Urgent.News

What's breaking now, across thousands of outlets.

World

GS Retail fined $9.3 mil. over personal data leak of 1.66 mil. customers

GS Retail Co., a retail giant that operates GS25 convenience stores, has been issued a 12.8 billion-won ($9.3 million) fine over a personal data leak that affected 1.66 million customers, the privacy watchdog said Monday. According to the Personal Information Protection Commission (PIPC), an unidentified hacker infiltrated the company's home shopping platform GS SHOP and its convenience store…

GS Retail fined $9.3 mil. over personal data leak of 1.66 mil. customers

GS Retail, a major retail chain with over a thousand GS25 convenience stores, has been hit with a significant fine of $9.3 million for compromising the personal data of 1.66 million customers, according to the Personal Information Protection Commission (PIPC). The breach occurred between 2024 and 2025, as an unknown hacker exploited vulnerabilities in GS Retail's systems, specifically its GS SHOP home shopping platform and the convenience store chain.

The hacker used a technique called "credential stuffing," where they repeatedly entered stolen user IDs and passwords to gain unauthorized access to login systems. By targeting the member information modification pages, the hacker managed to access and steal personal data from 1.58 million GS SHOP users and 79,128 GS25 customers. The stolen information included sensitive details like names, genders, dates of birth, contact numbers, home addresses, and email addresses.

What made the situation even more concerning was the company's failure to detect the intrusion and subsequent data theft. The PIPC noted that GS Retail missed crucial warning signs, such as a sudden surge in login attempts and failures originating from identical IP addresses within a short period. This allowed the unauthorized access to remain undetected for an extended period, putting millions of customers at risk.

The company's lack of a dedicated security team and robust monitoring mechanisms also played a role in the breach. The PIPC emphasized that GS Retail failed to promptly identify and address the security gaps, allowing the hacker to exploit their systems for an extended period. The fine serves as a stern reminder of the importance of robust cybersecurity measures and proactive monitoring to protect sensitive customer data from malicious actors.

Written by urgent.news from The Korea Times's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at koreatimes.co.kr →

More in World

More from Monday 31 August →