Personal Information Protection Commission Fines GS Retail 12.8 Billion Won for Breach Affecting 1.58 Million Members
Credential Stuffing Attack: Random Use of Usernames and Passwords
No Measures in Place to Block Mass Login Attempts
GS Retail, which failed to prevent the personal data breach involving approximately 1.58 million members, has been fined around 12.8 billion won.
The Personal Information Protection Commission announced on August 31 that it held its 17th general meeting on August 26 and imposed an administrative fine of 12,836 million won and an additional penalty of 3 million won on GS Retail for violating personal information protection regulations. The commission also decided to issue a corrective order to establish measures to prevent recurrence, and mandated that the incident results be published on the company's website.
According to the commission's investigation, a hacker succeeded in logging into some member accounts by carrying out a ‘credential stuffing’ attack on the websites operated by GS Retail—namely, the GSSHOP home shopping site and the GS25 convenience store site. Credential stuffing is a type of cyberattack in which attackers use previously acquired username and password combinations to attempt logins en masse; this typically causes a sharp increase in both login attempts and failure rates.
The hacker then accessed the member information modification pages, resulting in the exposure of personal data for 1,581,025 people from GSSHOP and 79,128 people from GS25. The leaked personal information included names, gender, date of birth, contact information, addresses, and email addresses.
The investigation found that GS Retail did not have measures in place to detect or block mass login attempts from the same IP address in a short period of time. Consequently, the company failed to recognize the abnormal surge in login attempts and failures, resulting in the continued exposure of personal data. GS Retail first became aware of the breach on the GS25 website on January 4 last year but did not learn that the same attack was occurring on the GSSHOP website until the following February.
Additionally, at the time of the incident, there was no dedicated department responsible for personal information protection, and the security operations were divided, reflecting deficiencies in both the structure and management of personal information protection. Furthermore, 1,599 additional affected users were identified during the investigation after the initial breach notification, but it was confirmed that notification of this data breach was delayed beyond 72 hours without legitimate reason.
The Personal Information Protection Commission ordered the company to implement security policies capable of identifying abnormal access as part of its measures to prevent similar incidents from recurring. The commission also issued a corrective order to strengthen governance, instructing GS Retail to assign dedicated personnel for personal information protection, ensure rapid incident response, and review and improve the authority and responsibility of the Chief Privacy Officer (CPO).
Enrise, which operates the dating app service ‘Wippy,’ was fined 118.44 million won and received an additional penalty of 3.6 million won. The hacker exploited a vulnerability in the identity verification process of the dating app service, attempted to log in using 16,803 phone numbers, and leaked the personal information of 736 accounts. Leaked information included nickname, gender, profile photo, date of birth, personality traits, education, occupation, height, and blood type.
The investigation found that Enrise both neglected to address and review vulnerabilities in the app's identity verification and failed to establish a policy to block excessive access attempts from the same IP address.
SK Telecom was issued a penalty of 3.6 million won and a corrective order, while Atoz received a warning. Atoz, which was contracted by SKT to operate an event-specific website for the 'Ifland' service, exposed the administrator page to search engines, resulting in the disclosure of personal information (names and mobile phone numbers) of 1,140 people.
Atoz failed to implement access controls, such as restricting administrator page access by IP address. In addition, SKT reported and notified of the personal data breach only after more than 24 hours had passed.
Hot Picks Today
Seoul Tops London and Tokyo for the First Time... Foreign Media: "Seoul Is Becoming the New Paris"
- "Where Is My Suitcase?" 26 Checked Bags Missing at Incheon Airport in 10 Days... Why?
- With Two Extra Days Added to Chuseok Holiday: "Pack Up, Let's Go Anywhere"... Domestic Travel Demand Surges
- "Is the YouTuber Telling the Truth?" 300,000 Views in One Day... The Real Story Behind Shin Ramyun's Flavor, According to Nongshim [Tastelovers X-File]
The commission emphasized, "When operating personal information processing systems, it is essential to implement access controls to restrict unauthorized access, and to conduct periodic vulnerability checks and corrective actions as basic principles." The commission added, "In the event of a personal data breach, both notification and reporting must be completed within 72 hours to enable information subjects to quickly recognize and respond to the incident."
© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.