GS Retail Fined 12.8 Billion Won After 1.66 Million Data Leak

Privacy Commission Approves Sanctions Against GS Retail Hackers Breach GS Shop and GS25 Websites en Masse Surge in Failed Logins Went Undetected SK Telecom and Enlyze Also Fined

Technology|
|
By Lee Jin-seokljs@sedaily.com
||
Song Kyung-hee, chairperson of the Personal Information Protection Commission, bangs the gavel at the 17th plenary meeting held at the Government Complex Seoul on the 26th. Photo courtesy of the PIPC - Seoul Economic Daily Technology News from South Korea
Song Kyung-hee, chairperson of the Personal Information Protection Commission, bangs the gavel at the 17th plenary meeting held at the Government Complex Seoul on the 26th. Photo courtesy of the PIPC

South Korea's privacy regulator has imposed a fine of 12.836 billion won ($9.2 million) and an administrative penalty of 10.2 million won on GS Retail (007070) after the personal data of about 1.66 million customers was leaked.

The Personal Information Protection Commission said on the 31st that it approved the measures against GS Retail for violations of personal data protection rules at a plenary meeting on the 26th. The commission also ordered the company to draw up measures to prevent a recurrence and to disclose the case on its website.

The investigation found that from June 2024 to February 2025, hackers attempted to log in to member information pages on the GS Shop and GS25 websites operated by GS Retail using credential stuffing, in which previously obtained account information is entered indiscriminately. Through this method, they stole personal data including names, gender, dates of birth, contact numbers, addresses and email addresses belonging to a total of 1,660,153 people — 1,581,025 from GS Shop and 79,128 from GS25.

GS Retail had no system in place to detect and block large volumes of login attempts from a single IP address over a short period, and failed to recognize the warning signs in time even as failed logins rose sharply, the commission found. The company also identified the breach at the GS25 website first in January 2025 but neglected follow-up measures, confirming the hacking of GS Shop only in February, two months after the incident.

The commission ordered GS Retail to adopt a security policy capable of identifying and blocking abnormal access by analyzing service traffic volumes and patterns. It also instructed the company to assign dedicated personnel for personal data protection and to review and improve its overall governance framework, including clarifying the authority and responsibilities of its chief privacy officer.

Enlyze, which operates a dating app service, was fined 118.44 million won and given an administrative penalty of 3.6 million won after personal data from 736 accounts was leaked in March 2023. The company was found to have breached its duty to take safety measures, including neglecting checks on identity verification vulnerabilities within the app and failing to block excessive access from a single IP address.

A leak also occurred at A to Z, which was contracted to build and operate an event website for ifland, the metaverse platform of SK Telecom (017670). An administrator page was exposed to search engines, leaking the names and mobile phone numbers of 1,140 users from November 2022 to January 2023.

According to the commission, A to Z failed to take access control measures such as IP restrictions on the administrator page, while SK Telecom reported and notified the breach late, exceeding the legally required 24 hours. The commission imposed an administrative penalty of 3.6 million won and a corrective order on SK Telecom, and issued a warning to A to Z.

"When operating personal data processing systems, it is essential to comply with basic security rules such as access controls that restrict unauthorized access and periodic vulnerability checks," a commission official said. "When a leak occurs, it must be reported and notified without delay within the legal deadline so that data subjects can respond quickly."

Companies in this story

Original reporting by Lee Jin-seok for Seoul Economic Daily.

AI-translated from Korean. Quotes from foreign sources are based on Korean-language reports and may not reflect exact original wording.

Watch · Seoul Economic Daily

More →
2:58

AI KEY

Preview
Korean Corporate Intelligence HubKOSPI · KOSDAQ · 12 sectors

A live, cap-weighted view of every KOSPI and KOSDAQ sector, with same-day Korean reporting distilled by company — built for foreign investors, correspondents and analysts who need to scan Korea before the next session.

Korea Company Atlas

Preview
Market Ontology · The Feedback LoopKFTC 2025 · 92 groups · 121,954 articles

An English ontology of the Korean market — how companies, the media, the government and the National Assembly move each other in a loop. Korea's named controlling persons and designated business groups are a mechanism, not a risk to be priced blind.

SIGNAL

Now live
English Edition · Capital MarketsM&A · IPO · PE · Fund Flows

SIGNAL English Edition is live — Korea's deal desk reporting in English. M&A, IPOs, private equity and fund flows, covered daily for global institutional investors. Browse free; subscriber-only scoops at the 50% intro rate.