GS Retail has been fined more than 12.8 billion won ($9.3 million) over a data breach that affected 1.66 million users, the Personal Information Protection Commission (PIPC) said Monday.
The PIPC decided to impose a 12.84 billion won fine and a 3 million won penalty on the operator of home-shopping retailer GS Shop and convenience store chain GS25 for violating personal information protection laws at its plenary meeting on Wednesday.
An unidentified hacker carried out credential-stuffing attacks on the GS Shop website from June 21, 2024, through Feb. 13, 2025, and on the GS25 website from Dec. 26, 2024, through Jan. 4, 2025. The hacker successfully accessed user accounts.
Related Article
Credential stuffing is a cyberattack in which hackers attempt to log in to accounts by repeatedly entering large numbers of usernames and passwords in their possession.
The hacker used the compromised accounts to access pages containing members’ personal information. They reportedly extracted data from 1.58 million GS Shop users and 79,128 GS25 users. The information included name, gender, date of birth, phone number, address and email address.
GS Retail did not have adequate security measures to detect and block large numbers of login attempts from the same IP address within a short period, the commission found.
The company also failed to promptly recognize warning signs, including sharp increases in login attempts and failures. Lax controls allowed the data breaches to continue for an extended period, according to the PIPC.
GS Retail first learned that GS25 had suffered a data breach on Jan. 4, 2025. It took the company more than a month to discover that GS Shop was being attacked in the same way.
A total of 327 IP addresses used in the GS25 attack were also used to target GS Shop.
The PIPC investigation also found shortcomings in GS Retail’s privacy protection organization and operations. The company had no dedicated privacy protection team at the time of the breach, while its security operations were divided between separate systems.
During the PIPC investigation, an additional 1,599 people affected by the breach were identified after the company had issued its initial notification to affected users, whom GS Retail failed to notify within 72 hours without justifiable cause, the commission found.
In addition to the fines, the PIPC ordered the company to disclose the disciplinary action on its website.
The commission also ordered GS Retail to strengthen safeguards against future breaches, including measures to detect abnormal access. The company must also assign dedicated personal information security staff and clarify the authority and responsibilities of its chief privacy officer (CPO).
The PIPC also imposed fines, penalties and corrective orders on Nrise, SK Telecom and AtoZ over separate data breaches.
At Nrise, the operator of the dating app Wippy, a hacker attempted to log in using 16,803 phone numbers in March 2023. Personal information from 736 accounts was compromised, including their nicknames, genders, profile photos, dates of birth, education and occupations.
The PIPC imposed a 118.44 million won fine and a 3.6 million won penalty on Nrise for failing to adequately inspect vulnerabilities in its identity verification system and take measures to block excessive access attempts.
An administrator page for an “ifland” event website operated by AtoZ on behalf of SK Telecom was exposed to search engines from Nov. 21, 2022, to Jan. 3, 2023. The exposure leaked the names and phone numbers of 1,140 people.
SK Telecom was fined 3.6 million won and issued a corrective order for missing the 24-hour deadline to notify users and report the breach after learning of the leak. AtoZ was warned for inadequate access controls on the administrator page.
