Financial Authority Reduces Lotte Card's Business Suspension for Data Breach

by Galim Kwon Posted : July 31, 2026, 17:44Updated : July 31, 2026, 17:44

The Financial Services Commission has imposed a 1.5-month business suspension on Lotte Card following a cyber breach that exposed the information of 2.97 million customers. This penalty is significantly lower than the 4.5-month suspension recommended by the Financial Supervisory Service, taking into account the potential impact on consumers.

On July 31, the Financial Services Commission finalized the sanctions during a regular meeting.

Investigations revealed that Lotte Card violated security obligations by failing to conduct necessary corrections in its online payment system, not encrypting personal identification numbers and passwords, and not installing antivirus software.

The suspension will take effect from August 1 and last until September 15, totaling 1.5 months. This is a substantial reduction from the initially proposed 4.5-month suspension.

Initially, there were expectations of a severe penalty for Lotte Card, especially since this is not the first incident; the company faced a three-month suspension in 2014 due to a similar data breach. The seriousness of the current breach was heightened by the fact that it resulted from external hacking rather than internal employee misconduct.

However, Lotte Card's proactive response immediately following the incident and the absence of further secondary damage likely contributed to the reduced suspension period.

A Financial Services Commission official stated, "The duration of the business suspension was determined by considering various factors, including fairness with previous sanctions, the company's recovery efforts, and the impact on the financial market and consumers."

The official added, "It is undesirable for customers who are not at fault for the data breach to experience inconvenience due to the business suspension. Therefore, while new card services for new members will be halted, existing members will still be able to apply for and use card-related services."

The fine has been confirmed at 5 billion won, as originally proposed. The disciplinary action against former CEO Jo Jwa-jin, which was also recommended by the Financial Supervisory Service, will be handled according to the Credit Finance Business Act, which allows the Financial Supervisory Service to impose certain sanctions on retired executives.

To prevent future data breaches, the Financial Services Commission plans to introduce punitive fines for serious security incidents, which could be up to 3% of total revenue. It will also actively support the passage of amendments to the Electronic Financial Transactions Act, which includes strengthening the authority of Chief Information Security Officers (CISOs) to enhance security measures.





* This article has been translated by AI.