Search
Close this search box.
Audit Uncovers Unauthorized Access to Soldiers’ Medical Records

Seoul: A military audit has revealed that unauthorized access to soldiers' personal medical information occurred online late last year, leading to the military shutting down the program over a potential data breach, a lawmaker's office reported on Friday.

According to Yonhap News Agency, the breach targeted the Picture Archiving and Communication System (PACS), managed by the Armed Forces Medical Command, between November and December. Approximately 8 gigabytes of data, or around 1,000 files, were affected, as detailed by Rep. Lim Jong-deuk of the main opposition People Power Party.

PACS is responsible for storing medical images such as X-rays, CT scans, and MRIs of soldiers. These records are crucial for healthcare staff to access for medical purposes.

This incident follows closely after a significant cyberattack on a think tank associated with the foreign ministry, where most diplomats' email addresses and personal data were compromised and remained undetected for several months.

The breach of soldiers' medical information was discovered by the military's counterintelligence command during a security audit in April, prompting an immediate shutdown of the system for data protection purposes.

A joint military investigation initiated last month aims to assess the extent of the unauthorized access. Findings from the investigation indicate no actual data leak occurred. A defense ministry official stated, "There are possibilities or circumstantial evidence suggesting a potential leak, but nothing has been confirmed." The official added, "It is difficult to definitively say whether this was an intentional (cyber)attack."

The compromised medical records belonged to six hospitals across the country, including locations in Goyang, north of Seoul, the front-line area of Pocheon, and the southeastern city of Daegu, as per the audit's results.

The unauthorized user reportedly accessed the system through an open network port, which remained exposed from November through March. The defense ministry official acknowledged that the mobile PACS platform was only implemented in the medical archive system in July 2025, suggesting that system management may have lacked adequate security oversight.

The military plans to implement measures to prevent future incidents based on the findings of the joint investigation.

ADVERTISEMENT