Lotte Card Fined ₩5B and Handed 1.5-Month Business Suspension Over Massive Data Breach
KO YONG-CHUL Reporter
korocamia@naver.com | 2026-08-01 07:16:00
SEOUL — South Korea’s top financial regulator, the Financial Services Commission (FSC), officially decided on Friday to impose a 1.5-month partial business suspension and a 5 billion KRW ($3.7 million USD) administrative fine on Lotte Card Co., following a massive cyberattack that exposed the sensitive credit information of nearly 3 million customers.
The regulatory action stems from a severe security breach in September 2025, when external hackers compromised Lotte Card's online payment system, exfiltrating personal credit details belonging to 2.97 million cardholders. The final 1.5-month suspension period finalized by the FSC represents a reduction from the initial three-month suspension previously signaled in the Financial Supervisory Service's (FSS) advance notice.
Explaining the rationale behind the mitigation, an official FSC spokesperson stated that the committee carefully weighed several factors: "The 1.5-month suspension period was determined by evaluating fairness relative to past regulatory cases, the extensive post-incident remediation efforts undertaken by Lotte Card, and the broader implications for financial markets and consumer convenience."
Partial Operational Freeze & Customer Impact
The business suspension takes effect from August 1 through September 15, 2026. Under the terms of the order, Lotte Card is strictly prohibited from recruiting new members or engaging in new card issuance operations. However, to prevent unnecessary disruption to the day-to-day economy, existing cardholders will experience no operational limits—they can continue using active cards, making standard payments, and accessing customer services normally.
A forensic audit conducted by financial authorities uncovered widespread statutory non-compliance under the Credit Financial Business Act and the Use and Protection of Credit Information Act. Regulators reported that Lotte Card failed to perform essential maintenance and patching on its online payment processing systems, omitted mandatory anti-virus software installation, and failed to encrypt sensitive identification data (such as Resident Registration Numbers) and user passwords.
Legislative Reforms Ahead
In light of the incident, financial authorities announced plans to pursue comprehensive legislative reforms to prevent future occurrences. The government intends to actively support amendments to the Electronic Financial Transactions Act to introduce punitive damages—allowing fines of up to 3% of a financial institution's total annual revenue for severe security breaches. Additionally, the revisions seek to enhance the authority of Chief Information Security Officers (CISOs), enabling them to proactively lead cybersecurity enhancements across their organizations.
In response to the sanction, Lotte Card issued a formal apology. "We express our sincere apologies to our customers for causing immense concern due to this incident," a company representative stated. "Moving forward, we will make every necessary effort to fortify our information security infrastructure and restore public trust as a reliable financial institution."
WEEKLY HOT
- 1Why There Is No High-Speed Rail Between Gwangju and Busan: How Seoul-Centric Tracks Are Draining South Korea’s Regions
- 2South Korea Launches Pan-Government 'One Health' Council to Combat Complex Infectious Disease Threats
- 3SK Hynix Hits Historic Daily Limit High for the First Time in Company History
- 4Chromosome Abnormalities Found in 30% of Defectors from North Korean Nuclear Test Site Area
- 5South Korea to Import Argentine Crude Oil to Diversify Energy Supply Amid Middle East Turmoil
- 6Slight Relief: Domestic Fuel Prices Drop for 11th Consecutive Week as Gasoline and Diesel Hover in 1,800-Won Range