How to check whether your personal data has leaked — and block identity theft
However complicated your password is, it does not help when the company holding it gets breached. Leaked pairs of usernames and passwords are tried against other sites automatically, and accounts opened that way are used for the next crime. The good news is that Korea has official services for checking whether your credentials are already circulating, whether accounts exist in your name, and whether a phone line was opened without you. Here is where to look and what order to move in.

A leak is rarely your fault
Most personal data leaks happen at the service you signed up to. What a user can control is not the breach itself but whether the leaked details spread to other accounts.
The single most dangerous habit is password reuse. Credential-stuffing attacks replay one leaked combination across dozens of sites, so the more accounts share a password, the wider the damage runs. That is why the checking process should ask "which of my accounts is exposed" rather than "who was hacked".
Start with the leaked-credentials check
The Personal Information Protection Commission and the Korea Internet & Security Agency jointly run a leaked account lookup service. It collects credentials found on the dark web and in illicit distribution channels and tells you whether the ID or email you enter appears among them.
- The lookup runs after identity verification, and the ID you type is used only for matching.
- If the result says your details were leaked, change the password on every service using that address — not just the site you suspect.
- A clean result is not a guarantee. Leaks that have not yet been collected will not show up.
Daily lookups are limited, so start with the email addresses you actually use for important accounts.
Finding accounts opened in your name
Sites you have no memory of joining may still hold your identity. The e-Privacy Clean Service exists for this. It gathers the identity verifications carried out with your mobile number, i-PIN or certificate, shows which sites performed them, and lets you request withdrawal on the spot.
Look for two things: sites you do not recognise, and services you joined years ago and forgot. There is no reason to leave a dormant account standing — closing it is a deletion request in practice.

Phone lines — checking and blocking
To see whether a line has been opened in your name, use M-Safer, the identity-theft prevention service. It lists mobile, internet-phone and landline subscriptions across carriers in one place.
While you are there, consider switching on the line-opening block. With new subscriptions barred, identity theft becomes far harder, and you can lift the block yourself when you genuinely need a new line. Check the service notice for whether budget carriers are included.
If the phone itself has actually been lost, the order of operations is different — see the first thirty minutes after losing your phone.
Financial identity theft — accounts and loans
Finance is split across two windows. The integrated account information service lists every bank and brokerage account in your name and lets you close dormant ones. The Financial Supervisory Service's consumer portal shows your insurance policies and outstanding loans.
- Query any account you do not recognise with the institution immediately — it may be in use as a mule account.
- Turning on credit-inquiry alerts or blocks at a credit bureau means you are notified whenever a loan check runs against your name.
- If actual damage is confirmed, report it to the police and keep the report receipt; later steps go faster with it.

Once a leak is confirmed, follow an order
Panicked password changes tend to miss the account that matters. Work through it in sequence.
- Email first. Every other reset link arrives there, so nothing else is secure while that account is open.
- Then banking and payments — banking apps, wallets, shopping sites, in that order.
- Then everything that shared the old password. Give each site a different password, and use a password manager if that is hard to keep track of.
- Turn on two-factor authentication for the important accounts; a leaked password alone will no longer log anyone in. Setup is covered in how to set up two-factor authentication.
- Review login alerts and session history for devices you do not recognise.
After a leak, tailored scam messages increase — texts that quote a real payment or delivery to sound convincing. The tells are set out in how to spot smishing and phishing texts, and the equivalent care when dealing with strangers directly is in avoiding secondhand trading scams.
In summary
There are four windows. Leaked credentials at the leaked-account lookup service; sites holding your identity at the e-Privacy Clean Service; phone lines at M-Safer; accounts and loans at the integrated account service and the FSS consumer portal. When a leak is confirmed, change passwords in the order email → finance → everything else, and switch on two-factor authentication for the accounts that matter. Above all, not reusing one password across sites is what decides how large the damage becomes.
All content is fact-checked under our editorial standards.