In an era where almost everyone uses at least one or two credit cards, personal information protection is central to financial life. The repercussions of the massive data breach that occurred at Lotte Card last year continue into 2026, drawing significant attention. This unprecedented incident involved the leakage of customer information for a staggering 2.97 million people, and with strong sanctions from financial authorities anticipated, Lotte Card is once again put to the test. How will Lotte Card navigate this crisis?
Beyond a simple personal information leak, the situation has escalated to include controversy over business suspension. There is considerable interest in whether Lotte Card can regain customer trust and normalize its operations. The company is making comprehensive efforts under a new CEO, but there still seems to be a long way to go.
The Full Story of the 2.97 Million Data Breach

The Lotte Card hacking incident occurred on August 26, 2025. Lotte Card reported this fact to financial supervisory authorities on September 1. As a result of its internal investigation, it was determined that customer information for approximately 2.97 million people had been leaked. The problem was not merely the leakage of personal information like names or contact details. For about 280,000 of these customers, critical information directly usable for fraudulent payments, such as card numbers, expiration dates, and CVC numbers, was also exposed. This was a serious level of information leakage that could lead to financial fraud.
Strong Sanctions from Financial Authorities and Their Background

Financial authorities imposed very strong sanctions regarding the large-scale data breach. On April 9, 2026, the Financial Supervisory Service (FSS) pre-notified Lotte Card of a disciplinary action plan that included a 4.5-month business suspension and a fine of 5 billion Korean Won. Subsequently, on April 30, this disciplinary action plan passed the Sanctions Review Committee. However, the business suspension is not yet finalized, as it still awaits the final resolution of the Financial Services Commission (FSC). Additionally, the Personal Information Protection Commission (PIPC) separately imposed a fine of 9.62 billion Korean Won and an administrative penalty of 4.8 million Korean Won on March 12. Given Lotte Card’s previous 3-month business suspension during the 2014 credit card data breach, it is analyzed that repeated violations acted as an aggravating factor this time.
Lotte Card’s Crisis Response and Efforts to Rebuild Trust

Immediately after the incident, Lotte Card issued a public apology and promised full compensation to affected customers. It also announced a 5-year, 110 billion Korean Won investment plan in information security to strengthen its security systems. Jeong Sang-ho, the new CEO who took office on March 12, 2026, has made regaining customer trust and normalizing operations his top priorities. Indeed, Lotte Card successfully rebounded in performance, with its operating profit in Q1 2026 surging by 201% year-on-year. This is attributed to the restructuring of its portfolio around prime customers and proactive risk management efforts. The company emphasizes that not a single instance of attempted fraudulent use or actual consumer damage resulting from the breach has been confirmed, and it is striving to minimize customer inconvenience.
Lotte Card encountered a major obstacle in the form of a large-scale data breach, but under swift response and the leadership of its new CEO, it is dedicating all its efforts to rebuilding trust and normalizing operations. While the final level of sanctions has not yet been determined, and customer anxiety has not been completely alleviated, the company’s continuous efforts and transparent communication will be key to overcoming this crisis.
