GS Retail Fined 12.8 Billion Won for Leaking Personal Data of 1.66 Million People
- Input
- 2026-08-31 12:15:07
- Updated
- 2026-08-31 12:15:07
The commission said the company neglected preventive security measures that should have allowed it to immediately detect and respond to signs of abnormal activity while collecting and managing consumer personal data.
On the 26th, the Personal Information Protection Commission decided at a plenary meeting to impose a fine of 12.836 billion won and a penalty of 3 million won on GS Retail for violating personal data protection rules, it said on the 31st.
According to the commission's investigation, the hacker used a credential stuffing attack to successfully log in to the GS SHOP website operated by GS Retail from June 21, 2024, to February 13 last year, and to the GS25 website from December 26, 2024, to January 4 last year. After gaining access, the hacker entered the member information edit page and stole personal data, including names, genders, birth dates, contact numbers, addresses and email addresses, from 1,581,025 GS SHOP members and 79,128 GS25 members.

"Credential stuffing" is an attack method in which a hacker tries to log in by indiscriminately using multiple IDs and passwords obtained in advance.
Although the hacker's attacks continued for more than a year, GS Retail was found to have had no measures in place to detect and block large-scale login attempts from the same IP address within a short period of time.
In particular, GS Retail knew in January last year that personal data had been leaked from the GS25 website, but took no meaningful action. As a result, it did not realize until a month later that the same attack was also taking place on GS SHOP, showing that its security system was inadequate.
Even as suspicious signs such as a sharp increase in login attempts and failed logins emerged, the company responsible for managing personal data failed to recognize them, allowing the leak to continue for a long period. Of the IP addresses used in the GS25 attack, 327 were also used in the GS SHOP attack, but the company failed to prevent further damage.
The commission said, "At the time of the incident, the company did not have a dedicated personal data team, and its security operations were split in two, indicating that its personal data protection organization was poorly structured and managed. Moreover, during the commission's investigation after the initial leak notice, 1,599 additional victims were identified, but GS Retail notified them of the breach more than 72 hours later without a valid reason."

Accordingly, the commission ordered GS Retail to pay the fine and penalty, and to disclose the disciplinary action on its website. It also instructed the company to prepare specific measures to prevent recurrence, including security policies that can identify abnormal access, and to review and improve its overall personal data governance system, such as assigning dedicated privacy staff and clarifying the authority and responsibilities of the Chief Privacy Officer.
In response, GS Retail said, "We once again apologize for causing concern over the personal data breach," and explained its recent efforts to strengthen security systems. "Since the breach, GS Retail has conducted a full review of its security systems and management framework, strengthened its information protection level, and formed an Information Security Measures Committee with key executives and outside experts to advance its security response system," it said.
The company added, "From the perspective of putting customers first, we are treating companywide personal data protection as a key management priority and continuing efforts to prevent recurrence, including employee training and improvements to internal management systems. We will continue to do our utmost to protect customer information and prevent another personal data leak."
Meanwhile, the commission also imposed fines, penalties and corrective orders on NRISE, SK Telecom and Atoz.
In the case of NRISE, which operates the dating app Wippy, a hacker attempted to log in using 16,803 mobile phone numbers in March 2023, and personal data such as nicknames, genders, profile photos, birth dates, education and occupations from 736 accounts were leaked.
NRISE was found to have neglected inspections and corrective measures for weaknesses in identity verification and failed to set a policy to block excessive access from the same IP address.
The commission imposed a fine of 11.844 million won and a penalty of 3.6 million won on NRISE.
On the event website for the metaverse service IFLAND, operated by SK Telecom and outsourced to Atoz, the administrator page was exposed to search engines from November 21, 2022, to January 3, 2023, resulting in the leak of the names and mobile phone numbers of 1,140 people.
Atoz did not apply access controls such as IP address restrictions to the administrator page, and SK Telecom was found to have notified and reported the breach after the legal deadline of 24 hours had passed once it became aware of the leak.
The commission imposed a penalty of 3.6 million won and a corrective order on SK Telecom, and issued a warning to Atoz.
[email protected] Lee Gu-soon Reporter