GS Retail fined 12.8 bln won over personal data leak of 1.66 mln customers
SEOUL, Aug. 31 (Yonhap) -- GS Retail Co., a retail giant that operates GS25 conv...
Seoul, August 31 - GS Retail, a major retail company operating GS25 convenience stores, has received a 12.8 billion won ($9.3 million) fine for a personal data breach affecting 1.66 million customers, according to the Personal Information Protection Commission (PIPC). The breach, which occurred between 2024 and 2025, was caused by an unidentified hacker who infiltrated GS Retail's home shopping platform, GS SHOP, and its convenience store network.
The hacker exploited the system by repeatedly using a large number of pre-secured user IDs and passwords to bypass login systems. By using member information modification pages, the hacker was able to access and leak personal data of 1.58 million GS SHOP users and 79,128 GS25 customers. This data included names, gender, dates of birth, contact numbers, home addresses, and email addresses.
The PIPC stated that GS Retail failed to detect abnormal signs, such as a sudden increase in login attempts and failures from the same IP addresses, which allowed the unauthorized access to remain undetected for an extended period. The company also lacked a specific department dedicated to privacy protection at the time of the incident.
In response to the breach, the PIPC has ordered GS Retail to implement concrete preventive measures, including advanced security policies to identify abnormal connections and to appoint dedicated personnel for privacy protection.
Written by urgent.news from Yonhap News's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.