South Korea's Personal Information Protection Commission said on Aug. 31 it imposed a total of 12.95 billion won in penalties and 10.2 million won in fines on GS Retail and three other operators for violating personal data protection rules, after holding a plenary meeting on Aug. 26.
The commission also voted to issue corrective orders, including requiring measures to prevent recurrence, and to publish the results on the operators' websites.
The commission also imposed penalties and fines on Nrise, which operates a dating app, SK Telecom, which provides a metaverse service, and Atoz, an online marketing services company, in addition to GS Retail.
The commission said the operators failed to take adequate security measures, including access controls for personal data processing systems, leading to data leaks.
GS Retail was fined 12.84 billion won and 3 million won in penalties.
An unidentified hacker attempted credential-stuffing attacks and successfully logged in to the GS SHOP website operated by GS Retail from June 21, 2024 to Feb. 13, 2025, and to the GS25 website from Dec. 26, 2024 to Jan. 4, 2025. The hacker then used the member information edit page to leak personal data, including names, gender, date of birth, contact details, address and email, of 1,581,025 people from GS SHOP and 79,128 people from GS25.
GS Retail did not put in place measures to detect and block large-scale login attempts from the same IP address within a short period. It also failed to recognise abnormal signs such as a sharp increase in login attempts and login failures, allowing the leak to continue for a long period.
GS Retail first became aware of the leak on the GS25 website on Jan. 4, 2025, but responded poorly to the incident. It also became additionally aware in February 2025 that the same attack was occurring on the GS SHOP website, and personal data continued to be leaked even after the initial detection of the breach.
In Nrise's case, an unidentified hacker exploited a vulnerability in the app's identity verification and attempted logins using 16,803 mobile phone numbers from March 23 to March 27, 2023, leaking personal data from 736 accounts. The commission imposed a penalty of 118.44 million won and a fine of 3.6 million won.
Atoz was commissioned by SK Telecom to run an event for the Ifland service and produced and operated an event website. From Nov. 21, 2022 to Jan. 3, 2023, the admin page was exposed to search engines, leaking personal data, including names and mobile phone numbers, of 1,140 people. The commission imposed a fine of 3.6 million won on SK Telecom and issued a warning to Atoz.