The Personal Information Protection Commission imposed a 12.8 billion won penalty surcharge on GS Retail after a massive leak of customer personal information. Although red flags such as a surge in failed logins appeared, the company failed to detect and block them, and even after confirming the leak in one service, the same attack continued in another service, leading to additional leaks for about 40 days, it was found.
The Personal Information Protection Commission said on the 31st that it held its 17th plenary meeting on the 26th and resolved to impose a total penalty surcharge of 12.836 billion won and fines of 3 million won on GS Retail for violating obligations on personal information protection measures. Along with corrective orders such as preparing measures to prevent recurrence, it also ordered the company to disclose the disposition on its website.
The investigation found that an unidentified hacker carried out a "credential stuffing" attack by indiscriminately attempting to log in to the GS Shop and GS25 websites operated by GS Retail using IDs and passwords obtained in advance. The attacks continued from June 21, 2024, to Feb. 13, 2025, on GS Shop and from Dec. 26, 2024, to Jan. 4, 2025, on GS25. After successfully logging in, the hacker accessed pages such as the member information edit page and stole the personal information of 1,581,025 GS Shop users and 79,128 GS25 users.
When a credential stuffing attack occurs, the number of login attempts and the failure rate typically spike from the same internet protocol (IP) address. However, GS Retail was found not to have prepared measures to detect and block such abnormal access.
Problems also emerged in the incident response. GS Retail first identified on Jan. 4, 2025, that personal information had been leaked from the GS25 website, but it did not confirm until Feb. 13 of the same year that the same attack was underway on GS Shop. Even after recognizing the first leak, personal information continued to be leaked for about 40 days on the other service. In particular, 327 of the IP addresses used to attack GS25 were confirmed to have been used identically in the GS Shop attack.
The Personal Information Protection Commission determined that at the time of the incident, GS Retail lacked a dedicated personal information protection unit and had a bifurcated security operation, indicating deficiencies in its personal information protection organization and operating system. It also found that even though 1,599 additional affected persons were identified during the investigation after the initial leak notification, the company informed them of the leak only after 72 hours had passed without justifiable reason.
Accordingly, it ordered GS Retail to implement measures to prevent recurrence, such as applying security policies that analyze service traffic volume and access patterns to identify abnormal access. It also ordered comprehensive improvements to personal information protection governance, including assigning dedicated personnel for personal information protection and clarifying the authority and responsibilities of the chief privacy officer (CPO).
Meanwhile, the Personal Information Protection Commission decided the same day to impose a 118.44 million won penalty surcharge and fines of 3.6 million won on dating app operator NLIZ. The investigation found that on the dating app operated by NLIZ, a hacker exploited a vulnerability in the identity verification process and, from March 23 to 27, 2023, attempted logins with 16,803 mobile phone numbers, leaking personal information such as the dates of birth, education, and occupations of 736 accounts. NLIZ was found to have neglected inspection and remediation of the app's identity verification vulnerability and failed to configure blocks even when excessive access occurred from the same IP address.
In addition, SK Telecom received fines of 3.6 million won and a corrective order, while Atoz received a warning. While operating SK Telecom's "ifland" event website from Nov. 21, 2022, to Jan. 3, 2023, Atoz failed to properly control access to the administrator page, resulting in the leak of the names and mobile phone numbers of 1,140 people. The Personal Information Protection Commission said SK Telecom recognized the leak but notified and reported it past the statutory 24-hour deadline.