GS Retail: Wippy Data Breach Exposes 736 Users' Height, Blood Type; South Korea Fines nRiZE ₩118 Million — BigGo Finance

GS Retail: Wippy Data Breach Exposes 736 Users' Height, Blood Type; South Korea Fines nRiZE ₩118 Million — BigGo Finance

South Korean Regulator Fines Dating App Wippy and GS Retail for Major Data Breaches

South Korea’s Personal Information Protection Commission (PIPC) has imposed fines on two companies nRiZE, operator of the dating app Wippy, and retail giant GS Retail for failing to prevent large-scale data breaches that exposed sensitive user information.

In the case of Wippy, an attacker exploited a vulnerability in the app’s identity verification system between March 23 and 27, 2023, attempting logins with 16,803 mobile phone numbers. The breach compromised 736 user profiles, leaking nicknames, gender, photos, dates of birth, and highly personal details such as education, occupation, height, and blood type. The PIPC fined nRiZE ₩118.44 million ($86,000) and issued an additional ₩3.6 million ($2,600) administrative penalty, citing the company’s failure to implement basic security measures, including blocking excessive access attempts from the same IP address.

Separately, GS Retail faced a ₩12.84 billion ($9.3 million) fine and a ₩3 million ($2,200) administrative penalty for a credential-stuffing attack that exposed the data of 1.66 million users across its GS SHOP and GS25 platforms. The breach occurred between June 2024 and February 2025 for GS SHOP and December 2024 to January 2025 for GS25, with attackers extracting names, birthdates, contact details, addresses, and email addresses. Investigators found that GS Retail ignored warning signs, including a spike in failed logins, and failed to detect the attack on GS SHOP for nearly a month after identifying the GS25 breach despite the same 327 IP addresses being used in both incidents.

Both cases highlight critical lapses in cybersecurity protocols, including the absence of rate-limiting measures and delayed threat detection. The PIPC’s actions underscore the growing regulatory scrutiny on companies handling personal data in South Korea.

Source: https://finance.biggo.com/news/18fc3dab-8a16-4281-8e0c-f5b9b1345d8e

(주)GS리테일(GS Retail Inc.) cybersecurity rating report: https://www.rankiteo.com/company/gs-retail

"id": "GS-1788150360",
"linkid": "gs-retail",
"type": "Breach",
"date": "3/2023",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '736',
                        'industry': 'Technology/Dating Services',
                        'location': 'South Korea',
                        'name': 'nRiZE (Wippy)',
                        'type': 'Dating App Operator'},
                       {'customers_affected': '1.66 million',
                        'industry': 'Retail',
                        'location': 'South Korea',
                        'name': 'GS Retail',
                        'type': 'Retail Giant'}],
 'attack_vector': ['Exploited vulnerability in identity verification system',
                   'Credential stuffing'],
 'data_breach': {'number_of_records_exposed': {'GS Retail': '1.66 million',
                                               'Wippy': '736'},
                 'personally_identifiable_information': ['Nicknames',
                                                         'Gender',
                                                         'Photos',
                                                         'Dates of birth',
                                                         'Education',
                                                         'Occupation',
                                                         'Height',
                                                         'Blood type',
                                                         'Names',
                                                         'Birthdates',
                                                         'Contact details',
                                                         'Addresses',
                                                         'Email addresses'],
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Personally Identifiable '
                                              'Information (PII)',
                                              'Sensitive personal details']},
 'date_detected': {'GS Retail': {'GS SHOP': '2025-02', 'GS25': '2025-01'},
                   'Wippy': '2023-03-27'},
 'description': 'South Korea’s Personal Information Protection Commission '
                '(PIPC) has imposed fines on two companies, nRiZE (operator of '
                'the dating app Wippy) and retail giant GS Retail, for failing '
                'to prevent large-scale data breaches that exposed sensitive '
                'user information.',
 'impact': {'data_compromised': {'GS Retail': '1.66 million users (names, '
                                              'birthdates, contact details, '
                                              'addresses, email addresses)',
                                 'Wippy': '736 user profiles (nicknames, '
                                          'gender, photos, dates of birth, '
                                          'education, occupation, height, '
                                          'blood type)'},
            'financial_loss': {'GS Retail': '₩12.84 billion ($9.3 million)',
                               'Wippy': '₩118.44 million ($86,000)'},
            'identity_theft_risk': 'High',
            'legal_liabilities': ['Fines imposed by PIPC',
                                  'Administrative penalties'],
            'systems_affected': ['Wippy identity verification system',
                                 'GS SHOP and GS25 platforms']},
 'investigation_status': 'Completed',
 'lessons_learned': 'Critical lapses in cybersecurity protocols, including the '
                    'absence of rate-limiting measures and delayed threat '
                    'detection.',
 'post_incident_analysis': {'root_causes': ['Failure to implement basic '
                                            'security measures',
                                            'Ignored warning signs (e.g., '
                                            'spike in failed logins)',
                                            'Delayed detection of attacks']},
 'recommendations': ['Implement rate-limiting measures',
                     'Enhance threat detection capabilities',
                     'Monitor for excessive access attempts',
                     'Improve incident response times'],
 'references': [{'source': 'Personal Information Protection Commission '
                           '(PIPC)'}],
 'regulatory_compliance': {'fines_imposed': {'GS Retail': '₩12.84 billion '
                                                          '($9.3 million)',
                                             'Wippy': '₩118.44 million '
                                                      '($86,000)'},
                           'legal_actions': ['Administrative penalties'],
                           'regulations_violated': ['South Korea’s Personal '
                                                    'Information Protection '
                                                    'Act']},
 'title': 'South Korean Regulator Fines Dating App Wippy and GS Retail for '
          'Major Data Breaches',
 'type': ['Data Breach', 'Credential Stuffing'],
 'vulnerability_exploited': ['Lack of rate-limiting measures',
                             'Failure to detect excessive access attempts']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.