GS Retail fined $9.3 million over data leak hitting 1.66 million customers
Synopsis
Key Takeaways
GS Retail, the South Korean conglomerate behind the GS25 convenience store chain and the GS SHOP home shopping platform, has been slapped with a 12.8 billion-won ($9.3 million) fine after a cyberattack exposed the personal data of 1.66 million customers, the country's privacy regulator announced on Monday, 31 August. The penalty, issued by the Personal Information Protection Commission (PIPC), is one of the largest data-privacy fines in South Korea's retail sector in recent years.
How the Breach Unfolded
According to the PIPC, an unidentified hacker exploited a technique known as credential stuffing — repeatedly injecting large volumes of pre-obtained user IDs and passwords to bypass login systems. The intrusion spanned GS SHOP and the GS25 platform between 2024 and 2025, giving the attacker prolonged, undetected access to member information modification pages.
The breach compromised the data of 1.58 million GS SHOP users and 79,128 GS25 customers. Exposed information reportedly included names, gender, dates of birth, contact numbers, home addresses, and email addresses — a combination that security experts consider high-risk for identity fraud and phishing campaigns.
What GS Retail Failed to Do
The PIPC found that GS Retail failed to detect clear warning signals: a sharp spike in login attempts and repeated failures originating from identical IP addresses within short timeframes. The regulator noted that the company also lacked a dedicated privacy protection office at the time of the incident — a structural gap that allowed the unauthorised access to persist undetected over a prolonged period.
Notably, credential-stuffing attacks are well-documented and widely anticipated in the retail sector. The failure to flag anomalous login patterns suggests the company's security monitoring was below the standard regulators now expect of large consumer platforms.
Regulatory Orders Issued
Beyond the fine, the PIPC has directed GS Retail to implement concrete preventive measures, including advanced security policies capable of identifying abnormal connection patterns in real time, and to appoint dedicated personnel responsible for privacy protection. The orders signal that regulators expect structural, not cosmetic, remediation.
Coupang Probe Hits a Wall
Separately, a fair trade investigation into the South Korean arm of US-listed Coupang has reportedly stalled after the e-commerce giant declined to cooperate with on-site inspections planned for last week through this week. According to industry sources, the Fair Trade Commission (FTC) had scheduled the inspections over allegations that Coupang violated the Act on Fair Transactions in Large Retail Business — specifically, suspicions that the company shifted discount costs onto its suppliers.
Coupang reportedly cited procedural grounds for its refusal, claiming it had not been notified of the inspections as required under the Framework Act on Administrative Investigations. The standoff adds a layer of regulatory uncertainty for the platform at a time when South Korean authorities are intensifying scrutiny of large retail operators.
Wider Implications for South Korea's Retail Sector
The twin developments — the GS Retail fine and the Coupang probe setback — underscore a broader regulatory tightening around data privacy and fair trade practices in South Korea's competitive retail landscape. As credential-stuffing attacks grow more sophisticated globally, regulators are increasingly holding platforms accountable not just for breaches, but for the absence of basic detection infrastructure. How GS Retail implements the mandated changes, and whether the FTC escalates action against Coupang, will be closely watched in the weeks ahead.