Han Jun-ho: "Reinstalled Server OS Even After Being Notified of a Security Breach"... LG Corp.: "Submitted Forensic Data; Investigation Underway"
[2026 Parliamentary Audit] Questions from the Science and ICT Committee
Questions for LG Uplus Executive Vice President Hong Kwan-hee Regarding Incident Response
Server OS Work... Criticized for Failing to Preserve Original Data
Hong Kwan-hee, CISO: "I understand that forensically verifiable data has been submitted"
[E-Daily Reporter Yun Junghoon ] Questions continued to be raised during a National Assembly audit regardingLG Uplus(032640)’s response to a security breach. The key issue was whether reinstalling the server operating system (OS) after being notified of the breach by the Korea Internet & Security Agency (KISA) complied with the principle of evidence preservation.
Democratic Party Representative Han Jun-ho (right) is questioning Hong Kwan-hee, Head of the Information Security Center at LG Uplus (Photo: National Assembly Broadcasting)
On the 6th, during the afternoon session of the 2026 Science and ICT Committee parliamentary audit, Han Jun-ho, a lawmaker from the Democratic Party of Korea, questioned Hong Kwan-hee, Head of the LG Uplus Information Security Center (Executive Vice President), about LG Uplus’s response process during the 2025 security breaches involving the three major telecom companies. Rep. Han stated, “There are aspects of LG Uplus’s incident response that I simply cannot understand, which is why I invited you as a witness,” and requested precise answers.
Rep. Han pointed out that KISA notified LG U+ of the breach on July 19 of last year, and that server OS maintenance related to the Account Management System (APPM) was subsequently performed on August 12. He then asked, “Isn’t it standard practice to preserve the original state before reinstalling the server OS when notified of a potential breach?”
Executive Director Hong replied, “I believe we took measures within the scope of what was possible to preserve the original state,” adding, “There were some shortcomings.”
Another lawmaker mentioned that a server image had been submitted to KISA prior to the reinstallation and asked whether it was a simple backup or a forensic image—a bit-by-bit clone of the entire disk.
Executive Director Hong replied, “It’s difficult for me to comment since this is currently under investigation,” but added, “I understand it was submitted as material suitable for forensic analysis.”
(Photo courtesy of Rep. Han Jun-ho’s office)
The timing of the forensic image’s creation also became a point of contention. One lawmaker asked, “Was it before or after the notification to KISA?” Executive Director Hong replied, “I understand it was after the notification, and that aspect was investigated by the investigative authorities.”
Rep. Han criticized, “There was nearly a month between the notification on July 19 and August 12, so the fact that server OS work was suddenly performed on August 12 inevitably raises suspicion.”
He also said, “They claim to have submitted the image and preserved the original, yet why did the government’s joint public-private investigation team officially announce that they could not verify traces of the breach or the attack path due to the OS reinstallation?” He added, “LG Uplus’s response is the most baffling of all.”
Chinese battery manufacturer CATL has begun trial production at its battery cell plant in Debrecen, Hungary. By establishing its largest production base outside of China in Europe, the company is movi…
LotteChilsungBeverage is introducing alcoholic beverages that go beyond zero-sugar and low-calorie options to now reduce “purine” content as well. As the “subtraction competition” in the alcoholic bev…
Alteogen Inc.(196170)is securing an investment of 200 billion won from the National Growth Fund and SkyLake. Alteogen Inc. plans to use these funds to construct new production facilities and introduce…