DistantNews
Support us
Weekly Security Briefing: Data Breach Hits 1.66 Million People, GS Retail Fined 12.8 Billion Won

Weekly Security Briefing: Data Breach Hits 1.66 Million People, GS Retail Fined 12.8 Billion Won

From Dong-A Ilbo · () Korean

Translated from Korean and summarized by DistantNews. Read the original for the full story.

At a glance

In-depth Official statement New plan
  • South Korea’s Personal Information Protection Commission fined GS Retail 12.836 billion won after hackers stole data from 1,581,025 GS SHOP users and 79,128 GS25 users.
  • The commission also penalized EnRise, SK Telecom and its contractor AtoZ over separate data-security and notification failures.
  • Gartner expects the global AI security market to grow 69% next year, while KISA is recruiting companies for an AI-assisted simulated penetration exercise.

A credential-stuffing attack exposed the personal information of more than 1.66 million people through GS Retail’s GS SHOP and GS25 websites, prompting South Korea’s privacy regulator to impose a 12.836 billion won fine.

The Personal Information Protection Commission said hackers used account credentials obtained elsewhere and repeatedly tried them on the two websites. The attacks affected GS SHOP from June 2024 to February 2025 and GS25 from late December 2024 to early January 2025. The attackers obtained names, genders, dates of birth, contact details, addresses and email addresses from 1,581,025 GS SHOP users and 79,128 GS25 users.

The regulator said GS Retail lacked basic measures to detect and block large numbers of login attempts from the same IP address. It also failed to respond quickly when login failures surged. Although the company became aware of the GS25 breach in January 2025, it did not identify the GS SHOP attack until February. The investigation also found no dedicated personal-information team, divided security operations and delayed breach notifications for some affected people.

The commission separately fined EnRise 118.44 million won and imposed a 3.6 million won penalty after a weakness in identity verification exposed 736 accounts. SK Telecom faced a 3.6 million won penalty and a corrective order after 1,140 people’s information leaked through AtoZ, a contractor operating an event page for its ifland metaverse service. AtoZ received a warning.

The briefing also highlighted the rapid expansion of AI security. Gartner forecasts that the market will reach about $4.783 billion next year, up 69% from this year, and $7.7 billion in 2028. The report points to prompt injection, data poisoning and supply-chain attacks as emerging risks. Meanwhile, the Ministry of Science and ICT and the Korea Internet and Security Agency are recruiting companies for a simulated cyber crisis exercise from Oct. 19 to 30. The exercise will pilot AI agents that analyze website structures and create tailored attack scenarios.

About this summary

Originally published by Dong-A Ilbo in Korean. Translated, summarized, and contextualized automatically by DistantNews, with a note on how the source frames the story. Not individually reviewed before publishing. How this works.