Lotte Card CEO Cho Jwa-jin said the hacking incident happened because the IT system had not been reinforced eight years ago.
Cho said at a Science. ICT. Broadcasting. and Communications Committee hearing on the morning of the 24th, "A web logic inside the online payment server had not been upgraded since 2017, creating a vulnerability," and "All 48 web logic programs should have been reinforced, but we missed one of them." Web logic refers to a web application server developed by global IT corporations Oracle. It improves system efficiency and security.
Cho said, "We have now reinforced the system through a full audit."
Earlier, on the afternoon of the 14th of last month, Lotte Card suffered a hack that leaked internal files. The scale of the leak was about 200GB (gigabytes), and 2.97 million people were affected. The hack exposed some members' resident registration numbers, CVC (three-digit number on the back of the card), and internal identification numbers.