주메뉴바로가기본문바로가기
비즈한국 비즈한국

Personal Information Protection Commission Imposes 9.6 Billion Won Fine on Lotte Card… The First Challenge Facing New CEO Jung Sang-ho

This article was automatically translated by AI. There may be errors compared to the original Korean article.  Read original in Korean →

[비즈한국] Regarding the massive personal information leak at Lotte Card, the Personal Information Protection Commission (PIPC) has imposed a fine of nearly 10 billion won. Some evaluate the level of sanctions to be lower than expected, as the fine was applied only to partial revenue related to the violation. With additional sanctions from financial authorities still pending, newly appointed Lotte Card CEO Jung Sang-ho, set to take office on the 16th, faces the dual challenges of managing the aftermath of the incident and responding to these sanctions.

In connection with the personal information leak in September 2025, Lotte Card was fined approximately 9.6 billion won by the Personal Information Protection Commission. Photo = Reporter Im Jun-seon
In connection with the personal information leak in September 2025, Lotte Card was fined approximately 9.6 billion won by the Personal Information Protection Commission. Photo = Reporter Im Jun-seon

During its 4th plenary meeting on the 11th, the Personal Information Protection Commission decided on sanctions, including a fine of 9.62 billion won, a penalty of 4.8 million won, and an order for corrective measures and public notification against Lotte Card. This follows an investigation into whether Lotte Card violated its obligations regarding the processing of resident registration numbers, stemming from a leak of personal information for 2.97 million users in September 2025.

In August 2025, Lotte Card's online payment system was hacked by an external attacker. The hacker embedded malicious code into Lotte Card's online payment servers and exfiltrated log files generated during the payment process. About half of the files stolen by the hacker were encrypted, but the remainder were leaked in plaintext. The leaked personal information included CI (encrypted personal identification information), virtual payment codes, card numbers, expiration dates, and CVC numbers.

It was confirmed that the leaked information also included the resident registration numbers of 450,000 individuals. The PIPC determined that Lotte Card violated the Personal Information Protection Act by failing to encrypt personal information, including resident registration numbers, in logs related to online payments, and by failing to properly encrypt the log files themselves. The Personal Information Protection Act stipulates that resident registration numbers may only be processed when explicitly required by law or to protect the life, body, or property of the data subject.

Furthermore, the commission pointed out that while log files should record only the minimum amount of personal information, Lotte Card's storage of extensive personal information, including resident registration numbers, led to the large-scale hacking incident. In addition to the fines, the PIPC ordered Lotte Card to strengthen the responsibility and independence of its Chief Privacy Officer (CPO) and to overhaul its overall personal information protection system.

The PIPC is also launching industry-wide inspections in the wake of the incident. It announced plans to conduct preliminary status checks in March regarding the practice of financial sector companies processing resident registration numbers unnecessarily without legal basis.

Financial authorities are expected to impose sanctions after investigating Lotte Card for violations of the Credit Information Act. Pictured is the consultation center established at Lotte Card headquarters in September 2025. Photo = Reporter Choi Jun-pil
Financial authorities are expected to impose sanctions after investigating Lotte Card for violations of the Credit Information Act. Pictured is the consultation center established at Lotte Card headquarters in September 2025. Photo = Reporter Choi Jun-pil

Following the PIPC's announcement, industry observers reacted by noting that the level of punishment was lower than expected. Woori Card, in the same industry, was fined 13.4 billion won in March 2025 for violating the Personal Information Protection Act. It appears that Lotte Card’s fine remained below 10 billion won because the scale of revenue related to the violation, which serves as the basis for calculating the fine, was relatively small.

The PIPC explained, "We only investigated the violations related to the duty to process resident registration numbers and the duty to implement encryption measures. The fine was calculated based solely on revenue related to the online payment service," adding, "The calculation ratio relative to revenue varies according to the severity of the violation, and is determined after primary adjustments and secondary weighting or mitigation."

Lotte Card is expected to contest the decision. Lotte Card stated, "We voluntarily reported the incident and cooperated faithfully with the PIPC's investigation," adding, "There are aspects where the details we clarified, such as legal grounds, were not sufficiently reflected. After receiving the written decision, we will carefully review the contents and continue to provide explanations through available objection procedures.”

Meanwhile, on the 12th, the day the PIPC announced its sanctions, Lotte Card held an extraordinary shareholders' meeting and a board meeting to finalize the appointment of Jung Sang-ho as the new CEO. The new CEO's term runs from March 16, 2026, to March 29, 2028. Effectively, the new CEO has taken on the challenge of managing the sanctions immediately upon taking office.

Attention is also focused on the upcoming results of the financial authorities' investigation. The Financial Services Commission and the Financial Supervisory Service are investigating whether Lotte Card fulfilled its duty to implement safety measures in accordance with the Credit Information Act regarding the personal information leak. Under the Credit Information Act, fines for personal information leaks caused by hacking are capped at 5 billion won. However, if violations of the Specialized Credit Finance Business Act are confirmed, a six-month suspension of business is possible, and sanctions against the executive team remain a possibility.

Lotte Card stated, "We deeply apologize for the inconvenience and concern caused by this cyber security incident," and added, "We will do our utmost to prevent recurrences and strengthen personal information protection in the future."

This article was automatically translated by AI. There may be errors compared to the original Korean article.
심지영 기자

금융, 가상자산, 핀테크, 투자 업계 중심으로 취재하고 있습니다. 언제든 제보주세요.

jyshim@bizhankook.com
저작권자 ⓒ 비즈한국 무단전재 및 재배포 금지