[비즈한국] A massive personal information breach has occurred at Lotte Card. It has been confirmed that the data of 2.97 million customers was leaked, with the volume of data exceeding 200 gigabytes (GB). Immediately following the final investigation results, Lotte Card issued a public apology, announced customer support measures, and pledged to expand investments in information security. Although Lotte Card handled the situation relatively transparently, a strong backlash is expected as it was revealed that, contrary to its initial claims that 'no personal information was leaked,' a massive amount of data had in fact been compromised.

The personal information of 2.97 million Lotte Card customers was leaked due to a hacking incident. The volume of leaked data exceeds 200GB. Lotte Card CEO Cho Jwa-jin personally announced these details during a briefing on September 18. Lotte Card is currently notifying the 2.97 million affected customers of the hacking and subsequent measures via text message.
When initially reporting the incident to financial authorities, Lotte Card stated the leaked data volume was around 1.7GB, but the investigation revealed an additional leak of 200GB. According to Lotte Card, the hacking occurred between August 13 and August 27. The leaked information, generated and collected during payment processes via a compromised online server, includes CI (Encrypted Personal Identification Information), virtual payment codes, and simplified payment service data.
The issue is that 280,000 customers are at risk of fraudulent charges. These individuals are customers who registered new cards for pay services or online commerce between July 22 and August 27. The leaked information includes card numbers, expiration dates, and CVC numbers.
However, Lotte Card explained that the stolen data does not include information required to replicate physical cards, making offline fraudulent payments impossible. Regarding online payments, the company noted that secondary verification processes such as SMS authentication and biometric authentication make fraudulent use difficult. While there is a possibility of unauthorized use through 'Key-In' methods—where card information is entered directly into a terminal—no such cases have been reported yet.
Lotte Card first detected traces of a server intrusion on August 26. Later, on August 31, they discovered traces of an attempt to move information out of the online payment server and reported it to financial authorities at 10:00 AM on September 1. However, it was confirmed that the hacker had planted malicious code on the online payment server as early as August 13. This has led to criticism regarding weak security, given that Lotte Card took about two weeks to notice the breach.
The sequence of events is as follows: The external attacker (hacker) leaked a 1.7GB file on August 14-15, and then siphoned an additional 2,708 (excluding duplicates) log files generated during online payment processing between August 15 and 27. Of these, 56% were encrypted files, while the remaining 44% were leaked in plain text. The problem lies with the 1.7GB file leaked on August 14-15; as the hacker deleted the files on the server after the theft, Lotte Card has been unable to verify exactly what information was contained within them.
Choi Yong-hyuk, Lotte Card's Chief Information Security Officer, explained, "It was a different method than common intrusions. Furthermore, the server that was hacked had very little traffic, which delayed detection. The hacker didn't take the information in bulk, but rather in small portions over time, which dragged out the process." Regarding why it took time to grasp the details after discovery, CEO Cho explained, "It took time to recover, match, and categorize the 200GB of encrypted files for each customer. This work was completed around 6:00 PM on the 17th."

The entity behind the hack has not yet been identified. CEO Cho said, "The Cyber Investigation Unit is tracing IP addresses and cloud providers. Based on the hacking method, we suspect an overseas hacker group, but we have not been able to pinpoint them yet."
As customer support and protection measures, Lotte Card announced full compensation for any damages from fraudulent use, priority card reissuance, expansion of the dedicated 24/7 consultation center, interest-free 10-month installments without limit for affected customers until the end of the year, free provision of the 'Credit Care' financial compensation service, and free card usage notification services. In particular, the 280,000 customers at risk of fraudulent charges will have their annual membership fees waived without limit upon card reissuance.
The company also plans to expand investment in information security. They intend to invest 110 billion won over the next five years and raise the ratio of the information security budget to 15% of the total IT budget. Responding to criticism that the issue stemmed from cost-cutting, CEO Cho stated, "We have steadily increased internal personnel and information security investment, and prepared by employing white-hat hackers, but it seems it was not enough."
Meanwhile, it appears difficult for Lotte Card to avoid sanctions from financial authorities. In 2014, KB Kookmin Card, NH Nonghyup Card, and Lotte Card were subject to business suspension and fines by the Financial Services Commission following a card company data breach. Furthermore, during a meeting with CEOs of credit-specialized financial companies on the 16th, Financial Supervisory Service (FSS) Governor Lee Chan-jin remarked, "As the credit card industry handles the information of all citizens, we will apply a zero-tolerance policy. CEOs must personally take the lead in establishing and implementing security measures. The FSS will strictly manage and supervise, and will impose stern and heavy responsibility for any violations."
CEO Cho Jwa-jin appears to have decided to step down before the end of his term to take responsibility for the situation. On the 18th, Cho stated, "I will complete a major personnel reform by the end of the year, including myself. There will be a level of reform acceptable to the market, including my resignation as CEO. I will do my utmost with the resolute mindset that my final duty as Lotte Card CEO is to zero out customer damages and minimize inconvenience."
CEO Cho was inaugurated in March 2020 and successfully served three consecutive terms in March 2022 and March 2024. His term is two years, with the current term scheduled to last until March 2026.