김성훈
| 2026-08-31 11:22:01
SEOUL, Aug. 31 (Yonhap) -- GS Retail Co., a retail giant that operates GS25 convenience stores, has been issued a 12.8 billion-won (US$9.3 million) fine over a personal data leak that affected 1.66 million customers, the privacy watchdog said Monday.
According to the Personal Information Protection Commission (PIPC), an unidentified hacker infiltrated the company's home shopping platform GS SHOP and its convenience store chain between 2024 and 2025 by repeatedly injecting a large number of pre-secured user IDs and passwords to successfully bypass login systems.
Through the member information modification pages, the hacker compromised the personal data of 1.58 million GS SHOP users and 79,128 GS25 customers. The leaked information included their names, gender, dates of birth, contact numbers, home addresses and email addresses.
The privacy watchdog said GS Retail failed to notice abnormal signs, such as a sharp spike in login attempts and failures from identical IP addresses within a short time frame, which allowed the unauthorized access to persist undetected over a prolonged period. The company also lacked a dedicated office for privacy protection at the time of the incident.
The PIPC said it has ordered GS Retail to formulate concrete preventive measures, such as advanced security policies capable of identifying abnormal connections, and to appoint dedicated personnel for privacy protection.
(END)
[ⓒ K-VIBE. 무단전재-재배포 금지]