The Korea Times

Homeplus under probe over personal data leak

- By Baek Byung-yeul baekby@koreatimes.co.kr

Homeplus, one of the country’s top discount store chains, is facing investigat­ion by the telecommun­ications regulator over the hijacking of 49,000 customer accounts, according to a lawmaker, Thursday.

Rep. Byun Jae-il of the ruling Democratic Party of Korea (DPK) said the Korea Communicat­ions Commission (KCC) and the Korea Internet & Security Agency (KISA) have been investigat­ing the discount store chain after acknowledg­ing that an unidentifi­ed intruder logged into Homeplus’ online shopping mall using customers’ ID and passwords.

“For about a year from Oct. 17, 2017 to Oct. 1, 2018, the unidentifi­ed person logged into the online shopping mall of Homeplus to steal customers’ rewards points. The total number of compromise­d accounts is 49,000,” the lawmaker said.

Homeplus belatedly noticed the incursions on Sept. 20, almost two years after the first case occurred, after a customer filed a complaint with the company for not getting the rewards points.

The KCC said it conducted an on-site investigat­ion of Homeplus on Wednesday together with the KISA. The regulator said it will impose sanctions on Homeplus once it is confirmed that the company violated the law.

The lawmaker accused the discount store chain of acting irresponsi­bly as the company didn’t notify its customers even though it is legally mandatory for a company to report cyberattac­ks to the relevant users.

According to Article 27-3 of the informatio­n communicat­ions network act, when a provider of informatio­n and communicat­ions services becomes aware of the loss, theft or leak of personal informatio­n, the provider is supposed to inform the relevant users immediatel­y and report the situation to the KCC or the KISA.

“Though Homeplus reported the case to the telecommun­ications regulators right after the case was revealed, the company didn’t notify its customers. Its action amounts to a breach of the informatio­n communicat­ions network act,” Byun said, adding that Homeplus can be charged up to 30 million won ($25,021) of fine.

However, Homeplus refuted the lawmaker’s claim, saying it notified the telecommun­ications regulators and customers on the same day the suspicious activity was detected.

“As soon as we detected the incident on Sept. 20, Homeplus reported the case to the telecommun­ications regulators. At the same time we also notified our customers via email and cellphone text message,” a Homeplus official said.

This is not the first time Homeplus has been embroiled in an informatio­n leak case as its former and current employees were found guilty of selling customers’ personal data to LINA Life Insurance and Shinhan Life Insurance between 2011 and 2014.

 ?? Korea Times file ?? Homeplus headquarte­rs in Gangseo-gu, Seoul
Korea Times file Homeplus headquarte­rs in Gangseo-gu, Seoul

Newspapers in English

Newspapers from Korea, Republic