Sogang University
180,000 records at a university with roughly 12,000 students. The gap between those numbers is the story.
What happened?
Sogang University in Seoul disclosed a breach affecting approximately 180,000 records containing student and staff ID numbers, email addresses, phone numbers, and encrypted passwords. No threat actor has been publicly attributed as of this writing.
What data was actually inside?
Student and staff identification numbers, email addresses, phone numbers, and encrypted passwords. No financial data or government identifiers have been reported.
The student ID number carries more weight than it appears to. On most campuses it is the identifier for library systems, dormitory access, meal plans, health services, course registration, and the account recovery flow. It functions as an internal identity document, which makes it directly useful for impersonation against the institution itself.
Who gets hurt and how?
180,000 records at an institution with roughly 12,000 enrolled students. The affected population is therefore not the current campus. It is everyone who ever enrolled, plus applicants who were rejected, plus staff who left decades ago.
The current students face account takeover and phishing, and their contact details are current. The alumni face a different problem: they have no active account to secure, their contact details may be stale enough that notification fails, and they have no ongoing relationship through which to learn what happened.
Rejected applicants are the group with the least recourse of all. They never became students, they never consented to indefinite retention in any meaningful sense, and they are the least likely to be reachable.
What did they think they were doing right?
Passwords were encrypted, which is the control that matters most in a credential exposure and the one most frequently absent. Korean universities also operate under PIPA, one of the stricter personal information regimes globally, with genuine enforcement.
The assumption worth examining is that protecting the active student information system protects student data. The active system is well defended. The archive of everyone who came before sits in the same estate, frequently in the migrated remnants of previous systems, and receives none of the same attention because nobody is logging into it.
What did they not know about their own data?
Higher education has a structural retention problem no other sector shares. A retailer's relationship with a customer ends. A university's never does — transcript requests arrive forty years later, alumni relations depend on permanent contact records, and donor cultivation is built on the same file.
So the record stays, and it is carried across three or four generations of student information systems. Each migration moves the fields the new system needs and leaves the rest in an archive that is retained because deleting it was never anybody's project and nobody is certain what would break.
The 180,000 figure is institutional memory rather than a roster. Very few universities could produce, on request, a list of every system holding records for people who left in 1998.
If your environment was compromised today, could you say within 24 hours exactly what sensitive data was accessed?
What does attribution look like the morning after?
Korea's Personal Information Protection Act requires notification of affected data subjects without delay and reporting to the Personal Information Protection Commission for breaches meeting defined thresholds. PIPA carries meaningful administrative fines and, unusually, permits statutory damages without proof of actual loss.
The operational difficulty is reaching the affected population. Notification obligations do not scale down for people you have lost contact with, and an institution holding 180,000 records will find that a substantial share of the email addresses and phone numbers no longer work. International alumni add further regimes, since a Korean university's graduates are distributed globally and GDPR may apply to those resident in the EU.
What would have changed the outcome?
Knowing what is in the oldest systems — so that indefinite retention is a decision someone made rather than a default nobody revisited.
Data you cannot describe is data you cannot delete, and data you never delete is data you will eventually notify on. Every organisation that keeps records permanently — universities, insurers, health systems, government agencies — carries an archive that grew by accretion rather than decision. The useful first question is not how to secure it better. It is what is actually in there, because a meaningful share of it can probably be disposed of and the rest deserves protection proportionate to a risk nobody has measured. See also our analysis of the Latvia CSDD breach, where receipts dating to 2008 were still live.
Sogang University found out the hard way.
Your team could spend the next 6 months rebuilding systems, notifying customers, and answering legal questions. Or you could spend 24 hours finding out what's actually at risk.