Find the Right GRC Solution

Search and compare GRC technology built for the problems you’re trying to solve

South Korea Fines GS Retail $9.5 Million After Breaches Expose Data of More Than 1.6 Million People

South Korea Fines GS Retail $9.5 Million After Breaches Expose Data of More Than 1.6 Million People

By
Key Takeaways
  • GS Retail Faces Nearly $9.5 Million in Penalties: South Korea’s PIPC imposed an approximately $9.47 million (KRW 12.836 billion) administrative monetary penalty on GS Retail, plus an additional fine, corrective orders and a publication order.
  • More Than 1.6 Million People Were Affected: Credential-stuffing attacks exposed personal information belonging to 1,581,026 people through GS SHOP and another 79,128 through GS25.
  • The Response to the First Breach Became Part of the Case: The PIPC found that GS Retail failed to take adequate follow-up measures after discovering the GS25 breach, with some attacker IP addresses later appearing in attacks against GS SHOP.
  • Privacy Governance Was a Regulatory Issue: Beyond technical security failures, the PIPC cited GS Retail’s lack of a sufficiently structured privacy team, fragmented security operations and shortcomings in its breach reporting.
  • Three Other Companies Were Sanctioned: NRISE, SK Telecom and ATOZ also faced penalties, corrective measures or warnings over separate failures involving authentication, access controls and breach notification.
Deep Dive

South Korea’s Personal Information Protection Commission has imposed an approximately $9.47 million (KRW 12.836 billion) administrative monetary penalty on GS Retail, finding that the company failed to put adequate protections in place against cyberattacks and, after discovering the first breach, failed to respond adequately enough to prevent what followed.

The PIPC also imposed an administrative fine of about $2,200 (KRW 3 million), ordered GS Retail to publish the sanctions on its website and directed the company to make changes to its privacy organization and breach-prevention practices.

The regulator approved the sanctions at its Aug. 26 plenary meeting as part of an enforcement action covering four companies. NRISE, SK Telecom and ATOZ were also sanctioned over separate breaches. Across the four cases, the PIPC said it imposed administrative monetary penalties and fines totaling approximately $9.6 million (KRW 13 billion). GS Retail accounted for almost all of that amount.

The attacks were not especially novel. They were credential-stuffing attacks, an old and stubbornly effective technique that relies on a fact about internet users that attackers have understood for years: passwords get reused. Armed with credentials stolen elsewhere, attackers repeatedly tried to log into GS Retail accounts until some of those combinations worked. GS SHOP was targeted between June 21, 2024, and Feb. 13, 2025. The attack against GS25 ran from Dec. 26, 2024, through Jan. 4, 2025.

The personal information of 1,581,026 people was leaked through GS SHOP. Another 79,128 people were affected through GS25.

What troubled the PIPC was not simply that attackers got in. GS Retail had failed to implement measures to detect or block repeated login attempts coming from the same IP address over a short period, the regulator found. Nor did its systems catch the obvious signals such an attack produced, including sharp increases in login attempts and failures.

The result was an intrusion that could keep going. Then came Jan. 4. GS Retail learned of the breach involving GS25 that day, according to the PIPC. The regulator found that the company did not take adequate follow-up measures, and a subsequent breach involving GS SHOP occurred in February. Some of the IP addresses used against GS25 were also used in attacks against GS SHOP.

That sequence mattered to the regulator. The PIPC concluded that GS Retail’s failure to adequately address the problem after learning about the initial incident prolonged the breaches. The investigation also moved beyond the mechanics of authentication and traffic monitoring. Inside GS Retail, the PIPC found a privacy operation that was not adequately established or organized. The company lacked a structured privacy team, while its security operations were fragmented rather than integrated.

There was another failure after the breach was reported. GS Retail did not report an additional leak affecting 1,599 people to the competent authority within 72 hours and lacked justifiable grounds for the delay, according to the PIPC.

Its corrective orders consequently reach beyond another layer of technical defenses. GS Retail must establish and carry out concrete plans for preventing repeat breaches, including analyzing service traffic and access patterns for anomalies. It must also review and improve its privacy and data-protection governance, including the staffing of its privacy organization and the roles and responsibilities assigned to its chief privacy officer.

The distinction is worth noticing. The regulator found defective controls, but it also found an organization that was not adequately arranged to recognize and respond to what those controls were telling it.

The Other Breaches

The three other cases announced by the PIPC were much smaller, though the failures behind them were familiar. NRISE, which operates the dating app WIPPY, was hit after unknown hackers exploited vulnerabilities in the service’s self-authentication process. Between March 23 and March 27, 2023, attackers made login attempts using 16,803 mobile phone numbers and compromised 736 accounts.

The information exposed went considerably further than a username and phone number. It included nicknames, profile photographs, birthdates, personality information, educational backgrounds, occupations, heights and blood types.

The PIPC found that NRISE had failed to adequately review its authentication process for vulnerabilities and take the measures needed to address them. It also lacked sufficient safeguards for blocking or responding to surges in traffic from the same IP addresses. NRISE received an administrative monetary penalty of approximately $87,300 (KRW 118.44 million) and an administrative fine of about $2,650 (KRW 3.6 million).

The final case began with a website built for ifland, SK Telecom’s metaverse service. SK Telecom had entrusted ATOZ with building and operating a site used to host ifland events. For more than a month, from Nov. 21, 2022, through Jan. 3, 2023, the site’s administrator page could be found through search engines.

Personal information belonging to 1,140 people, including names and mobile phone numbers, was leaked. The PIPC found that ATOZ had failed to implement adequate access controls, including restrictions limiting access to the administrator page by IP address. SK Telecom committed a different violation: it failed to notify affected individuals and report the breach to the competent authority within 24 hours.

That deadline reflects the version of South Korea’s Personal Information Protection Act applicable to the incident. Under the earlier legal framework cited by the PIPC, information and communications service providers were required to notify affected people and report a breach within 24 hours after becoming aware of it.

The PIPC imposed an administrative fine of approximately $2,650 (KRW 3.6 million) on SK Telecom and issued a corrective order. ATOZ received a warning.

The four cases differ in size and circumstance, but the PIPC drew a fairly plain lesson from them. Companies operating systems that process personal information are expected to restrict unauthorized access, regularly look for vulnerabilities and fix the ones they find. When a breach occurs, notification and reporting obligations are not optional administrative cleanup.

The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

🔒
Cancel anytime
Full archive access
Custom alerts

Oops! Something went wrong