TITLE: South Korea's Financial Services Commission Imposes Business Suspension and Fine on Lotte Card for Data Breach
BODY:
On July 31, 2026, the Financial Services Commission (FSC) resolved to impose a 1.5-month business suspension and a 5 billion won fine on Lotte Card following a data breach that exposed the credit information of approximately 2.97 million customers in August 2025.
The FSC's action followed an investigation conducted by the Financial Supervisory Service (FSS) from September to October 2025, after Lotte Card reported the hacking incident on September 1, 2025. The FSS inspection identified multiple security violations under the Specialized Credit Finance Business Act and the Credit Information Use and Protection Act, including failure to implement system patches for the online payment system, non-encryption of resident registration numbers and passwords, and absence of antivirus software installation.
The FSC determined this represented the first business suspension imposed for a hacking incident involving data breach. The 1.5-month suspension period reflects consideration of fairness with previous enforcement actions, the company's remedial efforts, and impacts on financial markets and consumers. The business suspension takes effect August 1, 2026, and concludes September 15, 2026.
To minimize customer inconvenience, the FSC differentiated restrictions between existing and new members. Existing members retain full card service access, including payment transactions, limit increases, card reissuance, and new applications for card loans, cash advances, and revolving credit. New member card issuance is prohibited, with limited exceptions for public-purpose cards including welfare cards and military-related cards.
The FSC announced plans to strengthen financial company security management systems through amendments to the Electronic Financial Transactions Act, including introducing punitive fines up to three percent of total revenue for serious security incidents and enhancing the authority of Chief Information Security Officers (CISOs). The FSC will continuously monitor impacts on financial consumers to ensure service continuity.