CSIDB logo
Incident

Lotte Card

Incident posture

Attack window
Jul 2026
Location
South Korea
Status
Unknown
CIA posture
Available to members
Updated
2026-09-19 21:47

Linked entities

Victim
Lotte Card
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Pending
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Lotte Card disclosed a breach that exposed personal and financial data of approximately 2.97 million customers. The disclosure came amid a notable increase in cyberattacks targeting South Korean companies and government institutions, with security systems logging billions of suspicious alerts and numerous confirmed incidents across sectors. Authorities have been monitoring the situation and coordinating with national cybersecurity agencies to assess the impact and prevent further exposure.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

Two months before the September 2026 report, Lotte Card reported a data breach affecting 2.97 million customers. The available account did not provide the exact date of the announcement beyond that relative timing. It did not state when the intrusion began, how long it remained active, or when it was contained. It did not identify the affected systems, the method used to gain access, or the categories of customer information involved. No attacker identity, attribution, or claimed responsibility was reported for the Lotte Card incident. The account also did not describe how the breach was detected, whether police or prosecutors became involved, or what technical containment actions Lotte Card took. The company’s reported response was limited to disclosing the breach and stating the number of customers affected. No customer compensation, notification procedure, or remediation measure was described in the available material.

The disclosure followed Coupang’s November 2025 statement that information tied to 33.7 million customer accounts had been exposed. The account also described KT’s report of a network intrusion involving about 20,000 subscribers and unauthorized mobile payments. It later reported that a government investigation found a June attack on TVING had compromised about 39.54 million accounts, while noting that this total included multiple accounts held by the same users. The article presented these events as part of a broader run of private-sector breaches, but it did not identify a shared attacker, method, or infrastructure linking Lotte Card to the other incidents.

Sources

Sources available to members: 1 source.

CSIDB