Korea's FSC Cuts Lotte Card Suspension to 1.5 Months Over Massive Data Breach

South Korea’s Financial Services Commission has imposed a 1.5-month business suspension and a 5 billion won ($3.6 million-range) penalty on Lotte Card over last year’s hacking incident, which exposed the personal information of 2.97 million customers. The sanction, finalized at the commission’s 14th meeting on July 31, is markedly lighter than the 4.5-month suspension originally on the table — a two-thirds reduction that turns one of the harshest penalties contemplated for a Korean card issuer into a far more survivable one.
A Two-Thirds Reduction at the Final Hurdle
The headline number in the decision is not the fine but the gap between the proposed and final suspension periods. A 4.5-month halt would have kept Lotte Card out of the affected business lines for more than a full quarter; the final 1.5-month term confines the disruption to roughly half of one. The 5 billion won penalty surcharge accompanies the suspension as the monetary component of the sanction.
Reductions of this scale generally emerge during the commission’s deliberation stage, where factors such as remediation spending, cooperation with investigators, and consumer-compensation measures are weighed against the severity of the underlying failure. The FSC’s decision notice frames the case squarely as a consequence of the information leak, making it one of the most significant data-security enforcement actions against a Korean credit card company since the industry-wide breach scandals of the mid-2010s.
The Breach Behind the Penalty
The sanction traces back to a hacking attack on Lotte Card’s systems last year that compromised data belonging to 2.97 million customers — a substantial share of the company’s customer base and, in absolute terms, one of the larger single-company leaks in recent Korean financial-sector history. Under Korean law, credit card issuers face some of the strictest data-handling obligations in the financial industry precisely because of that earlier era of mass leaks, which reshaped the country’s credit-information regime.
Why the Company Had to Tell the Market
Lotte Card filed a material-fact report on the business suspension with the Financial Supervisory Service’s electronic disclosure system, DART. That filing category is reserved for events deemed capable of affecting a company’s business or value, underscoring that even the reduced 1.5-month term is a materially consequential event for the issuer rather than a routine administrative slap.
The Calibration Question
The decision leaves Korean financial institutions with a double-edged precedent. On one hand, the FSC has shown it is willing to reach for business suspension — not just fines — when customer data is exposed at scale. On the other, the final penalty landing at a third of the proposed term signals that mitigation efforts can substantially soften the outcome. How regulators explain that calibration will shape how boards at other card issuers and lenders price the risk of underinvesting in security: as a multi-month existential threat to their sales pipeline, or as a bounded cost that diligent post-incident conduct can contain.
Sources (7) — Financial Services Commission · Yonhap News Agency · DART (Financial Supervisory Service)
- Financial Services Commission, 2026-07-31
- Yonhap News Agency, 2026-07-31
- Financial Services Commission, 2026-07-31
- Yonhap News Agency, 2026-07-31
- Yonhap News Agency, 2026-07-31
- Yonhap News Agency, 2026-07-31
- DART (Financial Supervisory Service), 2026-07-31
출처: 금융감독원 전자공시시스템(DART)