South Korea’s ₩351 Billion Data Center Disaster: Audit Uncovers Illegal Subcontracting, Missed Safety Checks and Critical Failures
SEOUL, South Korea — What initially appeared to be a catastrophic equipment failure at a South Korean government data center has now been traced to a far broader chain of human and institutional failures.
A government audit has found that unlicensed companies were brought into a battery replacement project at the National Information Resources Service (NIRS) in Daejeon, where a fire in September 2025 crippled hundreds of government information systems and triggered one of South Korea’s worst digital-service disruptions.
The Board of Audit and Inspection (BAI) said the work passed through multiple layers of subcontracting before reaching two companies that were not properly licensed for the work. The companies also failed to follow basic safety procedures during the battery operation.
The consequences were enormous.
The fire ultimately disrupted 709 government information systems, and full normalization took 95 days. The BAI now estimates the broader damage at ₩351.1 billion, dramatically higher than the data center's earlier estimate of ₩59.7 billion.
And the audit found that the fire was only the beginning of the failures.
The subcontracting chain that investigators uncovered
According to the BAI, the battery replacement project did not remain with the contractor originally selected to perform the work.
The original contractor hired another company, which subsequently subcontracted the work to two unlicensed firms.
Those firms then carried out the battery-related work without crucial safety measures, including properly cutting power to the battery rack before work began.
The data center had reportedly been informed that outside personnel would participate in the project.
But the audit found that officials failed to verify whether the companies involved possessed the necessary licenses and registrations.
That failure became critical because the work involved lithium-ion batteries used in an uninterruptible power supply system, equipment that can pose significant fire risks when improperly handled.
Earlier police investigations had already pointed toward negligence during the battery relocation work. Police subsequently referred suspects to prosecutors, while investigators examined whether required power-shutdown procedures had been followed.
Only one of eight battery racks was powered down
The latest audit findings provide an even more troubling picture of what happened inside the data center.
According to Asia Business Daily's account of the BAI investigation, only one of eight battery racks had been powered down before disassembly work proceeded.
The audit also found that cable terminals were not properly insulated, allowing conditions that could produce sparks during the work. Investigators concluded that these failures led to the fire.
The blaze began at approximately 8:16 p.m. on September 26, 2025, in a computer room at the Daejeon NIRS facility.
The fire was not fully extinguished until approximately 22 hours later.
That distinction is important.
The latest audit does not simply identify an accidental battery failure. It describes a sequence in which procurement, subcontracting, licensing, electrical safety and supervision all failed before the fire began.
The warning that came five months earlier
Perhaps one of the most striking findings concerns what happened before the fire.
The National Fire Agency had decided to conduct a safety inspection of the data center approximately five months before the blaze.
But an NIRS official rejected the inspection request, reportedly arguing that the computer server rooms were designated as security zones.
As a result, the relevant areas were not subjected to the requested fire-safety inspection.
The BAI has requested disciplinary action over the failure and notified the National Fire Agency to consider whether the matter should be reported for prosecution.
In other words, the audit found that an opportunity to identify potential safety problems existed before the disaster—but the inspection never happened.
The response after the fire made the damage worse
The problems did not stop when the fire started.
The audit found that the data center failed to implement key measures in its own fire-response procedures.
Instead of immediately taking all prescribed actions, the facility reportedly asked firefighters not to use water on the equipment because of concerns about damaging the computer network.
According to Asia Business Daily's detailed account, water-based firefighting did not begin until approximately 11:13 p.m., around three hours after the fire began.
The audit also found weaknesses in emergency preparedness.
A fire-response manual prepared in October 2024 had not been properly distributed to employees and was reportedly stored only on a manager's computer. Fire drills were also found to have been inadequate, with exercises lasting roughly 10 minutes and focusing mainly on detection rather than the specific challenges posed by battery fires.
The disaster exposed a second problem: weak backup systems
The physical fire was only part of the catastrophe.
The blaze exposed major weaknesses in South Korea's ability to keep government digital services operating after a major infrastructure failure.
According to the audit findings reported by Asia Business Daily, only 54 of the 709 affected systems—about 7.6%—had separate disaster-recovery systems.
Even more striking, only seven of those systems were actually used for recovery.
The audit also found that 237 of 690 backup storage facilities were located in the same computer room as the original data.
That meant a physical disaster could potentially destroy both the primary and backup copies.
Meanwhile, 501 systems, or 72.6% of the total, had not undergone mock recovery drills since 2015, according to the same report.
For a government whose public services increasingly depend on digital infrastructure, the findings raise a much larger question: what happens when a single physical facility goes offline?
In this case, the answer was a nationwide digital disruption.
709 government systems were ultimately affected
Authorities initially reported that 647 systems had been disrupted.
That figure was later revised to 709 after the internal management system nTOPS was restored and officials were able to obtain a more accurate accounting.
The affected systems included critical government and public services.
The disruption forced citizens and government workers to deal with problems ranging from online administrative services to digital document processing.
Recovery continued for weeks.
Eventually, the government reported that all 709 affected systems had been restored, with full normalization reached after 95 days, according to Seoul Economic Daily.
The real cost was far higher than the original estimate
The financial impact also changed dramatically as authorities examined the full consequences.
The data center had initially estimated the damage at ₩59.7 billion.
The BAI's broader assessment put the total at ₩351.1 billion, incorporating not only direct physical damage but also wider social and economic costs.
Asia Business Daily reported that the broader calculation included losses connected to business data and the opportunity costs created by interruptions to government services.
That means the true price of the fire was not simply the cost of replacing servers, batteries or damaged equipment.
It was also the cost of a government forced to operate without critical digital infrastructure.
The disaster had already raised red flags
The new audit findings reinforce concerns that emerged during the original investigation.
In October 2025, police were already investigating the possibility that improper battery relocation procedures contributed to the fire. Investigators questioned personnel and examined whether auxiliary power remained active during the work.
By late October, Korean media reported that police had charged five people in connection with professional negligence and had uncovered a chain of illegal subcontracting.
Those findings now align with the broader BAI audit.
What began as an investigation into a battery fire has evolved into a much larger examination of procurement, subcontracting, safety supervision, emergency response and disaster recovery.
South Korea eventually restored the digital system—but the questions remain
The government eventually brought the affected systems back online after 95 days.
But restoration did not erase the underlying weaknesses exposed by the disaster.
The Ministry of the Interior and Safety has said it would strengthen safety standards for public data centers and overhaul disaster-recovery capabilities.
In May 2026, NIRS also began full-scale operation of an integrated information-management system covering 14 of the systems damaged in the Daejeon fire and subsequently restored and migrated to the Daegu center's public-private cloud infrastructure.
The government has therefore moved from emergency recovery toward rebuilding a more resilient national information infrastructure.
But the audit shows just how expensive the original weaknesses became.
This was bigger than a fire
The most important lesson from the Daejeon disaster may not be about lithium-ion batteries.
It is about what happens when multiple safeguards fail at the same time.
A contractor passed work down a chain of subcontractors. Unlicensed companies became involved. Basic electrical safety measures were not properly followed. A requested fire inspection was rejected. Emergency procedures were not effectively implemented. Firefighting was delayed. Backup systems were insufficient.
Each failure increased the consequences of the one before it.
By the time the fire was extinguished, the problem was no longer confined to a single server room.
It had become a nationwide digital crisis.
The warning South Korea cannot ignore
The September 2025 NIRS fire disrupted 709 government systems, took 95 days to fully recover and generated an estimated ₩351.1 billion in broader damage.
The new audit suggests that the disaster was not the result of one isolated mistake.
It was the product of a chain of failures that stretched from the contracting process to fire prevention, emergency response and disaster recovery.
And that may be the most unsettling finding of all.
The fire started in one battery rack—but the audit found vulnerabilities throughout the system designed to prevent a disaster from becoming a national digital blackout.