{
  "id": 4556802,
  "title": "GS Retail fined $9.3 mil. over personal data leak of 1.66 mil. customers",
  "url": "https://urgent.news/2026/08/31/gs-retail-fined-9-3-mil-over-personal-data-leak-of-1-66-mil-customers",
  "topic": "world",
  "section": "World",
  "published": "2026-08-31T03:17:03.000Z",
  "source": {
    "name": "The Korea Times",
    "slug": "the-korea-times",
    "url": "https://www.koreatimes.co.kr/business/companies/20260831/gs-retail-fined-93-mil-over-personal-data-leak-of-166-mil-customers"
  },
  "original_language": "en",
  "account": "GS Retail, a major retail chain with over a thousand GS25 convenience stores, has been hit with a significant fine of $9.3 million for compromising the personal data of 1.66 million customers, according to the Personal Information Protection Commission (PIPC). The breach occurred between 2024 and 2025, as an unknown hacker exploited vulnerabilities in GS Retail's systems, specifically its GS SHOP home shopping platform and the convenience store chain.\n\nThe hacker used a technique called \"credential stuffing,\" where they repeatedly entered stolen user IDs and passwords to gain unauthorized access to login systems. By targeting the member information modification pages, the hacker managed to access and steal personal data from 1.58 million GS SHOP users and 79,128 GS25 customers. The stolen information included sensitive details like names, genders, dates of birth, contact numbers, home addresses, and email addresses.\n\nWhat made the situation even more concerning was the company's failure to detect the intrusion and subsequent data theft. The PIPC noted that GS Retail missed crucial warning signs, such as a sudden surge in login attempts and failures originating from identical IP addresses within a short period. This allowed the unauthorized access to remain undetected for an extended period, putting millions of customers at risk.\n\nThe company's lack of a dedicated security team and robust monitoring mechanisms also played a role in the breach. The PIPC emphasized that GS Retail failed to promptly identify and address the security gaps, allowing the hacker to exploit their systems for an extended period. The fine serves as a stern reminder of the importance of robust cybersecurity measures and proactive monitoring to protect sensitive customer data from malicious actors.",
  "summary": "GS Retail Co., a retail giant that operates GS25 convenience stores, has been issued a 12.8 billion-won ($9.3 million) fine over a personal data leak that affected 1.66 million customers, the privacy watchdog said Monday. According to the Personal Information Protection Commission (PIPC), an unidentified hacker infiltrated the company's home shopping platform GS SHOP and its convenience store…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 3,
    "also_reported_by": [
      {
        "outlet": "Yonhap News",
        "title": "GS Retail fined 12.8 bln won over personal data leak of 1.66 mln customers",
        "url": "https://urgent.news/2026/08/31/gs-retail-fined-12-8-bln-won-over-personal-data-leak-of-1-66-mln",
        "published": "2026-08-31T02:22:01.000Z"
      },
      {
        "outlet": "The Korea Times",
        "title": "GS Retail fined $9.3 mil. over personal data leak of 1.66 mil. customers",
        "url": "https://urgent.news/2026/08/31/gs-retail-fined-9-3-mil-over-personal-data-leak-of-1-66-mil-customers-4558185",
        "published": "2026-08-31T03:22:03.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}