Jeju Air Customer Passport Data Exposed on Naver Search Engine
Over 100 travelers had personal reservation details leaked in the latest wave of South Korean corporate data breaches.
Personal reservation information belonging to more than 100 Jeju Air customers was exposed on the Naver search engine on August 5, 2026. The leak highlights persistent vulnerabilities in how major South Korean firms handle sensitive traveler data.
The exposed data included customer names and passport numbers, although the airline noted that the passport details were partially obscured. Upon discovering the breach, Jeju Air blocked the affected page and reported the incident to the Personal Information Protection Commission. The company is currently in the process of contacting the affected users to notify them of the exposure. A Jeju Air representative stated, "We are currently investigating the exact circumstances of the incident."
A Pattern of Systemic Failure
This incident is not an isolated event but part of a broader, troubling trend of data insecurity across South Korea's corporate landscape. The region has seen a surge in high-profile breaches involving some of the country's largest service providers. Most recently, the OTT streaming service Tving suffered a large-scale leak in June 2026, following similar security failures reported at the e-commerce giant Coupang and telecommunications leader SK Telecom.
Risks to Travelers
The exposure of passport information, even when partially masked, presents a significant security risk to international travelers. Passport numbers are primary identifiers used in global travel and financial verification; when combined with full names, they provide a foundation for identity theft and targeted phishing attacks. For the aviation industry, such leaks erode passenger trust and suggest that current data management protocols are insufficient to protect against indexing by public search engines.
Next Steps for Oversight
Regulators are now expected to determine how the data became indexable by Naver and whether Jeju Air failed to implement basic security headers or access controls. While the airline has taken immediate steps to remove the data, the focus now shifts to the Personal Information Protection Commission's investigation. It remains to be seen if the commission will impose fines or mandate a systemic audit of the airline's data handling practices to prevent future recurrences.