bytevyte
bytevyte
Language
quick-beats

GS Retail Data Breach Draws $9.3M Fine After 1.66 Million Customer Records Leak

GS Retail data breach

South Korea's data protection watchdog has fined GS Retail 12.8 billion won, about $9.3 million, after a data breach exposed personal information of roughly 1.66 million customers. The penalty, announced Monday by the Personal Information Protection Commission (PIPC), stems from the GS Retail data breach, which involved credential-stuffing attacks on the GS Shop home shopping platform and the GS25 convenience store chain.

The attackers submitted stolen username and password pairs repeatedly until some logins worked. GS Shop systems were targeted from June 21, 2024 to February 13, 2025, while GS25 came under attack between December 26, 2024 and January 4, 2025. Roughly 1.58 million GS Shop accounts and more than 79,000 GS25 accounts were compromised. Names, birth dates, genders, phone numbers, physical addresses, and email addresses were among the leaked fields.

Penalty and Corrective Orders

The PIPC found that GS Retail lacked controls sufficient to block repeated login attempts from individual IP addresses. The company also missed the legally required 72-hour deadline for notifying some affected users. Beyond the main fine, the commission imposed an administrative penalty of 10.2 million won and corrective orders; the measures were approved at a plenary meeting on August 26 and made public on August 31.

GS Retail, which operates the GS25 convenience store chain and the GS Shop home shopping platform, must now form a dedicated privacy team, clarify the responsibilities of its chief privacy officer, and prepare safeguards against a repeat incident. For affected customers, contact details and birth dates are already in an attacker's hands. Unsolicited messages that reference personal data should be treated as possible phishing attempts, and passwords used on either platform should be changed if reused elsewhere.

Why This Matters

Credential stuffing exploits reused passwords rather than software flaws and remains one of the most common ways consumer accounts are compromised. With 1.66 million people affected and a notification deadline missed, the penalty shows that South Korean regulators expect retailers to answer for both the breach and its aftermath.

AI-generated image.

✔Human Verified


Researched and cross-referenced against primary sources by the Bytevyte editorial team. This article was generated with the assistance of artificial intelligence and reviewed by the Bytevyte editorial team.