![]() |
| Song Kyeong-hee, Chairperson of the Personal Information Protection Commission. / Personal Information Protection Commission |
A fine of about 12.8 billion won has been imposed on GS Retail after the personal data of approximately 1.66 million users was confirmed to have been leaked from the websites of GS SHOP and GS25, both operated by the company.
The Personal Information Protection Commission (PIPC) announced on the 31st that it held a plenary meeting on the 26th and resolved to impose a fine of 12.836 billion won and an administrative fine of 3 million won on GS Retail for violating personal information protection laws and regulations. The commission also issued a corrective order requiring the company to publicly disclose the administrative measures on its website and formulate countermeasures to prevent recurrence.
According to the investigation, an unidentified hacker launched credential stuffing attacks against the GS SHOP website from June 21, 2024 to February 13 of last year, and against the GS25 website from December 26, 2024 to January 4 of last year. The attacker attempted to log in by inputting large volumes of previously obtained usernames and passwords. After successfully logging in, the hacker accessed the member profile modification pages and extracted information—including names, genders, dates of birth, contact details, addresses, and email addresses—belonging to 1,581,025 GS SHOP members and 79,128 GS25 members.
The investigation revealed that GS Retail failed to establish sufficient security measures to detect or block high-volume login attempts originating from the same IP address within a short period of time. The company also failed to properly identify anomalies such as sudden spikes in failed and attempted logins, allowing the leak to continue over an extended period.
In particular, even after recognizing the data leak at GS25 on January 4 of last year, GS Retail confirmed that the same attack was underway at GS SHOP only about a month later. Although 327 of the IP addresses utilized in the GS25 attack were reused in the assault on GS SHOP, the company failed to prevent additional damage.
The operation of the company's personal data protection organization was also found to be deficient. At the time of the incident, a dedicated organization for personal data protection had not been separately established, and security operations were bifurcated. Furthermore, while 1,599 additional affected individuals were identified during the PIPC investigation, GS Retail notified them of the leak well past the statutory 72-hour deadline without justifiable grounds.
The PIPC ordered GS Retail to improve its overall personal information protection framework by establishing security policies capable of identifying and blocking abnormal access, deploying dedicated personnel, and clearly defining the authority and responsibilities of the Chief Privacy Officer (CPO).
Kim Hong-chan
1
2
3
4
5
6
7