The South Korean authority fines GS Retail 12.83 billion won for a massive personal data breach

The Personal Information Protection Commission (PIPC), the South Korean authority, sanctioned four companies for security flaws leading to data breaches, emphasizing the imperative to implement robust technical measures against credential stuffing attacks and to ensure effective internal governance for rapid incident response.

Facts and context

The South Korean data protection authority today issued a sanction decision against GS Retail (including a fine of 12,836,000,000 KRW, approximately €8,600,000) for failures related to data security and breach notification. Three other companies, Nrise, SK Telecom, and Atoz, were also sanctioned in this same wave of decisions for similar reasons.

The case originates from several distinct data breaches at these four operators, resulting from insufficient security measures, notably flaws in access control to their personal information processing systems.

Grounds for the decision

Regarding GS Retail, which operates convenience store services GS25, home shopping GS SHOP, and supermarkets GS THE FRESH, the authority found several breaches:

  • Obligation to ensure the security of processing: An unidentified attacker conducted credential stuffing attacks against GS SHOP sites (from June 21, 2024, to February 13, 2025) and GS25 (from December 26, 2024, to January 4, 2025), successfully logging in and exfiltrating data of 1,581,025 GS SHOP customers and 79,128 GS25 customers (name, gender, date of birth, contact, address, email). The authority concluded a violation of the security obligation, as the company had implemented no technical measures to detect and block massive and abnormal login attempts from the same IP addresses over a short period. This lack of monitoring allowed the attack to continue for a long duration undetected.
  • Obligation to ensure adequate data protection governance: The investigation revealed the company lacked a dedicated personal data protection team and that its security structure was dual-organized, hindering incident detection and response. The authority considered this internal organizational failure directly contributed to the slow reaction, with the company only becoming aware of the GS SHOP site attack in February 2025, more than a month after detecting the initial attack on the GS25 site, despite some IP addresses being common to both attacks.
  • Obligation to notify data breaches: During the investigation, an additional 1,599 data subjects were identified. The authority found the company notified them of the breach beyond the legal 72-hour deadline without justifying the delay.

Regarding the three other companies:

  • Nrise, operating a dating app, suffered a data breach affecting 736 accounts. The attacker exploited a vulnerability in the app's identity verification process. The authority reproached the company for not fixing this known flaw and for not implementing a policy to block excessive connections from the same IP address.
  • Atoz, acting as a subcontractor for SK Telecom for an event for the "ifland" service, exposed data of 1,140 people (name, phone number). The event website's admin page, which had no access control measures such as IP address restrictions, was indexed by search engines.
  • SK Telecom, as the data controller, was sanctioned for notifying the aforementioned data breach beyond the 24-hour deadline then applicable under the former Personal Information Protection Act.

Authority's decision

Consequently, the authority imposed a fine of 12,836,000,000 KRW (approximately €8,600,000) and a penalty of 3,000,000 KRW (approximately €2,010) on GS Retail. The three other companies were fined and penalized for a total amount of 118,440,000 KRW (approximately €79,000) and 7,200,000 KRW (approximately €4,800).

Furthermore, the authority ordered GS Retail to take specific corrective measures, including: developing and implementing prevention measures to identify abnormal access by analyzing connection volumes and patterns; establishing a dedicated data protection team to ensure rapid incident response; clarifying the powers and responsibilities of its data protection officer; and publishing the decision on its website.

Lessons learned

This decision confirms / specifies / reminds that:

  • Protection against credential stuffing attacks is not solely the users' responsibility in choosing their passwords but requires data controllers to implement proactive technical measures (rate limiting, behavioral analysis, IP blocking) to detect and counter such large-scale automated access attempts.
  • A clear and effective internal governance structure for data protection, with dedicated staff and a data protection officer with well-defined responsibilities, is essential to ensure rapid and coordinated detection and management of security incidents.
  • The data controller remains fully responsible for its processors' security failures and must ensure through appropriate technical and organizational measures that they comply with their obligations, notably regarding access control to information systems.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire