기사 메일전송
Lotte Card Hack Victims Pile Up... Customer Protection and Compensation Plan to be Announced Tomorrow
  • Yonhap News
  • September 17, 2025 at 7:54 PM
기사수정
  • Initially reported a 1.7GB data leak, but..."scale is much larger," investigation concludes
  • Millions of victims estimated… Card numbers, CVC, etc. also potentially leaked


Lotte Card Hacking Incident: Possibility of Millions of VictimsThis image shows the Lotte Card headquarters in Jongno-gu, Seoul, on the 17th. The scale of the 'hacking incident' at Lotte Card, which has approximately 9.6 million members, is being understood to be much larger than initially expected, leading to projections of tens of thousands to millions of victims. Yonhap News.

The impact of the 'hacking incident' at Lotte Card, which boasts approximately 9.6 million members, is growing as the scale of the damage is proving to be far greater than anticipated.


There are even projections that the number of victims could reach several million.


According to financial authorities and the card industry on the 17th, Lotte Card and financial authorities are finalizing their work to confirm the extent of information leakage and the number of victims resulting from the hacking incident and will hold a result briefing on the 18th.


Cho Ja-jin, CEO of Lotte Card, will personally explain the circumstances of the incident and announce a public apology and customer protection measures.


Lotte Card had initially reported the leaked data volume to the Financial Supervisory Service (FSS) as around 1.7 gigabytes (GB). However, the scale of the damage identified through on-site inspections by financial authorities is known to be much more severe than initially expected.


A financial authority official stated, "The extent of the damage is estimated to be much larger than what has been reported," adding, "If the confirmation work concludes successfully, we may be able to announce the results within this week."


A Lotte Card official also commented, "The volume of leakage is larger than what we had assessed," and said, "We are preparing to announce the details as soon as the customer information leakage is confirmed and identified."


The number of victims also appears unlikely to be limited to the tens of thousands as initially estimated.


While the severity of the leaked information may vary, there are also predictions that the total number of victims could reach the millions.


In a report to the office of National Assembly member Kang Min-guk, the Financial Supervisory Service indicated the possibility of customer information leakage, stating, "It appears to include records of online payment requests, such as card information."


The assumption was that an online payment server was hacked on January 14th-15th, leading to the leakage of internal files, and that card information may have been included in the payment request records.


There is speculation that sensitive credit information such as card numbers, expiration dates, and CVC codes may have been leaked.


Although it was initially reported that only two days of payment history were leaked externally, given the circumstances of the large-scale data breach, there is speculation that payment history from a longer period may have been compromised.


The previous day, CEO Cho decided that addressing the hacking incident was the priority and notified the FSS Governor Lee Chan-jin that he would not attend the introductory meeting with industry officials.


Governor Lee has been consistently emphasizing 'consumer protection' as the top priority, stating at the meeting the previous day, "We must use recent cyber intrusion incidents in the financial sector as a moment for painful self-reflection."


Consequently, there is much attention on whether Lotte Card's result briefing will include substantial measures such as card replacement and customer compensation plans.


Discussions include refunding annual fees without deduction for withdrawn members.


SK Telecom [017670] provided benefits such as T membership partner discounts for one month as follow-up measures for user hacking damage.


President Lee Jae-myung also stated, "The public is very concerned due to the recent series of hacking incidents at telecommunications and financial companies," and ordered, "Please promptly prepare related measures to ensure strong responses, including punitive fines, are taken against companies that repeatedly experience security incidents."


The fact that Lotte Card's largest shareholder is the private equity firm MBK Partners is also being closely watched by the industry.


There have been ongoing criticisms that MBK Partners, which acquired Lotte Card, has focused on maximizing profits and has not invested adequately in security.


It is reported that Lotte Card's payment management server, which has been in use for approximately 10 years, had vulnerabilities discovered about a decade ago, and while most financial institutions installed security patches, Lotte Card did not apply them, leaving it exposed to hacking attacks.


Furthermore, it has been revealed that the situation was only recognized on July 31st, 17 days after the initial hacking attack, around noon.


Meanwhile, MBK Partners is currently facing simultaneous investigations by financial authorities and prosecutorial inquiries in relation to the 'Homeplus incident.'


Yonhap News


What do you think of this article?
recommend
0
great
0
moved
0
정기구독배너
Go to Mobile Site