
South Korea’s privacy regulator has fined GS Retail 12.836 billion won, about $9.2 million, along with an additional administrative penalty of 10.2 million won, after hackers stole personal data belonging to roughly 1.66 million customers.
The Personal Information Protection Commission announced the penalties on the 31st, saying it approved the measures against GS Retail for violations of personal data protection rules during a plenary meeting held on the 26th. The commission also directed the company to develop steps to prevent a repeat incident and to publish details of the case on its website.
According to the commission’s investigation, hackers targeted member information pages on the GS Shop and GS25 websites between June 2024 and February 2025 using credential stuffing, a technique that relies on previously stolen login credentials to force entry into accounts. The intrusion exposed names, genders, birth dates, phone numbers, home addresses and email addresses belonging to 1,660,153 people in total, including 1,581,025 GS Shop customers and 79,128 GS25 customers.
Investigators determined that GS Retail had no mechanism to detect or block high volumes of login attempts originating from a single IP address within a short span of time, and that the company missed clear warning signs even as failed login attempts climbed. The commission also found that GS Retail discovered the breach on the GS25 site first, in January 2025, but did not follow up adequately, and did not confirm that GS Shop had also been compromised until the following month, roughly two months after the intrusion began.
As part of its corrective order, the commission instructed GS Retail to implement a security policy that can identify and block abnormal access by analyzing patterns and volumes of service traffic. It also directed the company to designate staff specifically responsible for personal data protection and to strengthen its broader governance structure, including clarifying the authority and duties of its chief privacy officer.
GS Retail operates GS25 convenience stores and the GS Shop home shopping platform. The commission said an unidentified hacker breached both platforms between 2024 and 2025 by repeatedly submitting large batches of previously obtained usernames and passwords to bypass login systems, ultimately accessing member information modification pages to extract customer data.
The commission noted that GS Retail did not have a dedicated privacy protection office in place at the time of the breach, and it has since ordered the company to establish advanced security policies capable of flagging abnormal connections and to appoint personnel dedicated to privacy protection.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543