Internet

GS Retail Fined 12.836 Billion Won for Personal Information Breach

Personal Information of 1.66 Million GS Holdings Shop and GS25 Members Leaked Inadequate Detection and Blocking of Massive Login Attempts Data Leak Continued for 40 Days Even After Initial Discovery Sanctions Imposed on Enrise’s ‘Wipi’ and SKTelecom’s ‘Ifland’

An Yu-ri
2026-08-31 11:00:05
[E-Daily Reporter An Yu-ri ] GS Retail(007070), which experienced a personal information leak, has been fined 12.836 billion won for violating the Personal Information Protection Act.
Song Kyung-hee, Chair of the Personal Information Protection Commission, taps the gavel during the 17th plenary session held at the Seoul Government Complex on Wednesday, the 26th. (Photo: Personal Information Protection Commission)

The Personal Information Protection Commission announced on the 26th that it held its 17th plenary session and imposed a total of 12.95444 billion won in administrative fines and 10.2 million won in administrative penalties on three companies: GS Retail, Enrise, and SKTelecom. The commission also voted to issue corrective orders, including measures to prevent recurrence, and to publicly announce the results of the disciplinary actions.

GS Retail was assessed an administrative fine of 12.836 billion won and an administrative penalty of 3 million won.

An unidentified Shinwon hacker attempted credential stuffing attacks on the GS Shop and GS25 websites from June 2024 through February of this year. Credential stuffing is an attack method that involves attempting to log in by brute-forcing previously obtained usernames and passwords.

After successfully logging in, the hacker accessed the member information modification page. During this process, the personal information of a total of 1,660,153 people—including 1,581,025 GS Holdings members and 79,128 GS25 members—was leaked. The leaked information included names, gender, dates of birth, contact information, addresses, and email addresses.

According to an investigation by the Personal Information Protection Commission, GS Retail had not implemented measures to detect and block large-scale login attempts originating from the same IP address, even when they occurred within a short period of time. The company also failed to recognize abnormal signs, such as a sudden surge in login attempts and failures, allowing the data breach to continue for an extended period.

GS Retail first became aware of the breach at GS25 on January 4 of this year. However, it was not until February that the company additionally discovered the same attack was underway at GS Shop. Consequently, the personal information leak continued from January 4—the date the initial incident was detected—through February 13. The investigation revealed that 327 of the IP addresses used in the GS25 attack were also used in the GS Shop attack.

It was also pointed out that there was no dedicated personal information protection team at the time of the incident. The investigation revealed that the composition and operation of the personal information protection organization were inadequate, including a fragmented security operations structure.

GS Retail identified an additional 1,599 affected individuals during the investigation following the initial breach notification; however, the investigation found that the company failed to notify them within the statutory 72-hour deadline without just cause.

The Personal Information Protection Commission ordered GS Retail to publish the details of the disciplinary action on its website. It also required the company to establish security policies that analyze service traffic volume and patterns to identify abnormal access. The Commission issued a corrective order to improve the overall governance system, including the assignment of dedicated personnel for personal information protection and the clarification of the authority and responsibilities of the Chief Privacy Officer (CPO).

GS Retail stated, “We once again apologize for the concern caused by this personal information leak,” adding, “Since the incident, we have conducted a comprehensive review of our security systems and management framework and have strengthened our information security measures.” GS Retail further emphasized, “We have established an ‘Information Security Measures Committee’ comprising key executives and external experts to enhance our security response system. With a customer-first approach, we have made company-wide personal information protection a key management priority and are continuing our efforts to prevent recurrence through employee training and the overhaul of internal management systems.”

Dating App ‘WIPPY’ Operator Fined 110 Million Won… SK Fined 3.6 Million Won

RIIZE, the operator of the dating app WIPPY, was hit with a fine of 118.44 million won and an administrative penalty of 3.6 million won. In March 2023, a hacker exploited a vulnerability in the identity verification system to attempt logins using 16,803 mobile phone numbers. As a result, personal information—including usernames, gender, profile photos, dates of birth, educational background, and occupations—was leaked from 736 of these accounts.

The investigation found that RIIZE neglected to inspect and address the identity verification vulnerability and failed to block excessive access attempts originating from the same IP address.

SKTelecom was fined 3.6 million won and issued a corrective order regarding “Ifland,” a metaverse platform it previously operated. A-Toz, which had been commissioned by SKTelecom to operate Ifland events, received a warning.

The names and mobile phone numbers of 1,140 people were leaked after the administrator page of an event website created by AtoZ became visible to search engines. AtoZ failed to implement access control measures, such as IP restrictions, for the administrator page. SKTelecom notified authorities and reported the personal information leak more than 24 hours after the incident—exceeding the legally mandated deadline.

The Personal Information Protection Commission stated, “When operating a personal information processing system, basic principles must be followed, such as restricting unauthorized access and periodically checking for vulnerabilities,” adding, “In the event of a data breach, it must be reported and notified within 72 hours so that data subjects can respond promptly.”

Economy

Corporation

IT·Science

Economy

“Learning About Money” Through Buying and Selling Coffee… DB Insurance Supports Financial Education for Students with Disabilities

DB INSURANCE(005830)is supporting hands-on financial education that allows students with emotional disorders and autism spectrum disorders to learn about the concept of money by buying and selling ite…
2026-08-31 09:13:18

Corporation

CMG Pharmaceutical Co., Ltd. Teams Up with Cha Medical Research Institute to Accelerate Commercialization of Three New Materials… Targeting ‘Longevity and Pet Care’

CMG Pharmaceutical Co., Ltd.(058820)is accelerating the commercialization of three next-generation functional materials secured through open innovation with the Cha Medical Research Institute (CHARI),…
2026-08-31 10:15:03

IT·Science

GS Retail Fined 12.836 Billion Won for Personal Information Breach

GS Retail(007070), which experienced a personal information leak, has been fined 12.836 billion won for violating the Personal Information Protection Act. Song Kyung-hee, Chair of the Personal Info…
2026-08-31 11:00:05