Lotte Card fined 5 billion won, suspended for 1.5 months over data leak
Translated from Korean, summarized and contextualized by DistantNews.
At a glance
- Lotte Card faces 1.5 months of business suspension and a 5 billion won fine for a massive customer data leak.
- The financial regulator cited security violations, including unpatched systems and unencrypted personal information, as reasons for the penalty.
- This marks the first time a financial authority has suspended business operations due to a hacking-related data breach.
South Korean financial authorities have imposed a significant penalty on Lotte Card following a large-scale customer data leak. The company will face a 1.5-month business suspension and a 5 billion won (approximately $3.6 million USD) fine. This decision comes after an investigation revealed multiple security vulnerabilities during the operation of its online payment system.
According to the Financial Services Commission, Lotte Card failed to implement security patches on its information processing systems, did not encrypt resident registration numbers and passwords, and lacked proper antivirus software. These oversights led to the exposure of credit information for 2.97 million customers in August of the previous year.
The Financial Supervisory Service had initially recommended a 4.5-month suspension. However, after considering Lotte Card's input and further deliberation, the commission reduced the suspension period to 1.5 months. This penalty is particularly noteworthy as it is the first instance of a business suspension being issued by financial authorities in response to a hacking-induced data breach.
Originally published by Dong-A Ilbo in Korean. Translated, summarized, and contextualized by our editorial team with added local perspective. Read our editorial standards.