NewsStocksH&M Discloses Customer Data Breach in South Korea

H&M Discloses Customer Data Breach in South Korea

Author: Korea Herald Business·

Key Takeaways

  • H&M confirmed unauthorized access and leakage of South Korean customer information through an attack on its business systems believed to have occurred around Aug. 5.
  • The compromised data was limited to email addresses, phone numbers, and order or return reference numbers, while resident registration numbers, credit card details, payment information, and passwords were not affected.
  • H&M strengthened its security measures, launched an investigation, and reported the incident to the relevant South Korean government authorities.
  • South Korea's Personal Information Protection Act, tightened by a 2023 amendment, requires breach notification within 72 hours, reporting to the PIPC, and allows administrative fines of up to 3 percent of total revenue for violations.
  • H&M has not disclosed how many customers were affected, leaving the scale of the breach undetermined as its investigation continues.
H&M Discloses Customer Data Breach in South Korea

Swedish fashion giant H&M has disclosed a data breach that exposed some of its customers' personal information in South Korea, the company said Friday.

In a notice sent to members, H&M said it had confirmed an incident involving the unauthorized access and leakage of customer information through an attack on its business systems, believed to have occurred around Aug. 5. H&M, formally known as Hennes & Mauritz, is headquartered in Stockholm and operates as one of the world's largest fashion retailers, and has maintained a presence in South Korea since opening its first store there in 2010.

The company said it moved quickly to strengthen its security measures and launch an investigation after detecting the attack. Based on its findings so far, the compromised information includes customers' email addresses, phone numbers, and order or return reference numbers.

H&M emphasized that more sensitive information — including resident registration numbers, South Korea's national identification numbers, as well as credit card details, payment information, and passwords — was not affected. South Korea has sharply restricted the online collection of resident registration numbers after past mass leaks, a legacy of the country's long history of large-scale data incidents.

South Korea regulates corporate data handling under the Personal Information Protection Act (PIPA), the country's main privacy law, which requires companies that suffer a breach to notify affected users and report the incident to the Personal Information Protection Commission (PIPC), the national data protection regulator. A 2023 amendment tightened those duties further, adding a 72-hour notification deadline and administrative fines of up to 3 percent of total revenue for violations. H&M said it also reported the incident to the relevant government authorities and is taking additional measures to prevent further unauthorized access and reduce any potential harm to customers.

The disclosure comes amid a string of recent data breaches involving companies operating in South Korea. In June, Korean streaming platform Tving said it had identified unauthorized access to users' personal information.

In a notice posted on its website, Tving said the potentially compromised data included user IDs, names, dates of birth, gender, mobile phone numbers, and email addresses. Resident registration numbers and payment-related information were not exposed, the streamer said.

The recent incidents follow some of the largest recorded data breaches anywhere, including a 2011 hack of web portal operator SK Communications that compromised data on roughly 35 million users and a 2014 leak at major South Korean credit card companies affecting tens of millions of customers — episodes that were followed by successive overhauls of the country's privacy laws.

H&M did not disclose how many customers were affected by the breach, leaving the scale of the incident among the open questions as its investigation continues.

Source: Korea Herald Business