---
title: Government24 Server Hacked via Children's Portal Vulnerability
url: https://www.dataloco.com/en/government24-server-hacked-via-childrens-portal-vulnerability
published: 2026-10-02T13:25:39+00:00
language: en
section: Security
source: https://www.dailysecu.com/news/articleView.html?idxno=208642
organizations: Government24, Ministry of the Interior and Safety, Personal Information Protection Commission
publisher: Dataloco
---

# Government24 Server Hacked via Children's Portal Vulnerability

Government24, the primary online civil service platform of the government, suffered an external attack in August that resulted in the leak of server memory information and some personal data.

The attack occurred around 5:29 PM on August 17 through a vulnerable page within the Children's Portal of Government24. During this incident, 11 memory dump files and other materials were leaked from the server. Memory dump files store data being processed in memory at a specific time and may contain account or personal information depending on the program and service structure.

According to a report submitted to the Personal Information Protection Commission on August 18, estimated leaked information includes 36 resident registration numbers, 3 phone numbers, and 55 Government24 IDs and passwords. These figures are initial estimates from the early investigation stage, and the final scale of the damage, including the exact number of affected individuals and whether additional information was leaked, has not yet been determined.

Investigators are working to determine the extent of the attacker's system access and the specific type of vulnerability used. It remains unclear if the attacker merely accessed specific files or secured permissions to execute commands on the server. Further analysis is required to see if the attacker installed web shells, created new accounts, or expanded access to other internal systems of Government24.

This cyber attack is distinct from a previous incident in 2024 involving the misissuance of civil documents. That prior error, which resulted in 646 academic certificates and 587 corporate tax certificates being issued to the wrong people, was caused by a program development error rather than an external attack.

## This story in other languages

- [中文](https://www.dataloco.com/zh/24)
- [Français](https://www.dataloco.com/fr/une-cyberattaque-touche-le-portail-gouvernemental-gouvernement24-des-donnees-sensibles-exposees)
- [Norsk](https://www.dataloco.com/no/eksternal-angrep-mot-government24-forte-til-lekkasje-av-minnedumpfiler)
- [Polski](https://www.dataloco.com/pl/wyciek-danych-z-systemu-rzadowego-przez-luke-w-serwisie-dla-dzieci)
- [Türkçe](https://www.dataloco.com/tr/gov24-platformu-siber-saldiriya-ugradi-ve-veriler-sizdirildi)
