Updates
Advertisement

H&M Reports Customer Data Breach in South Korea as Retail Cyber Risks Rise

h&m에서 패션, 홈, 아동 의류 등 다양한 아이템을

 

 

 

\TCF POST Report

SEOUL — Swedish fashion retailer H&M has disclosed a data breach in South Korea that exposed some customers’ personal information after unauthorized access to its business systems, adding the global fashion group to a growing list of companies facing cybersecurity threats in the country.

In a notice to Korean members, H&M said the intrusion is believed to have occurred around Aug. 5. The company said it detected the incident, strengthened its security measures and launched an investigation into the breach.

Based on its findings so far, the compromised information includes customers’ email addresses, phone numbers and order or return reference numbers. H&M said more sensitive information—including resident registration numbers, credit-card details, payment information and passwords—was not affected.

The retailer did not disclose how many customers were affected or provide details on the method used to gain access to its systems.

H&M said it has reported the incident to relevant government authorities and is taking additional measures to prevent further unauthorized access and minimize potential harm to customers.

Cybersecurity pressure grows in Korea

The incident comes as South Korea continues to tighten scrutiny of personal-data protection. Under the country’s Personal Information Protection Act, serious violations can result in administrative penalties of up to 3% of relevant annual revenue, while strengthened provisions introduced in 2026 allow higher penalties in certain repeat or large-scale cases.

For H&M, the breach is particularly significant because South Korea has been an established Asian market for the Swedish retailer since 2010, when it opened its first store in Seoul.

The disclosure also follows other recent data-security incidents in Korea. In June, streaming platform Tving reported unauthorized access potentially involving user IDs, names, dates of birth, gender, mobile numbers and email addresses, although it said resident registration and payment information were not exposed.

For fashion and retail companies, the incident highlights the growing cybersecurity risk surrounding customer-facing digital platforms, where contact details, transaction records and account information can become targets for phishing, fraud and other forms of misuse.

H&M’s investigation remains ongoing. The retailer is expected to determine whether the intrusion was confined to Korean operations or exposed weaknesses in systems connected to its wider regional or global technology infrastructure.

 

Leave a Comment

Americas

Europe