Woowa Brothers, operator of South Korea’s food delivery platform Baedal Minjok (Baemin), disclosed a customer data leak after a criminal ring infiltrated an outsourced firm that managed its customer service center. Police and the company said a suspect posed as a new rider recruit, gained access to a customer’s personal information including a contact number and address, and allegedly obtained the data for a retaliation-for-hire request coordinated through Telegram.
Police said the suspects were apprehended shortly after authorities informed Woowa Brothers of the breach. The company reported the incident to the Personal Information Protection Commission, notified customers believed to be affected, and said it will terminate its partnership with the service provider while tightening internal controls over personal data handling. The case adds Baemin to a growing list of South Korean companies hit by customer data leaks, alongside recent incidents involving Coupang, SK Telecom, and Lotte Card.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Woowa Brothers publicly disclosed the customer data leak involving its Baedal Minjok platform, reported the case to the Personal Information Protection Commission, and notified likely affected customers. The company also said it would terminate its partnership with the service provider and strengthen internal controls.
According to police and the company, the suspects were apprehended shortly after the case was reported, and police notified Woowa Brothers about the data leak. The client behind the request was described as unidentified.
A member of a criminal ring allegedly posed as a new recruit at an outsourced customer service provider for Woowa Brothers and obtained a customer's personal information, including contact number and address. Police said the data was apparently sought for a retaliation-for-hire scheme coordinated via Telegram.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.