Personal Information of Over 1.66 Million Leaked
Formation of Information Security Countermeasures Committee
Comprehensive Overhaul of Internal Management Systems

GS Retail has issued an apology and pledged to strengthen its security system and prevent future incidents following a massive data breach that exposed the personal information of approximately 1.66 million people and resulted in a fine of about 12.8 billion won.


On August 31, GS Retail stated, "We would like to once again apologize for the concern caused by this recent data leak," and added, "Since the incident, we have completely overhauled our security and management systems, enhancing our level of information protection."

'128 Billion Won Fine' GS Retail Apologizes for Data Breach, Vows to Strengthen Security System View original image

According to GS Retail, an 'Information Security Countermeasures Committee' composed of key executives and external experts has been established to upgrade its security response system. The company has designated personal information protection as a company-wide management priority and is currently conducting employee training and reorganizing its internal management. GS Retail added, "We will continue to do our utmost to protect customer information and prevent any recurrence of data breaches."


Previously, on August 26, the Personal Information Protection Commission imposed a penalty of 12,836,000,000 won and an administrative fine of 3 million won on GS Retail for violating personal information protection regulations, in addition to issuing corrective and disclosure orders.


According to the commission’s investigation, hackers used a method called 'credential stuffing', in which ID and password combinations obtained from other sources are entered to gain unauthorized access, to steal the personal information of around 1.66 million members of GS Shop and GS25. Data such as names, birth dates, contact information, addresses, and email addresses were leaked.


The commission noted that GS Retail failed to timely detect and block abnormal signs such as repeated large-scale login attempts from the same IP address. Even after detecting a leak at GS25 in January of last year, the company only discovered similar attacks on GS Shop over a month later. The absence of a dedicated personal information team and the failure to notify certain victims within the legally required 72 hours were also pointed out.



The commission ordered GS Retail to implement a security policy to detect abnormal access by analyzing connection volume and patterns. It also directed the company to assign dedicated staff for personal information protection, clarify the roles and responsibilities of the Chief Privacy Officer (CPO), and improve the overall information security governance.


This content was produced with the assistance of AI translation services.

© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.

Today’s Briefing