< Back to all clusters
[BUSINESS] · South Korea · 2 sources

GS Retail fined 12.8 billion won over massive data breach

South Korea’s Personal Information Protection Commission has imposed a fine of approximately 12.8 billion won on GS Retail following a massive data breach affecting roughly 1.66 million users. The breach occurred through “credential stuffing” attacks, where hackers used previously obtained IDs and passwords to gain unauthorized access to GS SHOP and GS25 websites.

Investigations revealed that GS SHOP saw approximately 1.58 million users compromised, while GS25 had about 79,000 users affected. The leaked data included names, genders, dates of birth, contact information, and addresses. The commission noted that GS Retail failed to implement measures to detect or block large-scale login attempts from single IP addresses, allowing the breach to persist despite abnormal login failure rates.

Furthermore, the company was criticized for its delayed response. Although GS Retail identified a breach at GS25 in early January, it did not realize the same attack pattern was affecting GS SHOP until February. The commission also cited a lack of a dedicated personal information protection organization and a failure to notify affected individuals within the legally required 72-hour window for certain users. GS Retail stated it is currently strengthening its security systems and management frameworks to prevent recurrence.

Entities

Enrise · GS Retail · GS SHOP · GS25 · Personal Information Protection Commission