GS Retail Hit with $9.3 Million Fine After Massive Data Breach Affecting 1.66 Million Customers
South Korea’s Personal Information Protection Commission (PIPC) has fined GS Retail Co., operator of the GS25 convenience store chain and GS SHOP home shopping platform, 12.8 billion won (US$9.3 million) following a major data breach that exposed the personal information of 1.66 million customers.
Between 2024 and 2025, an unidentified hacker exploited weak security controls by launching credential-stuffing attacks repeatedly injecting stolen user IDs and passwords to bypass login systems. The attacker accessed member information modification pages, compromising data from 1.58 million GS SHOP users and 79,128 GS25 customers. Leaked details included names, gender, dates of birth, contact numbers, home addresses, and email addresses.
The PIPC determined that GS Retail failed to detect abnormal activity, such as a surge in login attempts from the same IP addresses, allowing the breach to go unnoticed for an extended period. The company also lacked a dedicated privacy protection office at the time of the incident.
As part of the enforcement action, the PIPC has ordered GS Retail to implement advanced security measures, including systems to identify suspicious connections, and to appoint dedicated privacy protection personnel. The fine and corrective measures follow an investigation into the company’s security lapses.
Source: https://en.yna.co.kr/view/AEN20260831003900315
(주)GS리테일(GS Retail Inc.) cybersecurity rating report: https://www.rankiteo.com/company/gs-retail
"id": "GS-1788144886",
"linkid": "gs-retail",
"type": "Breach",
"date": "1/2024",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '1.66 million',
'industry': 'Retail, E-commerce',
'location': 'South Korea',
'name': 'GS Retail Co.',
'type': 'Corporation'}],
'attack_vector': 'Credential Stuffing',
'data_breach': {'number_of_records_exposed': '1.66 million',
'personally_identifiable_information': 'Names, gender, dates '
'of birth, contact '
'numbers, home '
'addresses, email '
'addresses',
'sensitivity_of_data': 'High (PII)',
'type_of_data_compromised': 'Personal Information'},
'description': 'South Korea’s Personal Information Protection Commission '
'(PIPC) fined GS Retail Co. 12.8 billion won (US$9.3 million) '
'following a major data breach that exposed the personal '
'information of 1.66 million customers. The breach occurred '
'due to credential-stuffing attacks exploiting weak security '
'controls.',
'impact': {'data_compromised': 'Names, gender, dates of birth, contact '
'numbers, home addresses, email addresses',
'financial_loss': '12.8 billion won (US$9.3 million)',
'identity_theft_risk': 'High',
'legal_liabilities': 'Fine imposed by PIPC',
'systems_affected': 'GS SHOP and GS25 login systems, member '
'information modification pages'},
'investigation_status': 'Completed',
'lessons_learned': 'Failure to detect abnormal activity (e.g., surge in login '
'attempts from the same IP addresses) and lack of a '
'dedicated privacy protection office contributed to the '
'breach.',
'post_incident_analysis': {'corrective_actions': 'Implementation of systems '
'to identify suspicious '
'connections, appointment of '
'dedicated privacy '
'protection personnel',
'root_causes': 'Weak security controls, lack of '
'abnormal activity detection, no '
'dedicated privacy protection '
'office'},
'recommendations': 'Implement advanced security measures to detect suspicious '
'connections, appoint dedicated privacy protection '
'personnel, and enhance monitoring of login systems.',
'references': [{'source': 'Personal Information Protection Commission '
'(PIPC)'}],
'regulatory_compliance': {'fines_imposed': '12.8 billion won (US$9.3 million)',
'legal_actions': 'Corrective measures ordered by '
'PIPC',
'regulations_violated': 'South Korea’s Personal '
'Information Protection '
'Act'},
'response': {'enhanced_monitoring': 'Systems to identify suspicious '
'connections',
'remediation_measures': 'Implementation of systems to identify '
'suspicious connections, appointment of '
'dedicated privacy protection personnel'},
'threat_actor': 'Unidentified hacker',
'title': 'GS Retail Data Breach and $9.3 Million Fine',
'type': 'Data Breach',
'vulnerability_exploited': 'Weak security controls, lack of abnormal activity '
'detection'}