
Lotte Card, which suffered a data leak affecting the credit information of 2.97 million customers, will be prohibited from issuing new cards to new members for one and a half months. This marks the first time financial authorities have imposed a business suspension on a financial company due to a hacking incident. However, the severity of the sanction was reduced from an initial four-and-a-half-month suspension to 1.5 months, taking into account the company’s post-incident remediation efforts and the impact on financial consumers.
The Financial Services Commission (FSC) decided at its 14th regular meeting on the 31st to impose a one-and-a-half-month business suspension and a fine of 50 billion won on Lotte Card. The suspension will take effect from the first day of next month through September 15.
Lotte Card reported to financial authorities on September 1 of last year that customer information had been leaked due to a hacker attack in August of the same year. Following the report, the Financial Supervisory Service (FSS) conducted an investigation from September to October last year.
According to the FSS investigation results, Lotte Card operated its online payment system without performing necessary corrections on its information processing systems. It was also found that the company violated security obligations under the Credit Information Act and the Specialized Financial Business Act by failing to encrypt resident registration numbers and passwords and by not installing antivirus software.
Consequently, the FSS recommended a four-and-a-half-month business suspension, a 50 billion won fine, and disciplinary warnings for all senior executives, which were then submitted to the Financial Services Commission.
After reviewing Lotte Card’s statements and discussions within the subcommittee on the matter, the FSC imposed a business suspension for one and a half months — the first such penalty for a hacking incident. The decision considered factors including fairness with previous sanctions, Lotte Card’s efforts to manage the aftermath of the incident, and the potential impact on financial markets and consumers.
During the suspension period, new members will not be able to obtain credit cards, debit cards, or prepaid cards from Lotte Card. Existing cardholders can continue to use all card-related services without restriction. Transactions, point accumulation and usage, reissuance of cards, and increases in credit limits remain permitted. Applications for new card loans, cash services, and revolving credit are also allowed.
To prevent a recurrence of the data leak, financial authorities plan to actively support the passage of amendments to the Electronic Financial Transactions Act through the National Assembly. The proposed revisions include imposing punitive fines of up to 3% of total sales in cases of major security breaches and strengthening the authority of the Chief Information Security Officer (CISO). Additionally, the authorities will continuously monitor the impact on consumers during the suspension period to ensure no inconvenience arises.