
South Korea's privacy regulator has imposed a fine of 12.836 billion won ($9.2 million) and an administrative penalty of 10.2 million won on GS Retail (007070) after the personal data of about 1.66 million customers was leaked.
The Personal Information Protection Commission said on the 31st that it approved the measures against GS Retail for violations of personal data protection rules at a plenary meeting on the 26th. The commission also ordered the company to draw up measures to prevent a recurrence and to disclose the case on its website.
The investigation found that from June 2024 to February 2025, hackers attempted to log in to member information pages on the GS Shop and GS25 websites operated by GS Retail using credential stuffing, in which previously obtained account information is entered indiscriminately. Through this method, they stole personal data including names, gender, dates of birth, contact numbers, addresses and email addresses belonging to a total of 1,660,153 people — 1,581,025 from GS Shop and 79,128 from GS25.
GS Retail had no system in place to detect and block large volumes of login attempts from a single IP address over a short period, and failed to recognize the warning signs in time even as failed logins rose sharply, the commission found. The company also identified the breach at the GS25 website first in January 2025 but neglected follow-up measures, confirming the hacking of GS Shop only in February, two months after the incident.
The commission ordered GS Retail to adopt a security policy capable of identifying and blocking abnormal access by analyzing service traffic volumes and patterns. It also instructed the company to assign dedicated personnel for personal data protection and to review and improve its overall governance framework, including clarifying the authority and responsibilities of its chief privacy officer.
Enlyze, which operates a dating app service, was fined 118.44 million won and given an administrative penalty of 3.6 million won after personal data from 736 accounts was leaked in March 2023. The company was found to have breached its duty to take safety measures, including neglecting checks on identity verification vulnerabilities within the app and failing to block excessive access from a single IP address.
A leak also occurred at A to Z, which was contracted to build and operate an event website for ifland, the metaverse platform of SK Telecom (017670). An administrator page was exposed to search engines, leaking the names and mobile phone numbers of 1,140 users from November 2022 to January 2023.
According to the commission, A to Z failed to take access control measures such as IP restrictions on the administrator page, while SK Telecom reported and notified the breach late, exceeding the legally required 24 hours. The commission imposed an administrative penalty of 3.6 million won and a corrective order on SK Telecom, and issued a warning to A to Z.
"When operating personal data processing systems, it is essential to comply with basic security rules such as access controls that restrict unauthorized access and periodic vulnerability checks," a commission official said. "When a leak occurs, it must be reported and notified without delay within the legal deadline so that data subjects can respond quickly."






