주메뉴바로가기본문바로가기
비즈한국 비즈한국

Field Report
"Personnel Reform Including CEO by Year-End"... Why Was Lotte Card's Response to Data Breach Delayed?

This article was automatically translated by AI. There may be errors compared to the original Korean article.  Read original in Korean →

[비즈한국] A massive personal information breach has occurred at Lotte Card. It has been confirmed that the data of 2.97 million customers was leaked, with the volume of data exceeding 200 gigabytes (GB). Immediately following the final investigation results, Lotte Card issued a public apology, announced customer support measures, and pledged to expand investments in information security. Although Lotte Card handled the situation relatively transparently, a strong backlash is expected as it was revealed that, contrary to its initial claims that 'no personal information was leaked,' a massive amount of data had in fact been compromised.

At a Lotte Card hacking incident briefing held on September 18, CEO Cho Jwa-jin (fifth from left) and key executives issued a public apology. Photo = Reporter Shim Ji-young
At a Lotte Card hacking incident briefing held on September 18, CEO Cho Jwa-jin (fifth from left) and key executives issued a public apology. Photo = Reporter Shim Ji-young

The personal information of 2.97 million Lotte Card customers was leaked due to a hacking incident. The volume of leaked data exceeds 200GB. Lotte Card CEO Cho Jwa-jin personally announced these details during a briefing on September 18. Lotte Card is currently notifying the 2.97 million affected customers of the hacking and subsequent measures via text message.

When initially reporting the incident to financial authorities, Lotte Card stated the leaked data volume was around 1.7GB, but the investigation revealed an additional leak of 200GB. According to Lotte Card, the hacking occurred between August 13 and August 27. The leaked information, generated and collected during payment processes via a compromised online server, includes CI (Encrypted Personal Identification Information), virtual payment codes, and simplified payment service data.

The issue is that 280,000 customers are at risk of fraudulent charges. These individuals are customers who registered new cards for pay services or online commerce between July 22 and August 27. The leaked information includes card numbers, expiration dates, and CVC numbers.

However, Lotte Card explained that the stolen data does not include information required to replicate physical cards, making offline fraudulent payments impossible. Regarding online payments, the company noted that secondary verification processes such as SMS authentication and biometric authentication make fraudulent use difficult. While there is a possibility of unauthorized use through 'Key-In' methods—where card information is entered directly into a terminal—no such cases have been reported yet.

Lotte Card first detected traces of a server intrusion on August 26. Later, on August 31, they discovered traces of an attempt to move information out of the online payment server and reported it to financial authorities at 10:00 AM on September 1. However, it was confirmed that the hacker had planted malicious code on the online payment server as early as August 13. This has led to criticism regarding weak security, given that Lotte Card took about two weeks to notice the breach.

The sequence of events is as follows: The external attacker (hacker) leaked a 1.7GB file on August 14-15, and then siphoned an additional 2,708 (excluding duplicates) log files generated during online payment processing between August 15 and 27. Of these, 56% were encrypted files, while the remaining 44% were leaked in plain text. The problem lies with the 1.7GB file leaked on August 14-15; as the hacker deleted the files on the server after the theft, Lotte Card has been unable to verify exactly what information was contained within them.

Choi Yong-hyuk, Lotte Card's Chief Information Security Officer, explained, "It was a different method than common intrusions. Furthermore, the server that was hacked had very little traffic, which delayed detection. The hacker didn't take the information in bulk, but rather in small portions over time, which dragged out the process." Regarding why it took time to grasp the details after discovery, CEO Cho explained, "It took time to recover, match, and categorize the 200GB of encrypted files for each customer. This work was completed around 6:00 PM on the 17th."

Lotte Card CEO Cho Jwa-jin stated, “I will carry out major personnel reform by the end of the year, including my own resignation.” Photo = Reporter Shim Ji-young
Lotte Card CEO Cho Jwa-jin stated, “I will carry out major personnel reform by the end of the year, including my own resignation.” Photo = Reporter Shim Ji-young

The entity behind the hack has not yet been identified. CEO Cho said, "The Cyber Investigation Unit is tracing IP addresses and cloud providers. Based on the hacking method, we suspect an overseas hacker group, but we have not been able to pinpoint them yet."

As customer support and protection measures, Lotte Card announced full compensation for any damages from fraudulent use, priority card reissuance, expansion of the dedicated 24/7 consultation center, interest-free 10-month installments without limit for affected customers until the end of the year, free provision of the 'Credit Care' financial compensation service, and free card usage notification services. In particular, the 280,000 customers at risk of fraudulent charges will have their annual membership fees waived without limit upon card reissuance.

The company also plans to expand investment in information security. They intend to invest 110 billion won over the next five years and raise the ratio of the information security budget to 15% of the total IT budget. Responding to criticism that the issue stemmed from cost-cutting, CEO Cho stated, "We have steadily increased internal personnel and information security investment, and prepared by employing white-hat hackers, but it seems it was not enough."

Meanwhile, it appears difficult for Lotte Card to avoid sanctions from financial authorities. In 2014, KB Kookmin Card, NH Nonghyup Card, and Lotte Card were subject to business suspension and fines by the Financial Services Commission following a card company data breach. Furthermore, during a meeting with CEOs of credit-specialized financial companies on the 16th, Financial Supervisory Service (FSS) Governor Lee Chan-jin remarked, "As the credit card industry handles the information of all citizens, we will apply a zero-tolerance policy. CEOs must personally take the lead in establishing and implementing security measures. The FSS will strictly manage and supervise, and will impose stern and heavy responsibility for any violations."

CEO Cho Jwa-jin appears to have decided to step down before the end of his term to take responsibility for the situation. On the 18th, Cho stated, "I will complete a major personnel reform by the end of the year, including myself. There will be a level of reform acceptable to the market, including my resignation as CEO. I will do my utmost with the resolute mindset that my final duty as Lotte Card CEO is to zero out customer damages and minimize inconvenience."

CEO Cho was inaugurated in March 2020 and successfully served three consecutive terms in March 2022 and March 2024. His term is two years, with the current term scheduled to last until March 2026.

This article was automatically translated by AI. There may be errors compared to the original Korean article.
심지영 기자

금융, 가상자산, 핀테크, 투자 업계 중심으로 취재하고 있습니다. 언제든 제보주세요.

jyshim@bizhankook.com
저작권자 ⓒ 비즈한국 무단전재 및 재배포 금지