
South Korean authorities have temporarily restricted some of Lotte Card’s business operations after a large-scale 2025 data breach compromised the data of millions of customers.
In September 2025, Lotte card said it identified a security breach where threat actors infiltrated its internal network and stole confidential data. The company immediately launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident.
The investigation confirmed that some customers’ personal credit information had been compromised. The leaked data included connecting information, resident registration numbers, card-related payment information and virtual payment codes. Lotte Card said it immediately removed the malicious code, blocked the suspected hackers’ IP address and addressed the security vulnerabilities in the affected system. The company added that it has strengthened its abnormal transaction monitoring system to the highest level to help prevent further customer harm.
The Seoul-based credit card company later said that the personal and financial information of approximately 2.97 million customers had been compromised, including credit card numbers, expiration dates and CVC details belonging to around 280,000 customers.
Recently, South Korea’s Financial Services Commission (FSC) ordered MBK Partners, the owner of Lotte Card, to partially suspend the card issuer’s business operations from August 1 to September 15 and imposed a $3.5 million fine.
According to the FSC, Lotte Card is barred from conducting new customer-related card business during the suspension period. However, existing customers will continue to have access to all card-related services, including applications and usage.
In a statement shared with the media, the FSC said, “We will move ahead with regulatory reforms designed to fundamentally strengthen the cybersecurity management systems of financial institutions to prevent similar data breaches from recurring.”
The regulator further supported revisions to the applicable legislation, which would introduce fines of up to 3% of a financial institution’s annual revenue for severe cyber security incidents.
Lotte Card has issued another apology to its customers, saying it would take all necessary measures to prevent similar incidents in the future and rebuild trust as a reliable financial institution.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543