CSIDB logo
Incident

Good Choice

Incident posture

Attack window
Mar 2017
Location
South Korea
Status
Historical
CIA posture
Available to members
Updated
2025-12-08 00:00

Linked entities

Victim
Good Choice
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Mar 2017
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Hackers breached a South Korean hotel reservation application, compromising personal data of nearly one million users. The attackers, operating domestically and in China, stole names, contact details, and reservation records before being arrested by local authorities. The incident impacted over 990,000 individuals through unauthorized access to the app's servers.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

In March 2017, attackers breached the servers of "Good Choice," a South Korean hotel and guesthouse reservation mobile application, compromising the personal data of over 990,000 users. The stolen information included user names, contact details, and historical reservation records. The intrusion was attributed to a hacking group operating across South Korea and China, though the specific technical methods used to infiltrate the systems were not publicly disclosed. The scale of the breach indicated a significant compromise of customer privacy, exposing sensitive travel patterns and personally identifiable information. The app's operator did not immediately detect or publicly acknowledge the incident at the time of the breach, delaying user notifications.

South Korean law enforcement agencies investigated the breach and subsequently arrested multiple suspects linked to the hacking group. Local police confirmed the arrests following a report by South Korean television network YTN on June 1, 2017, nearly three months after the intrusion occurred. The cross-border nature of the operation highlighted coordination between actors in South Korea and China, though authorities did not specify the motives behind the attack or whether stolen data was monetized. No remediation efforts or victim support measures by the app operator were detailed in available reports. The incident underscored vulnerabilities in hospitality-sector data storage practices and demonstrated law enforcement's capacity to apprehend geographically dispersed cybercrime suspects through coordinated investigations.

Sources

Sources available to members: 1 source.

CSIDB