GS Retail and SK Telecom: GS Retail fined 12.8 billion won over data breach affecting 1.66 million users

GS Retail and SK Telecom: GS Retail fined 12.8 billion won over data breach affecting 1.66 million users

GS Retail Hit with $9.3 Million Fine Over Massive Data Breach Affecting 1.66 Million Users

South Korea’s Personal Information Protection Commission (PIPC) has fined GS Retail 12.84 billion won ($9.3 million) for failing to protect user data during a prolonged credential-stuffing attack that compromised 1.66 million accounts. The breach, which spanned from June 2024 to February 2025, exposed sensitive personal information, including names, birthdates, phone numbers, addresses, and email addresses.

The attacks targeted GS Shop (June 21, 2024–Feb. 13, 2025) and GS25 (Dec. 26, 2024–Jan. 4, 2025), with hackers exploiting weak security controls to access 1.58 million GS Shop users and 79,128 GS25 users. The PIPC found that GS Retail lacked measures to detect and block suspicious login attempts, such as repeated failed logins from the same IP addresses. The company also failed to act on warning signs, including a surge in login attempts, allowing the breach to persist for months.

GS Retail only discovered the GS25 breach on January 4, 2025, and took over a month to identify the parallel attack on GS Shop. Investigators noted that 327 IP addresses used in the GS25 attack were also linked to the GS Shop breach. Further scrutiny revealed that GS Retail had no dedicated privacy protection team at the time, with security operations fragmented across separate systems.

The PIPC also criticized GS Retail for delayed notifications, as the company failed to inform all affected users within the legally required 72-hour window. An additional 1,599 victims were identified after the initial disclosure. In addition to the fine, the commission ordered GS Retail to publicly disclose disciplinary actions, strengthen breach detection measures, and appoint dedicated security personnel with clear responsibilities for its chief privacy officer.

The PIPC also penalized other companies for separate breaches:

"id": "SK-GSR1788172218",
"linkid": "sk-telecom, gsretaill",
"type": "Breach",
"date": "6/2024",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '1,660,000',
                        'industry': 'Retail',
                        'location': 'South Korea',
                        'name': 'GS Retail',
                        'type': 'Retail Corporation'},
                       {'customers_affected': '1,580,000',
                        'industry': 'Retail',
                        'location': 'South Korea',
                        'name': 'GS Shop',
                        'type': 'E-commerce Platform'},
                       {'customers_affected': '79,128',
                        'industry': 'Retail',
                        'location': 'South Korea',
                        'name': 'GS25',
                        'type': 'Convenience Store Chain'}],
 'attack_vector': 'Credential Stuffing',
 'customer_advisories': 'Delayed notifications to affected users',
 'data_breach': {'number_of_records_exposed': '1,660,000',
                 'personally_identifiable_information': 'Names, birthdates, '
                                                        'phone numbers, '
                                                        'addresses, email '
                                                        'addresses',
                 'sensitivity_of_data': 'High (names, birthdates, phone '
                                        'numbers, addresses, email addresses)',
                 'type_of_data_compromised': ['Personally Identifiable '
                                              'Information (PII)']},
 'date_detected': '2025-01-04',
 'description': 'South Korea’s Personal Information Protection Commission '
                '(PIPC) fined GS Retail 12.84 billion won ($9.3 million) for '
                'failing to protect user data during a prolonged '
                'credential-stuffing attack that compromised 1.66 million '
                'accounts. The breach exposed sensitive personal information, '
                'including names, birthdates, phone numbers, addresses, and '
                'email addresses.',
 'impact': {'brand_reputation_impact': 'Public disclosure of disciplinary '
                                       'actions required',
            'data_compromised': 'Names, birthdates, phone numbers, addresses, '
                                'email addresses',
            'financial_loss': '$9.3 million (fine)',
            'identity_theft_risk': 'High (exposure of personally identifiable '
                                   'information)',
            'legal_liabilities': 'Fine imposed by PIPC',
            'operational_impact': 'Delayed breach detection and response, '
                                  'fragmented security operations',
            'systems_affected': ['GS Shop', 'GS25']},
 'investigation_status': 'Completed',
 'lessons_learned': 'Lack of dedicated privacy protection team and fragmented '
                    'security operations contributed to prolonged breach. Weak '
                    'detection of suspicious login attempts and delayed '
                    'response exacerbated the incident.',
 'post_incident_analysis': {'corrective_actions': 'Strengthen breach detection '
                                                  'measures, appoint dedicated '
                                                  'security personnel, improve '
                                                  'notification timelines, '
                                                  'unify security operations',
                            'root_causes': 'Weak security controls, lack of '
                                           'detection for suspicious login '
                                           'attempts, fragmented security '
                                           'operations, no dedicated privacy '
                                           'protection team'},
 'recommendations': 'Implement robust detection for suspicious login attempts, '
                    'appoint dedicated security personnel, improve breach '
                    'notification timelines, and unify security operations '
                    'under a chief privacy officer.',
 'references': [{'source': 'Personal Information Protection Commission '
                           '(PIPC)'}],
 'regulatory_compliance': {'fines_imposed': '$9.3 million',
                           'legal_actions': 'Public disclosure of disciplinary '
                                            'actions ordered',
                           'regulations_violated': ['South Korea’s Personal '
                                                    'Information Protection '
                                                    'Act'],
                           'regulatory_notifications': 'Failed to notify all '
                                                       'affected users within '
                                                       '72-hour window'},
 'response': {'communication_strategy': 'Delayed notifications to affected '
                                        'users (beyond 72-hour legal '
                                        'requirement)',
              'enhanced_monitoring': 'Required as part of corrective actions',
              'remediation_measures': 'Strengthen breach detection measures, '
                                      'appoint dedicated security personnel'},
 'stakeholder_advisories': 'Public disclosure of disciplinary actions required '
                           'by PIPC',
 'title': 'GS Retail Data Breach Affecting 1.66 Million Users',
 'type': 'Data Breach',
 'vulnerability_exploited': 'Weak security controls, lack of detection for '
                            'suspicious login attempts'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.