GS Retail fined $9.3M following customer data breach
South Korea’s privacy regulator imposed a 12.8 billion-won fine after a cyberattack exposed the personal information of more than 1.66 million GS SHOP and GS25 customers.
GS Retail has been fined 12.8 billion won (approximately $9.3 million) by South Korea’s Personal Information Protection Commission (PIPC) following a data breach that affected more than 1.66 million customers across its GS SHOP and GS25 businesses.
According to the regulator, an unidentified hacker gained access to customer accounts between 2024 and 2025 by using previously obtained user IDs and passwords to repeatedly attempt logins until successfully bypassing the company’s authentication systems.
The incident compromised the personal information of around 1.58 million GS SHOP users and 79,128 GS25 customers. Exposed data included names, gender, dates of birth, phone numbers, home addresses and email addresses, as reported by The Korea Times.
The PIPC said GS Retail failed to detect warning signs of suspicious activity, including a sudden increase in login attempts and authentication failures originating from the same IP addresses within a short period. As a result, the unauthorized access continued for an extended time without being identified.
The regulator also found that the company did not have a dedicated privacy protection office in place at the time of the breach.
In response, the PIPC ordered GS Retail to implement stronger safeguards, including security measures capable of identifying abnormal connections and access patterns. The company was also instructed to appoint dedicated personnel responsible for privacy protection.