started · updated
GS Retail fined $9.3 million over 1.66 million customer data leak
South Korea’s Personal Information Protection Commission (PIPC) has imposed a fine of approximately 12.8 billion won ($9.3 million) on GS Retail following a massive personal data leak affecting 1.66 million customers.
The breach occurred via credential stuffing attacks, where hackers used previously obtained IDs and passwords to bypass login systems. The incident impacted 11.58 million users of GS SHOP and 79,128 customers of the GS25 convenience store chain. Leaked information included names, genders, dates of birth, contact numbers, addresses, and email addresses.
The PIPC noted that GS Retail failed to detect abnormal login spikes from identical IP addresses and lacked a dedicated privacy protection organization. The regulator has ordered the company to implement advanced security policies to identify abnormal connections and to appoint dedicated privacy protection personnel.
In related actions, the PIPC also issued fines and penalties to other entities, including dating app operator Enrise, SK Telecom, and AtoZ, for various security vulnerabilities and delays in reporting data breaches.
Entities
GS Retail · GS SHOP · GS25 · Personal Information Protection Commission · SK Telecom