Lotte Card Suspension Finalized at 1.5 Months Down from 4.5; New Card Issuance Banned
Sanctions Finalized Over Last Year’s Data Breach Affecting 2.97 Million Customers
Three-Month Shorter Suspension Than FSS Recommendation; 5 Billion Won Penalty Maintained
Financial Services Commission: "Considered Fairness With Past Sanctions an
The Financial Services Commission has finalized sanctions against Lotte Card, which suffered a hacking incident last August that led to the leak of credit information for 2.97 million customers. The sanctions include a 1.5-month suspension of work and a fine of 5 billion won. Although this is significantly less severe than the 4.5-month suspension initially decided by the Financial Supervisory Service, it is the first time a suspension of work has been imposed due to a data breach caused by hacking.
On July 31, the Financial Services Commission announced at its regular meeting that it had resolved to impose these sanctions on Lotte Card in accordance with the ‘Specialized Credit Financial Business Act’ and the ‘Act on the Use and Protection of Credit Information’.
An official at the Financial Services Commission stated, “After taking into account the company's statement and deliberation by the agenda subcommittee, this is the first time a suspension of work has been imposed for a data breach involving hacking. The 1.5-month suspension was decided by considering the fairness compared to previous cases, the company’s recovery efforts, and the potential impact on the financial market and consumers.”
Previously, the Financial Supervisory Service held a sanction review committee in April and initially decided on a 4.5-month business suspension and a fine of 5 billion won for Lotte Card. After review by the agenda subcommittee and a regular meeting by the Financial Services Commission, the suspension period was reduced by 3 months, while the fine remained unchanged.
As a result of this decision, Lotte Card will suspend work from August 1 until September 15. During this period, issuing new credit, check, and prepaid cards to new customers will be prohibited, except for a few exceptional cases such as cards for public purposes.
However, to minimize inconvenience to existing customers who are not at fault for the data breach, card services for these customers will operate normally. Existing members will be able to receive replacement cards and continue to apply for and increase limits for services such as card loans, cash advances, and revolving credit.
Financial authorities plan to use this incident as an opportunity to fundamentally strengthen security management systems within financial companies. They intend to introduce punitive fines of up to 3% of total revenue for severe security incidents, and to actively support the passage of amendments to the ‘Electronic Financial Transactions Act’ in the National Assembly, which include provisions to strengthen the authority of the Chief Information Security Officer (CISO).
Hot Picks Today
"30,000 Won Per Night, Is This for Real?"... What Is the Korean Experience Drawing Foreigners?
- "Even More Money Isn't Enough: Gen Z Refuses Management Roles Over Added Responsibility"
- 'Shocking Betrayal After 10 Years'... Housekeeper in Her 60s Stole Luxury Goods Worth Tens of Millions of Won
- Lending Out Clothes Lying Around the House Earns $7,000 a Month... This Side Hustle is Booming in the U.S.
- "Just Hold On," Says Chairman Choi Tae-won Who Bet 4.9 Billion Won... Earns 1.3 Billion Won in a Day
An official from the Financial Services Commission added, “We will make every effort to protect financial consumers, including continuously monitoring the impact of the business suspension, to prevent inconvenience in their use of card services.”
© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.