Seoul: A military audit has revealed that unauthorized access to the online records of soldiers' personal medical information occurred late last year, leading the military to shut down the affected program due to concerns over a potential data breach. The breach targeted the Picture Archiving and Communication System (PACS) operated by the Armed Forces Medical Command between November and December, affecting approximately 8 gigabytes of data, equivalent to around 1,000 files, according to Rep. Lim Jong-deuk of the main opposition People Power Party.
According to Yonhap News Agency, the PACS is designed to store medical images such as X-rays, CT scans, and MRIs of soldiers, enabling healthcare staff to access them for medical purposes. This breach follows a recent major cyberattack on a think tank affiliated with the foreign ministry, where email addresses and personal data of diplomats were compromised for months without detection. The military's counterintelligence command discovered the unauthorized access during a security audit in April, prompting an immediate shutdown of the system for data protection.
A joint military investigation was launched last month to assess the extent of the unauthorized access. So far, no actual data leak has been confirmed, although possibilities or circumstantial evidence suggest a potential leak. "There are possibilities or circumstantial evidence suggesting a potential leak, but nothing has been confirmed," a defense ministry official stated. Additionally, the official noted the challenge in determining whether the incident was an intentional cyberattack.
The compromised medical records belonged to six hospitals nationwide, including facilities in Goyang, north of Seoul, the front-line area of Pocheon, and the southeastern city of Daegu, based on the audit's findings. The unauthorized user reportedly accessed the system through an open network port, which remained exposed from November through March. The mobile PACS platform was only introduced to the medical archive system in July 2025, indicating a possible lack of sufficient security oversight in system management.
To prevent future incidents, the military plans to implement measures based on the joint investigation's outcomes. Meanwhile, the defense ministry has requested disciplinary action against three active-duty officers linked to the Armed Forces Medical Command and involved in the case, with the relevant procedure currently underway. "Based on the results of the audit, disciplinary measures were sought against three officials related to the case, and the process is ongoing," the ministry confirmed in a notice to the press.