GS25 and GS SHOP data leak confirmed: 1.66 million customers, what it means
If you are a customer of GS25 and GS SHOP, here’s what is being claimed, and what it would mean for you.
South Korea’s privacy regulator has confirmed that an attacker used stolen logins to read personal details of 1,581,025 GS SHOP members and 79,128 GS25 members. Names, home addresses, phone numbers, dates of birth, gender and emails were taken between 2024 and early 2025. GS Retail notified customers in 2025 and was fined 12.836 billion won in August 2026.
— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
Editor’s note: The claims described below originate from a ransomware group’s leak-site posting and have not been independently verified by GalaxyWarden. A listing of this kind is an assertion made by the group during an extortion attempt. It is not evidence that a breach occurred, and we report it as a claim rather than as a finding.
GS25 and GS SHOP customer?
See what’s already exposed about you — free, 15sWe check your email against known public breach records and the sites that publish your address, then show you what to do about each one. We don’t hold this company’s data. No account, no card.
Here for work? Check a company domain’s exposure.
South Korea’s Personal Information Protection Commission has confirmed that an unidentified attacker used previously stolen IDs and passwords to log into customer accounts and open the pages where people update their personal details. At GS SHOP that access ran from 21 June 2024 to 13 February 2025 and reached 1,581,025 members. At GS25 convenience stores it ran from 26 December 2024 to 4 January 2025 and reached 79,128 members. In total, about 1.66 million people.
The commission said the information taken included names, gender, dates of birth, phone numbers, home addresses and email addresses. GS Retail had already disclosed the incidents and apologised in January and February 2025; its GS SHOP notices also listed login IDs, marital status, wedding anniversary and personal customs clearance codes. On 31 August 2026 the regulator announced a 12.836 billion won (about US$9.3 million) fine and a 3 million won penalty, finding that the company went months without spotting obvious abnormal logins and had no dedicated privacy team at the time.
The fine is not what happened to you
Almost every report of this will lead with the penalty and the 1.66 million headcount. That is a story about a company being punished. It is not a story about what is now sitting in someone else’s hands.
The attacker did not grab an anonymous pile of rows. They used working logins, over months, to open the exact screens people use to change a home address or a phone number. What that produces is a matched set: a real name, a date of birth, a home address, a phone number and an email, attached to someone who shops with GS. That mix is what lets a stranger send a text or make a call that already feels like it knows you. Coverage of a corporate fine buries that.
Two other things get lost. This access started in 2024 and ended in February 2025. GS Retail’s first public apologies and customer notices went out in early 2025. The August 2026 news is the regulator finishing its case, not the day the information left. And a fine does not take the copies back.
Advertisement
Know the day any company files a breach.
Every SEC 8-K Item 1.05 and state breach notification — dated, sourced, and delivered by email + a JSON API the day it posts. Track any company, not just the ones in the news.
GalaxyWarden Signals and RecentBreaches share common ownership.
If you were not contacted in 2025, that does not prove you were spared. The commission said notice was delayed for 1,599 extra people found during its investigation. There is no public list you can search to see whether a given name was included. Anyone offering to check for you is guessing, or trying to get you to hand over more details.
What to actually expect
- A new wave of texts and calls that mention GS25, GS SHOP, “compensation,” or the government fine, and that use your real name or another detail from a customer file. The 2026 headlines are bait. The company will not ask you to confirm your address, date of birth or clearance code by phone or by a link in a message.
- Fake delivery, parcel or customs messages, especially if you used GS SHOP. Home address and phone number were taken; GS Retail’s own 2025 notices also listed personal customs clearance codes for that business. Those are the ingredients for a “your package is held” scam.
- Nothing dramatic needs to happen this week for the data to already be in use. It has been outside the company since 2024–2025. A quiet inbox is not proof you were left out, and you should not wait for a later alert as proof you were included.
- The GS login was opened with a password that had already leaked somewhere else. Other accounts where that same password was reused were the original opening. Treat that password as known to someone else, even if GS later locked accounts and blocked the attacker.
What you can and cannot fix
The copy of your name, gender, date of birth, phone number, home address and email that was read from those member pages cannot be undone. It is out. GS Retail cannot delete it from the attacker’s hands, a fine does not recall it, and no service can scrub it from whoever already has it. If your GS SHOP file also held a login ID, marital status, wedding anniversary or personal customs clearance code, as the company said in 2025, those are out too.
- Treat every inbound contact about this leak as a scam unless you started it inside the official GS app or website you typed yourself. Do not tap links in texts. Do not confirm an address, clearance code or date of birth to anyone who reached out to you.
- Change the password you used for GS, and every other place you used that same password. That is how the attacker got in: old IDs and passwords from elsewhere, tried in bulk. A different password on each remaining account closes that path.
- Cut back what people-search sites and public listings still show about you. A bare leaked record becomes much more dangerous when it can be joined to a listing that adds relatives, extra phone numbers, an employer or previous addresses. Those listings, unlike the stolen file, can actually be removed or suppressed. The leaked row cannot.
- Watch for someone using your name plus home address and date of birth as if they were you — a mobile plan you did not open, a delivery you did not order, or a message to family that sounds as if it knows your household. That is the fraud this particular mix of fields enables. The commission did not list bank account numbers or national ID numbers among the leaked fields; this is still not something to ignore.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
For security and vendor-risk teams: get an alert the day a vendor you watch files a breach with a US regulator or the SEC — the filing itself, dated and sourced, plus an API. GalaxyWarden Signals →
A staff address in a leak usually means a third party was breached, not you — check your own domain’s exposure. Exposure Monitoring →
Report details & sourcing
Related breaches
Kindol vintage shop leak: 136,464 customers and 109,311 home addresses taken
Treasure Factory confirmed on 28 August 2026 that a phishing email let an attacker into a staff acco…
Eastlink data breach August 2026: what the customer emails actually mean
Eastlink emailed some current and former customers on 28 August 2026 about accounts that may have be…
Tixel data breach: your email and mobile number may have been accessed
Tixel emailed customers on 28 August 2026 to say their email address and mobile number may have been…