GS Retail, the company behind GS25 convenience stores and the GS SHOP home shopping platform, has been fined 12.8 billion won, or about $9.3 million, after a personal data breach affected 1.66 million customers.

South Korea’s Personal Information Protection Commission (PIPC) said an unidentified hacker gained unauthorised access to GS Retail’s systems between 2024 and 2025. The attacker reportedly used large numbers of previously obtained usernames and passwords in repeated login attempts to bypass the company’s authentication systems.

The attack affected both GS SHOP and GS25 customers. According to the PIPC, personal information belonging to around 1.58 million GS SHOP users and 79,128 GS25 customers was accessed through member information modification pages.

The exposed information included customers’ names, gender, dates of birth, phone numbers, home addresses and email addresses, according to Yonhap News Agency.

The privacy watchdog said GS Retail failed to detect several warning signs that could have indicated the attack. These included a significant increase in login attempts and failed logins coming from the same IP addresses within short periods.

Because the unusual activity was not detected, the unauthorised access continued for an extended period. The PIPC also said GS Retail did not have a dedicated office responsible for privacy protection when the incident occurred.

As part of its response, the PIPC ordered GS Retail to introduce stronger security measures capable of detecting abnormal connections and to appoint dedicated personnel responsible for protecting customer information.

READ
Critical GiveWP WordPress Flaw Lets Hackers Execute Commands Remotely

Separately, South Korea’s Fair Trade Commission is investigating the local unit of US-listed e-commerce company Coupang over allegations involving its dealings with suppliers. The investigation reportedly suffered a setback after Coupang refused recent attempts by investigators to conduct on-site inspections.

The FTC had planned inspections over allegations that Coupang shifted the cost of discounts onto suppliers, potentially violating South Korea’s Act on Fair Transactions in Large Retail Business.


Buy ExpressVPN with PayPal or Credit Card

According to industry sources, Coupang declined to cooperate, arguing that investigators had not provided the required notification under the Framework Act on Administrative Investigations.

Advertisement