South Korea probes credit card company data breach affecting 3 million customers

South Korea’s data protection watchdog has launched an investigation into a cyberattack at Lotte Card, the country’s fifth-largest card issuer.

The Personal Information Protection Commission (PIPC) said on Monday it was working with financial regulators to determine the full scope of the breach, which exposed the personal data of about 3 million customers, and whether Lotte Card had violated the country’s data protection laws.

Lotte Card confirmed last week that hackers accessed a wide range of customer data in mid-August, including identification numbers, internal IDs and contact information. Sensitive financial details such as card numbers, expiration dates and verification codes belonging to thousands of customers were also compromised.

The Seoul-based lender, which serves around 9.6 million cardholders and processes roughly 10% of the nation’s daily credit card spending, has begun notifying at-risk customers to suspend or reissue cards. The company said no unauthorized transactions had been detected.

At a press conference on Thursday, Chief Executive Cho Jwa-jin made a public apology and pledged full compensation for damages. “We will use this as an opportunity to fundamentally reform not just security but the company’s entire management framework,” he said.

Local media reported that unnamed attackers exploited an unpatched vulnerability in a payments server that had gone unnoticed since 2017. Although a security fix was released that year, the company admitted one server, used for a little-used overseas payment service, was not updated.

Only about 56% of the 2,700 files believed to have been leaked were encrypted, according to reports. The breach went undetected until a routine server check nearly two weeks after the hackers gained access.

The incident has sparked debate over whether private equity firm MBK Partners, Lotte Card’s majority owner since 2019, neglected cybersecurity investment. Local media alleged the company’s security budget had fallen since the takeover.

MBK rejected the criticism, saying it had injected about 600 billion won ($430 million) into information technology at Lotte Card over the past six years, including security. “We view IT, security and governance as essential assets for maintaining corporate value and customer trust,” an MBK official said.

Still, the ruling People Power Party reportedly plans to summon MBK chairperson Kim Byung-ju to a parliamentary audit, arguing the firm should be held accountable for the scale of the breach.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

No previous article

No new articles

Daryna Antoniuk

Daryna Antoniuk

is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.

 

Total
0
Shares
Previous Post

Two New Supermicro BMC Bugs Allow Malicious Firmware to Evade Root of Trust Security

Next Post

State-Sponsored Hackers Exploiting Libraesva Email Security Gateway Vulnerability

Related Posts

China-Linked Tick Group Exploits Lanscope Zero-Day to Hijack Corporate Systems

The exploitation of a recently disclosed critical security flaw in Motex Lanscope Endpoint Manager has been attributed to a cyber espionage group known as Tick. The vulnerability, tracked as CVE-2025-61932 (CVSS score: 9.3), allows remote attackers to execute arbitrary commands with SYSTEM privileges on on-premise versions of the program. JPCERT/CC, in an alert issued this month, said that it
Read More

ThreatsDay Bulletin: 0-Days, LinkedIn Spies, Crypto Crimes, IoT Flaws and New Malware Waves

This week has been crazy in the world of hacking and online security. From Thailand to London to the US, we've seen arrests, spies at work, and big power moves online. Hackers are getting caught. Spies are getting better at their jobs. Even simple things like browser add-ons and smart home gadgets are being used to attack people. Every day, there's a new story that shows how quickly things are
Read More

2025 Cybersecurity Reality Check: Breaches Hidden, Attack Surfaces Growing, and AI Misperceptions Rising

Bitdefender’s 2025 Cybersecurity Assessment Report paints a sobering picture of today’s cyber defense landscape: mounting pressure to remain silent after breaches, a gap between leadership and frontline teams, and a growing urgency to shrink the enterprise attack surface. The annual research combines insights from over 1,200 IT and security professionals across six countries, along with an
Read More