South Korea’s FSC cut the sanction from the 4.5 months previously considered, but the card issuer still faces a halt in new customer acquisition, member attrition risk and market-share pressure.
Lotte Card was handed a 1.5-month business suspension and a 5 billion won fine after a hacking breach that exposed the personal information of 2.97 million customers, with South Korea’s Financial Services Commission reducing the sanction from the 4.5-month suspension previously deliberated by the Financial Supervisory Service. The penalties, imposed for violations of the Specialized Credit Finance Business Act and the Credit Information Use and Protection Act, will run from Aug. 1 to Sept. 15 and bar the company from issuing new credit, debit and prepaid cards to new members. The FSC said it lowered the sanction because the case involved an external hack and because Lotte Card moved quickly after the incident, including operating a 24-hour damage prevention center that prevented secondary harm such as fraudulent transactions. The regulator also cited the voluntary resignation of five executives including former CEO Jo Jwa-jin, a plan to invest 120 billion won over five years in information security, and broader remediation efforts. It said it had weighed fairness with past sanctions, the company’s follow-up measures, and the impact on financial markets and consumers. Existing members will still be able to use cards, receive renewals and replacement reissuance, and apply for card loans, cash advances, revolving credit and contract-limit increases. But even current customers will be barred from adding new cards during the suspension because that is treated as a new contractual relationship, with limited exceptions for public-purpose cards including Sunshine Loan cards, free subway cards for the elderly in Busan and military personnel-related cards. The decision leaves Lotte Card facing operational and competitive strain even though it avoided the harsher outcome many expected. Based on average monthly membership cancellations of 77,000 in the first half, the company could lose roughly 115,000 members during the 1.5-month suspension if cancellations continue and no new sign-ups are allowed. Lotte Card had 8.557 million active individual credit card members at the end of June. Its individual credit sales market share was 8.85% at end-June, down 0.34 percentage points from August last year, while Woori Card topped 7.0% in the first half, narrowing the gap to 1.91 percentage points. The ruling is being watched as the first business suspension imposed on a financial company in South Korea over an externally caused hacking-related data breach, potentially setting a benchmark for future cases. Financial authorities said they would support revisions to the Electronic Financial Transactions Act that would allow punitive fines of up to 3% of total revenue for major security incidents and strengthen the authority of the Chief Information Security Officer to establish security measures. Lotte Card said it would use the suspension period as a time for overhaul, focusing on stronger information security and core business competitiveness.