← Blog

Lotte Card Breach: 3M Customers Hit in Korea Hack

Share on X

Lotte Card, one of South Korea’s largest credit-card issuers, confirmed that attackers broke into systems in mid-August 2025 and walked away with personal data on about 3 million customers. The company later faced a Personal Information Protection Commission administrative fine reported at ₩9.62 billion (~US$6.4 million).

The Record and Korean outlets reported the haul included identification numbers, internal IDs, and contact details. For thousands of customers, card numbers, expiry dates, and verification codes were also taken. Lotte Card said it had not seen unauthorized transactions at the time of its early apologies, but it urged card suspension and reissue for at-risk accounts.

What happened

According to local reporting summarized by The Record, attackers exploited an unpatched vulnerability on a little-used overseas payments server. A security fix had been available since 2017; one server never received it. The intrusion went unnoticed for nearly two weeks until a routine check.

CEO Cho Jwa-jin apologized publicly and pledged compensation and broader security reforms. Ownership questions briefly focused on private-equity majority owner MBK Partners, which denied cutting cybersecurity investment.

What data was exposed

  • Customer identification and internal account identifiers
  • Contact information
  • For a smaller subset: payment-card numbers, expiry dates, and CVV-style verification codes

Who is at risk

Anyone who held a Lotte Card account during the intrusion window—especially customers later told to reissue cards. Korean cardholders should treat SMS and voice phishing that name Lotte Card as high risk.

Action items

  1. If Lotte Card contacted you, follow only official reissue instructions—do not click links in unexpected texts.
  2. Monitor card statements and enable transaction alerts.
  3. Place a fraud alert with Korean credit bureaus if you are in scope.
  4. Assume contact details may be used for targeted phishing for months.

Canonical record

Full catalog entry: https://breachhistory.com/lotte-card/lotte-card-hack2025. Primary sources include The Record and Lotte Card’s customer notice.