Skip to content
Back to Blog
high severity August 31, 2026 · 4 min read Unverified claim — what this is

GS25 and GS SHOP data leak confirmed: 1.66 million customers, what it means

If you are a customer of GS25 and GS SHOP, here’s what is being claimed, and what it would mean for you.

South Korea’s privacy regulator has confirmed that an attacker used stolen logins to read personal details of 1,581,025 GS SHOP members and 79,128 GS25 members. Names, home addresses, phone numbers, dates of birth, gender and emails were taken between 2024 and early 2025. GS Retail notified customers in 2025 and was fined 12.836 billion won in August 2026.

— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
GS25 and GS SHOP data leak confirmed: 1.66 million customers, what it means

South Korea’s Personal Information Protection Commission has confirmed that an unidentified attacker used previously stolen IDs and passwords to log into customer accounts and open the pages where people update their personal details. At GS SHOP that access ran from 21 June 2024 to 13 February 2025 and reached 1,581,025 members. At GS25 convenience stores it ran from 26 December 2024 to 4 January 2025 and reached 79,128 members. In total, about 1.66 million people.

Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 582 companies.
See what is exposed about you — free scan →
Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.

The commission said the information taken included names, gender, dates of birth, phone numbers, home addresses and email addresses. GS Retail had already disclosed the incidents and apologised in January and February 2025; its GS SHOP notices also listed login IDs, marital status, wedding anniversary and personal customs clearance codes. On 31 August 2026 the regulator announced a 12.836 billion won (about US$9.3 million) fine and a 3 million won penalty, finding that the company went months without spotting obvious abnormal logins and had no dedicated privacy team at the time.

The fine is not what happened to you

Almost every report of this will lead with the penalty and the 1.66 million headcount. That is a story about a company being punished. It is not a story about what is now sitting in someone else’s hands.

The attacker did not grab an anonymous pile of rows. They used working logins, over months, to open the exact screens people use to change a home address or a phone number. What that produces is a matched set: a real name, a date of birth, a home address, a phone number and an email, attached to someone who shops with GS. That mix is what lets a stranger send a text or make a call that already feels like it knows you. Coverage of a corporate fine buries that.

Two other things get lost. This access started in 2024 and ended in February 2025. GS Retail’s first public apologies and customer notices went out in early 2025. The August 2026 news is the regulator finishing its case, not the day the information left. And a fine does not take the copies back.

If you were not contacted in 2025, that does not prove you were spared. The commission said notice was delayed for 1,599 extra people found during its investigation. There is no public list you can search to see whether a given name was included. Anyone offering to check for you is guessing, or trying to get you to hand over more details.

What to actually expect

  • A new wave of texts and calls that mention GS25, GS SHOP, “compensation,” or the government fine, and that use your real name or another detail from a customer file. The 2026 headlines are bait. The company will not ask you to confirm your address, date of birth or clearance code by phone or by a link in a message.
  • Fake delivery, parcel or customs messages, especially if you used GS SHOP. Home address and phone number were taken; GS Retail’s own 2025 notices also listed personal customs clearance codes for that business. Those are the ingredients for a “your package is held” scam.
  • Nothing dramatic needs to happen this week for the data to already be in use. It has been outside the company since 2024–2025. A quiet inbox is not proof you were left out, and you should not wait for a later alert as proof you were included.
  • The GS login was opened with a password that had already leaked somewhere else. Other accounts where that same password was reused were the original opening. Treat that password as known to someone else, even if GS later locked accounts and blocked the attacker.

What you can and cannot fix

The copy of your name, gender, date of birth, phone number, home address and email that was read from those member pages cannot be undone. It is out. GS Retail cannot delete it from the attacker’s hands, a fine does not recall it, and no service can scrub it from whoever already has it. If your GS SHOP file also held a login ID, marital status, wedding anniversary or personal customs clearance code, as the company said in 2025, those are out too.

  • Treat every inbound contact about this leak as a scam unless you started it inside the official GS app or website you typed yourself. Do not tap links in texts. Do not confirm an address, clearance code or date of birth to anyone who reached out to you.
  • Change the password you used for GS, and every other place you used that same password. That is how the attacker got in: old IDs and passwords from elsewhere, tried in bulk. A different password on each remaining account closes that path.
  • Cut back what people-search sites and public listings still show about you. A bare leaked record becomes much more dangerous when it can be joined to a listing that adds relatives, extra phone numbers, an employer or previous addresses. Those listings, unlike the stolen file, can actually be removed or suppressed. The leaked row cannot.
  • Watch for someone using your name plus home address and date of birth as if they were you — a mobile plan you did not open, a delivery you did not order, or a message to family that sounds as if it knows your household. That is the fraud this particular mix of fields enables. The commission did not list bank account numbers or national ID numbers among the leaked fields; this is still not something to ignore.

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove — and removing them is what we do.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample582 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

Check your exposure
GS25 and GS SHOP is one listing. Your email is probably in others.
We can’t confirm any single incident against the sources we search, so we won’t pretend to. What we can show you is your own exposure — your email against 13.1B+ leaked records and the sites that publish your address. About 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity High contact details only, none of them permanent
Disclosed August 31, 2026
Last reviewed August 31, 2026
Affected Unconfirmed
Data exposed Full namesGenderDates of birthPhone numbersHome addressesEmail addresses
Unverified claim — what this report is
This page documents a public listing on a ransomware/extortion group’s leak site, tracked via public threat-intelligence sources. A listing is the attacker’s claim. GalaxyWarden aggregates and reports such claims; we have not independently verified that a breach occurred, what data (if any) was taken, or the accuracy of anything the group asserts, and the named organisation has not necessarily confirmed the incident. Sections above describe what the listing shows and the group’s documented history — not verified findings about the named organisation. If you represent this organisation and believe anything here is inaccurate, tell us and we’ll review it promptly.
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email