Data leaked from GS25, GS Home Shopping and GS Supermarket; Enlaiz and SK Telecom also sanctioned

Personal Information Protection Commission Chairperson Song Kyung-hee [Personal Information Protection Commission]
Personal Information Protection Commission Chairperson Song Kyung-hee [Personal Information Protection Commission]

The Personal Information Protection Commission has fined GS Retail about 12.8 billion won ($9.27 million) for leaking the personal data of roughly 1.66 million people, and ordered the company to overhaul its data-protection organization and put in place measures to prevent a recurrence.

The commission held a plenary session Wednesday and voted to impose a fine of 12.84 billion won and an administrative penalty of 3 million won on GS Retail for violating the Personal Information Protection Act, along with a corrective order and a requirement to publish the outcome on its website, the commission announced Monday.

GS Retail's websites — including those of GS Shop (home shopping) and GS25 (convenience store) — were subjected to hacking attacks between June 21, 2024, and Feb. 13 last year. The attacks used so-called credential stuffing, in which large volumes of previously obtained usernames and passwords are systematically tried against login systems.

As a result, the personal information of about 11.58 million GS Home Shopping users and 79,128 GS25 users was exposed, including names, genders, dates of birth, contact details, addresses and email addresses.

GS Retail had failed to put in place measures to detect and block mass login attempts originating from the same internet protocol address. Even as abnormal spikes in login attempts and failures emerged as warning signs, the company did not recognize them, allowing the breach to continue for an extended period.

The company first detected the GS25 website breach on Jan. 4 last year but was slow to respond. It did not discover until February last year that the same type of attack was simultaneously targeting the GS Home Shopping website. As a result, personal data continued to leak from Jan. 4 through Feb. 13 of that year, even after the initial breach was identified.

Investigators also found that 327 of the IP addresses used in the GS25 attack were the same ones used against GS Shop.

[Personal Information Protection Commission]
[Personal Information Protection Commission]

The commission also found that GS Retail lacked a dedicated personal data protection unit at the time of the incident and operated a fragmented security structure. During the investigation following the initial breach notification, an additional 1,599 affected individuals were identified, but the company notified them more than 72 hours after discovery without justifiable cause.

The commission ordered GS Retail to publish the details of the sanctions on its website, establish and implement recurrence-prevention measures — including security policies capable of identifying abnormal access — and assign dedicated personal data protection staff while clarifying the authority and responsibilities of its chief privacy officer.

Meanwhile, the commission fined Enlaiz, the operator of a dating app, 118.44 million won and imposed an administrative penalty of 3.6 million won over the leak of personal data from 736 accounts. SK Telecom was also sanctioned with an administrative penalty of 3.6 million won.

Atoz, which was commissioned by SK Telecom to run events for its "ifland" service and built and operated an event website for that purpose, leaked the names and mobile phone numbers of 1,140 people after failing to restrict access to its administrator page by IP address. SK Telecom received its administrative penalty for reporting the data breach more than 24 hours after it occurred.


ko@heraldcorp.com