PIPC fines GS Retail 12.836 billion won over customer data breach

  • PIPC fined GS Retail over data breaches affecting GS Shop and GS25 customers.
  • 1,660,153 customers had names, contact details and other personal data exposed.
  • PIPC separately sanctioned Enlyze, SK Telecom and A to Z over security breaches.

South Korea’s Personal Information Protection Commission imposed a 12.836 billion won fine and a 10.2 million won administrative penalty on GS Retail after credential-stuffing attacks exposed personal data from 1,660,153 customers of its GS Shop and GS25 websites. The affected records included names, gender, dates of birth, contact numbers, addresses and email addresses. The commission said GS Retail lacked controls to detect and block high-volume login attempts from individual IP addresses, failed to respond promptly to surging login failures, and did not adequately follow up after identifying the GS25 breach before confirming the GS Shop intrusion. It ordered stronger traffic monitoring, dedicated privacy personnel, clearer authority for the chief privacy officer, recurrence-prevention measures and publication of the case on the company’s website. In separate actions, the commission fined dating-app operator Enlyze 118.44 million won and imposed a 3.6 million won administrative penalty after data from 736 accounts leaked. It also penalized SK Telecom and warned A to Z over an ifland event website breach that exposed the names and mobile phone numbers of 1,140 users.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.