GS Retail fined $9.3 million over data leak hitting 1.66 million customers

Share:
Audio Loading voice…
GS Retail fined $9.3 million over data leak hitting 1.66 million customers

Synopsis

South Korea's privacy regulator has fined GS Retail $9.3 million after a hacker used credential stuffing to silently drain personal data from 1.66 million customers across GS SHOP and GS25 — and the company failed to notice the warning signs for months. The fine is compounded by a separate regulatory standoff: Coupang has reportedly blocked FTC inspectors from entering its premises, turning two of South Korea's biggest retail names into simultaneous regulatory flashpoints.

Key Takeaways

GS Retail was fined 12.8 billion won ($9.3 million) by South Korea's Personal Information Protection Commission (PIPC) on 31 August .
A credential-stuffing attack between 2024 and 2025 exposed data of 1.58 million GS SHOP users and 79,128 GS25 customers.
Leaked data included names, gender, dates of birth, contact numbers, home addresses, and email addresses.
GS Retail lacked a dedicated privacy protection office and failed to detect abnormal login patterns from identical IP addresses.
The PIPC has ordered the company to implement advanced anomaly-detection security policies and appoint dedicated privacy personnel.
Separately, Coupang reportedly blocked Fair Trade Commission (FTC) on-site inspections over alleged supplier discount cost-shifting, citing procedural grounds.

GS Retail, the South Korean conglomerate behind the GS25 convenience store chain and the GS SHOP home shopping platform, has been slapped with a 12.8 billion-won ($9.3 million) fine after a cyberattack exposed the personal data of 1.66 million customers, the country's privacy regulator announced on Monday, 31 August. The penalty, issued by the Personal Information Protection Commission (PIPC), is one of the largest data-privacy fines in South Korea's retail sector in recent years.

How the Breach Unfolded

According to the PIPC, an unidentified hacker exploited a technique known as credential stuffing — repeatedly injecting large volumes of pre-obtained user IDs and passwords to bypass login systems. The intrusion spanned GS SHOP and the GS25 platform between 2024 and 2025, giving the attacker prolonged, undetected access to member information modification pages.

The breach compromised the data of 1.58 million GS SHOP users and 79,128 GS25 customers. Exposed information reportedly included names, gender, dates of birth, contact numbers, home addresses, and email addresses — a combination that security experts consider high-risk for identity fraud and phishing campaigns.

What GS Retail Failed to Do

The PIPC found that GS Retail failed to detect clear warning signals: a sharp spike in login attempts and repeated failures originating from identical IP addresses within short timeframes. The regulator noted that the company also lacked a dedicated privacy protection office at the time of the incident — a structural gap that allowed the unauthorised access to persist undetected over a prolonged period.

Notably, credential-stuffing attacks are well-documented and widely anticipated in the retail sector. The failure to flag anomalous login patterns suggests the company's security monitoring was below the standard regulators now expect of large consumer platforms.

Regulatory Orders Issued

Beyond the fine, the PIPC has directed GS Retail to implement concrete preventive measures, including advanced security policies capable of identifying abnormal connection patterns in real time, and to appoint dedicated personnel responsible for privacy protection. The orders signal that regulators expect structural, not cosmetic, remediation.

Coupang Probe Hits a Wall

Separately, a fair trade investigation into the South Korean arm of US-listed Coupang has reportedly stalled after the e-commerce giant declined to cooperate with on-site inspections planned for last week through this week. According to industry sources, the Fair Trade Commission (FTC) had scheduled the inspections over allegations that Coupang violated the Act on Fair Transactions in Large Retail Business — specifically, suspicions that the company shifted discount costs onto its suppliers.

Coupang reportedly cited procedural grounds for its refusal, claiming it had not been notified of the inspections as required under the Framework Act on Administrative Investigations. The standoff adds a layer of regulatory uncertainty for the platform at a time when South Korean authorities are intensifying scrutiny of large retail operators.

Wider Implications for South Korea's Retail Sector

The twin developments — the GS Retail fine and the Coupang probe setback — underscore a broader regulatory tightening around data privacy and fair trade practices in South Korea's competitive retail landscape. As credential-stuffing attacks grow more sophisticated globally, regulators are increasingly holding platforms accountable not just for breaches, but for the absence of basic detection infrastructure. How GS Retail implements the mandated changes, and whether the FTC escalates action against Coupang, will be closely watched in the weeks ahead.

Point of View

And regulators globally now treat failure to block it as negligence, not bad luck. The PIPC's structural orders matter more than the fine itself; whether GS Retail treats them as a compliance checkbox or a genuine operational overhaul will determine its exposure in the next incident. Meanwhile, Coupang's refusal to allow FTC inspections is a high-stakes procedural gamble — blocking regulators rarely ends well, and the optics of a platform accused of shifting costs onto suppliers stonewalling investigators will be difficult to manage.
NationPress
31 Aug 2026

Frequently Asked Questions

Why was GS Retail fined $9.3 million?
GS Retail was fined 12.8 billion won ($9.3 million) by South Korea's Personal Information Protection Commission (PIPC) after a hacker used credential stuffing to breach its GS SHOP and GS25 platforms between 2024 and 2025, exposing personal data of 1.66 million customers. The regulator found the company failed to detect clear warning signs and lacked a dedicated privacy protection office.
What customer data was exposed in the GS Retail breach?
The breach exposed names, gender, dates of birth, contact numbers, home addresses, and email addresses of 1.58 million GS SHOP users and 79,128 GS25 customers. The combination of data types is considered high-risk for identity fraud and targeted phishing.
What is credential stuffing and how was it used in this attack?
Credential stuffing involves an attacker using large volumes of previously obtained usernames and passwords to systematically attempt logins on other platforms, exploiting users who reuse credentials. In this case, the hacker used the technique to bypass GS SHOP and GS25 login systems and access member information modification pages over an extended period between 2024 and 2025.
What has the PIPC ordered GS Retail to do?
The PIPC has ordered GS Retail to implement advanced security policies capable of detecting abnormal connection patterns in real time and to appoint dedicated personnel for privacy protection. The orders go beyond the fine and require structural changes to the company's data security infrastructure.
What is the Coupang FTC investigation about?
South Korea's Fair Trade Commission (FTC) is investigating Coupang's local unit over allegations that it violated the Act on Fair Transactions in Large Retail Business by shifting the costs of discounts onto its suppliers. The probe has reportedly stalled after Coupang declined to cooperate with planned on-site inspections, citing procedural notification requirements under the Framework Act on Administrative Investigations.
Nation Press
The Trail

Connected Dots

Tracing the thread behind this story — newest first.

8 Dots
  1. Latest 3 weeks ago
  2. 2 months ago
  3. 7 months ago
  4. 7 months ago
  5. 8 months ago
  6. 9 months ago
  7. 9 months ago
  8. 10 months ago
Google Prefer NP
On Google