GS Retail fined $9.3 mln over data leak affecting 1.66 mln customers
South Korea's privacy watchdog fined GS Retail 12.8 billion won for a data leak that exposed personal details of 1.66 million GS SHOP and GS25 customers.
According to the PIPC, an unidentified hacker infiltrated the company's home shopping platform GS SHOP and its convenience store chain between 2024 and 2025 by repeatedly injecting a large number of pre-secured user IDs and passwords, successfully bypassing login systems. Through member information modification pages, the attacker compromised the personal data of 1.58 million GS SHOP users and 79,128 GS25 customers. The leaked information included names, gender, dates of birth, contact numbers, home addresses and email addresses.
The privacy watchdog said GS Retail failed to notice abnormal signs, such as a sharp spike in login attempts and failures from identical IP addresses within a short time frame, which allowed the unauthorized access to persist undetected over a prolonged period. The company also lacked a dedicated office for privacy protection at the time of the incident.
The PIPC ordered GS Retail to formulate concrete preventive measures, such as advanced security policies capable of identifying abnormal connections, and to appoint dedicated personnel for privacy protection.