(LEAD) Audit finds unauthorized access to soldiers' medical info archive late last year

(LEAD) military-unauthorized access

김승연

| 2026-07-24 14:28:43

▲ The Armed Forces Medical Command, located in Seongnam, south of Seoul (Yonhap)

(ATTN: ADDS ministry official's comments in paras 7-8, more details throughout)

SEOUL, July 24 (Yonhap) -- A military audit has found unauthorized access to online records of soldiers' personal medical information occurred late last year, prompting the military to shut down the program over a potential data breach, according to a lawmaker's office Friday.

The breach targeted the Picture Archiving and Communication System (PACS), operated by the Armed Forces Medical Command, between November and December, affecting approximately 8 gigabytes of data, equivalent to around 1,000 files, according to Rep. Lim Jong-deuk of the main opposition People Power Party.

The PACS stores medical images, such as X-rays, CT scans and MRIs of soldiers, allowing healthcare staff to access them for medical purposes.

The latest breach comes on the heels of a major cyberattack at a think tank affiliated with the foreign ministry, where email addresses and personal data of most diplomats were compromised and left undetected for months.

The military's counterintelligence command discovered the breach of soldiers' medical information during a security audit in April, and the military immediately shut down the system for data protection.

A joint military investigation was launched last month to determine the extent of the unauthorized access and has so far found there was no actual leak of any data.

"There are possibilities or circumstantial evidence suggesting a potential leak, but nothing has been confirmed," a defense ministry official told reporters.

"It is difficult to definitively say whether this was an intentional (cyber)attack," she said.

The medical records belonged to six hospitals across the country, including Goyang, north of Seoul, the front-line area of Pocheon and the southeastern city of Daegu, according to the audit's results.

The unauthorized user is believed to have accessed the system through an open network port, which had been left exposed from November through March.

The mobile PACS platform was only installed in the medical archive system in July 2025, the official added, acknowledging that system management may have lacked sufficient security oversight.

The official said the military plans to take steps to prevent recurrence based on the outcome of the joint investigation.

(END)

[ⓒ K-VIBE. 무단전재-재배포 금지]