INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

ESET Alerts Data Sales on the Dark Web

| 2026-10-11 15:56 HIGH LOW DATA BREACH
Executive Summary
AI-generated
A security incident was reported by CJ Olive Young on October 3, 2026, after a post appeared on Dark Web claiming to sell the company's customer information. The actual data did not match the posted information and was found to be AI-generated fake data. Similarly, Kakao Mobility also received reports of its customer information being sold on Dark Web, but it was later verified as false by the company spokesperson. In total, 77 samples of leaked data were analyzed by KISA (Korea Internet & Security Agency), with none matching actual member information from CJ Olive Young or Kakao Mobility. The attackers are using AI-generated data to create fake leaks and sell them on Dark Web, which can deceive buyers and damage companies' reputations if not verified properly.
Technical Mitigations AI-generated
• User Training (ATT&CK mitigation for Impersonation): Train users to be aware of impersonation tricks and how to counter them, for example confirming incoming requests through an independent platform like a phone call or in- • Threat Intelligence Program (ATT&CK mitigation for Impersonation): Threat intelligence helps defenders and users be aware of and defend against common lures and active campaigns that have been used for impersonation. • Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity. • Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc • Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
ES
Incident Timeline
‎October 3
CJ Olive Young reported a security incident to KISA on October 3, after analyzing 77 samples of leaked customer information from the Dark Web that were found to be fake.
organisation CJ Olive Young
organisation KISA
organisation Korea Internet & Security Agency
general_metric 77 samples
‎2026/10/11
A post on the Dark Web falsely claimed to sell customer information from CJ Olive Young and Kakao Mobility, but was later found to be fake data.
organisation Kakao Mobility
organisation Olive Young
organisation CJ Olive Young and Kakao Mobility's
organisation CJ Olive Young's
organisation Kakao Mobility's
organisation Kakao