Korea's Personal Information Protection Commission Fines GS Retail 12.8 Billion Won for Data Breach

by Shin Hye An Posted : August 31, 2026, 11:04Updated : August 31, 2026, 11:04

The Personal Information Protection Commission (PIPC) has imposed a fine of 12.836 billion won and an additional penalty of 3 million won on GS Retail for violating personal data protection regulations. Enrise and SK Telecom also received fines and penalties, while Atoz was issued a warning.


On August 26, during its 17th plenary meeting, the PIPC announced that it had levied a total of 12.954 billion won in fines and 10.2 million won in penalties against GS Retail, Enrise, SK Telecom, and Atoz for breaches of personal data protection laws. The commission also ordered these companies to implement corrective measures and to publicly disclose the results on their websites.


The PIPC found that all four companies had neglected safety measures, such as access control to their personal data processing systems, leading to data breaches.


GS Retail was fined 12.836 billion won and received a penalty of 3 million won. According to the PIPC, an unidentified hacker successfully executed a credential stuffing attack on the GS SHOP website from June 21, 2024, to February 13, 2025, and on the GS25 website from December 26, 2024, to January 4, 2025. Credential stuffing involves using a large number of previously obtained usernames and passwords to gain unauthorized access.


The hacker accessed the member information modification page, resulting in the exposure of personal data for 1,581,025 GS SHOP users and 79,128 GS25 users, including names, genders, birth dates, contact information, addresses, and email addresses.


GS Retail failed to implement measures to detect and block large-scale login attempts from the same IP address within a short time frame. Despite a significant increase in login attempts and failures, the company did not recognize the anomaly, allowing the data breach to continue for an extended period.


Even after becoming aware of the breach, GS Retail did not take appropriate action, leading to further data exposure on GS SHOP. Although the company first recognized the data breach on January 4, 2025, it was not until February that it identified the same attack occurring on the GS SHOP website. Consequently, data exposure continued from January 4 to February 13.


Despite recognizing the breach on the GS25 website, GS Retail failed to adequately respond, resulting in the same attack on the GS SHOP website going unnoticed. Notably, 327 of the IP addresses used in the GS25 attack were also identified in the GS SHOP attack.


The investigation revealed that GS Retail lacked a dedicated personal data protection organization and that its security operations were poorly structured. An additional 1,599 individuals were identified as victims during the investigation, but the company notified them of the breach more than 72 hours after the initial incident without justifiable reasons.


As a result, the PIPC imposed a fine of 12.836 billion won and a penalty of 3 million won on GS Retail, ordering the company to publicly disclose the penalties on its website.


The commission also mandated GS Retail to implement security policies that analyze service access patterns to identify abnormal access and to establish a governance system that includes dedicated personnel for data protection and clarifies the roles and responsibilities of the Chief Privacy Officer (CPO).


The PIPC fined Enrise 118.44 million won and imposed a penalty of 360,000 won. A hacker exploited a vulnerability in the identity verification process of a dating app operated by Enrise, attempting to log in with 16,803 phone numbers from March 23 to 27, 2023. During this process, personal data, including nicknames, genders, profile pictures, birth dates, personalities, education, occupations, heights, and blood types of 736 accounts were exposed.


The investigation found that Enrise neglected to check and address the vulnerability in the app's identity verification process and failed to implement policies to block excessive access from the same IP address, violating its obligation to ensure safety.


The PIPC also imposed a penalty of 360,000 won and a corrective order on SK Telecom, while Atoz received a warning.


Atoz was contracted by SK Telecom to manage an event for its metaverse service, 'ifland,' and created an event website. During this process, from November 21, 2022, to January 3, 2023, the administrator page was exposed to search engines, leading to the exposure of names and phone numbers of 1,140 individuals.


The investigation revealed that Atoz did not implement access control measures, such as IP address restrictions, for the administrator page. SK Telecom was found to have reported the data breach more than 24 hours after becoming aware of it.


This incident falls under the previous Personal Information Protection Act, which requires information and communication service providers to notify and report data breaches within 24 hours of becoming aware of them.


The PIPC emphasized the importance of adhering to basic principles, such as restricting unauthorized access during the operation of personal data processing systems and conducting regular vulnerability assessments and measures. The commission urged that in the event of a data breach, affected individuals should be promptly informed and that notifications should be made within 72 hours.


GS Retail stated, “We have established an 'Information Security Countermeasures Committee' involving key executives and external experts to enhance our security response system. We are thoroughly reviewing our security systems and management frameworks to strengthen our data protection levels. From a customer-first perspective, we are making data protection a key management priority and are continuously working on employee training and internal management system improvements to prevent recurrence. We will continue to do our utmost to protect customer information and prevent future data breaches.”





* This article has been translated by AI.