< Back to situations

Monitor this situation.

[SITUATION] · [QUIET] · [BUSINESS]

2 clusters · 6 sources · 4 days · First seen · Last updated

South Korean data privacy enforcement

Overview

South Korea’s Personal Information Protection Commission (PIPC) imposed a fine of approximately 12.8 billion won ($9.3 million) on GS Retail following a massive personal data leak affecting 1.66 million customers.

The breach was executed via credential stuffing attacks, where hackers used previously obtained credentials to bypass login systems. The incident impacted 11.58 million GS SHOP users and 79,128 GS25 convenience store customers, exposing names, genders, dates of birth, contact numbers, addresses, and email addresses.

The PIPC determined that GS Retail failed to detect abnormal login spikes from identical IP addresses and lacked a dedicated privacy protection organization. As a result, the regulator has ordered the company to implement advanced security policies and appoint dedicated privacy protection personnel.

Entities

Personal Information Protection Commission · GS SHOP · HD Korea Shipbuilding & Offshore Engineering · HD Hyundai · HD Construction Equipment

Timeline

  1. 12 days ago

    [BUSINESS] 5 sources
    GS Retail fined $9.3 million over 1.66 million customer data leak

    GS Retail has been fined 12.8 billion won by South Korea’s PIPC after a credential stuffing attack leaked the personal data of 1.66 million GS SHOP and GS25 customers.

  2. 16 days ago

    [BUSINESS] 2 sources
    HD Hyundai affiliates fined over 9,500 personal data leaks

    South Korea's PIPC fined HD Hyundai affiliates after a hacker exploited server vulnerabilities to leak the personal data of over 9,500 employees and contractors.

Sources

bhaskarlive.in · biz.heraldcorp.com · newstomato.com · socialnews.xyz · tokenpost.kr · zdnet.co.kr