2024–2025 GS Retail — credential-stuffing on GS Shop/GS25; 1.66M users (PIPC ₩12.8B fine Aug 2026)
Data compromised
Names, gender, dates of birth, phone numbers, addresses, and email addresses from compromised member accounts — 1.58M GS Shop users and 79,128 GS25 users per regulator
Technical writeup
Verified regulator enforcement — August 31, 2026. South Korea’s Personal Information Protection Commission fined GS Retail ₩12.84 billion (~$9.3M) plus a ₩3 million penalty after credential-stuffing attacks compromised GS Shop and GS25 member accounts. An unidentified attacker logged into accounts using stolen username/password pairs: GS Shop from June 21, 2024 through February 13, 2025 (1.58 million users) and GS25 from December 26, 2024 through January 4, 2025 (79,128 users). Exposed fields included name, gender, date of birth, phone, address, and email. PIPC found GS Retail lacked controls to block high-volume login attempts from the same IPs, failed to heed warning spikes, had no dedicated privacy team at the time, and delayed user notification — including 1,599 additional victims identified after initial notices who were not told within 72 hours. GS Retail learned of the GS25 breach January 4, 2025 but took more than a month to recognize parallel GS Shop attacks despite 327 overlapping attacker IPs. recordsAffected 1660000 from PIPC attestation; companyConfirmed true via regulator action.
Root cause
Credential-stuffing attacks on GS Shop (Jun 21, 2024–Feb 13, 2025) and GS25 (Dec 26, 2024–Jan 4, 2025); inadequate IP login-throttling and delayed detection/notification per PIPC