| Title | The PIPC Sanctions GS Retail and Three Other Businesses over Data Breaches | ||
|---|---|---|---|
| Department | Date | 2026.09.03 | |
| Attachment | press release The PIPC Sanctions GS Retail and Three Other Businesses for Data Breaches.pdf | ||
| Page URL | https://pipc.go.kr/eng/user/ltn/new/noticeDetail.do?bbsId=BBSMSTR_000000000001&nttId=3172 | ||
| Contents |
The PIPC Sanctions GS Retail and Three Other Businesses over Data Breaches - The PIPC issued corrective orders on GS Retail to establish concrete plans to prevent recurring data breaches, review and improve its dedicated privacy organization and operations - The PIPC also imposed fines and issued corrective orders on three other businesses for their data breaches
August 31, 2026 (This is an unofficial translation of a press release, originally prepared in Korean.)
The Personal Information Protection Commission (PIPC) held its 17th plenary meeting of 2026 and resolved to sanction GS Retail Co., Ltd (GS Retail) and three other businesses for their failures to comply with the Personal Information Protection Act (PIPA) on August 26, 2026. The PIPC imposed administrative fines totaling approximately KRW 13 billion on the aforementioned businesses and issued corrective and publication orders. The sanctioned businesses are as follows:
● GS Retail: Service operation of GS25, GS SHOP, GS THE FRESH ● NRISE, Inc. (NRISE): A dating application (WIPPY) service provider ● SK Telecomm Co., Ltd. (SKT): A metaverse service provider ● ATOZ Co., Ltd (ATOZ): An online marketing service provider
The aforementioned businesses failed to put adequate safeguards in place, such as access controls to their personal information protection systems. The following explains the administrative sanctions imposed on them.
1. GS Retail: An administrative monetary penalty of KRW 12.836 billion and an administrative fine of KRW 3 million, and corrective and publication orders
Unknown hackers carried out credential-stuffing attacks against the websites of GS SHOP between June 21, 2024, and February 13, 2025, and GS 25 between December 26, 2024, to January 4, 2025. The hackers repeatedly submitted login requests using stolen credentials, gaining unauthorized access to the My Page of the respective websites. As a result, the personal information of 1,581,026 individuals via GS SHOP and 79,128 via GS25 was leaked.
Credential stuffing is a cyberattack in which attackers collect stolen credentials (ID, password, etc.) and use them to gain unauthorized access to other systems by submitting login requests. Attackers submit numerous login requests using previously discovered credential pairs. Such attacks lead to a significant increase in login attempts and failures.
GS Retail failed to implement measures to detect or block repeated login attempts originating from the same IP address within a short period. The company also failed to detect anomalies, including a surge in login attempts and failures, resulting in continued data leaks for a significant period.
Meanwhile, GS Retail became aware of a data breach involving the GS 25 website on January 4, 2025, but failed to take adequate follow-up measures. This failure led to a subsequent data breach involving the GS SHOP website in February 2025. Some of the IP addresses used to attack GS 25 were also used in attacks against GS SHOP. This negligence in taking measures to address the breaches prolonged them after GS Retail became aware of the initial incident.
It was also discovered that GS Retail failed to adequately establish and operate a dedicated privacy organization. In particular, the company lacked a structured privacy team, while its security operations were fragmented rather than integrated. After initially reporting the data breach, GS Retail failed to report an additional leak of 1,599 individuals to the competent authority within 72 hours, without justifiable grounds.
In this regard, the PIPC resolved to impose an administrative fine of KRW 12.836 billion and a KRW 3 million fine on GS Retail, and ordered the company to publicly disclose the sanctions results on its website.
The PIPC also issued the following corrective orders:
● Establishing and implementing concrete plans to prevent recurring data breaches, including analyzing service traffic and access patterns to detect anomalies ● Reviewing and improving its privacy and data protection governance across the board, including staffing its privacy organization and clarifying the roles and responsibilities of a Chief Privacy Officer (CPO), in order to ensure prompt and effective responses to data breaches
2. NRISE: An administrative monetary penalty of KRW 118.44 million and an administrative fine of KRW 3.6 million
Unknown hackers exploited vulnerabilities in the self-authentication process of a dating application service operated by NRISE to make login attempts using 16,803 mobile phone numbers between March 23 and March 27, 2023. The attacks resulted in a data breach involving 736 accounts. The leaked personal information included:
● Nickname ● Profile photo ● Birthdate ● Personality information ● Educational background ● Occupation ● Height ● Blood type
The PIPC’s investigation found that the company failed to adequately review and take necessary measures to address vulnerabilities in its self-authentication procedures. The Company also failed to put appropriate safeguards in place, including measures to block or respond to a surge in traffic originating from the same IP addresses.
3. SK Telecom and ATOZ
ATOZ was entrusted by SKT to build and operate a website to host events for ifland, SKT’s metaverse service. However, the administrator page of the website was accessible through search engines between November 21, 2022, and January 3, 2023, resulting in a data leak involving the personal information of 1,140 individuals, including their names and mobile phone numbers.
The PIPC’s investigation showed that ATOZ failed to implement access control measures, including restrictions on access to the administrator page based on IP addresses. The investigation also found that SKT failed to notify affected data subjects and report the data breach to the competent authority within 24 hours. *This data breach is subject to the provisions of the PIPA prior to amendments that took effect on August 5, 2020. Under the previous legal framework, information and communications service providers were required to notify affected data subjects and report data breaches to the competent authority within 24 hours of becoming aware of an incident.
Accordingly, the PIPC imposed an administrative fine of KRW 3.6 million and issued a corrective order on SKT and issued a warning to ATOZ.
Taking this opportunity, the PIPC reemphasized that businesses and other data controllers should comply with basic principles in terms of operating personal data processing systems, including:
● Implementing access controls, including unauthorized access restrictions ● Monitoring vulnerabilities on a regular basis and taking necessary measures to address vulnerabilities identified
At the same time, the PIPC urged data controllers to notify affected data subjects and report data breaches within 72 hours, without undue delay, to enable data subjects to become aware of the incident and respond to it promptly.
* A PDF file, formatted for better readability, is attached.
|
||