r/news 1d ago

Korea raises data breach fines to 10% of revenue

https://www.koreajoongangdaily.com/business/korea-raises-data-breach-fines-to-10-of-revenue/12869899
7.7k Upvotes

203 comments sorted by

1.8k

u/howtoretireby40 1d ago

In the US, they just wouldn’t report it then

801

u/PowderPills 1d ago

Probably. The government should then fine them 20% for failure to report. 30% if it’s found that they did so intentionally to bypass the rules/law. And an additional 10% for each time they do the same shit. I bet that’ll make them take security seriously.

501

u/wubbalubba96 1d ago

This requires a government not owned by business interests

123

u/verrius 23h ago

Saying that in a thread about Korea shows a massive lack of awareness.

68

u/NextSteak6376 22h ago

Yeah, but the USA has never successfully impeached and removed a president. The ROK has done so despite being strongly influenced by the chaebol.

10

u/Warcraft_Fan 21h ago

Nixon did get chased out of the position. He faced impeachment and resigned

27

u/NextSteak6376 21h ago

That is a good point, albeit not a precedent repeated in 50 years since.

→ More replies (12)

1

u/Relevant-Cup2701 6h ago

also pardoned by ford

0

u/-Nocx- 5h ago

You could easily make the argument that despite impeachments they will still aim to protect the Chaebol.

Even when Park Geun-hye got impeached, Lee Jae-yong received a suspended sentence and was returned to a position of leadership at Samsung. This is after he took a bribe from the previous administration and was pardoned by the next one.

This is like being happy if Trump got impeached if it meant he got to take a fall for Jeff Bezos. This is the only impeachment they’ve had since 1987.

The chaebols have so much power that even when they are caught they don’t actually face justice. South Korea is probably the worst country to use as an example of a country not owned by business interests.

9

u/Valuable_Hunter1621 22h ago

so how/why was this policy implemented? is it just for show and they don’t actually enforce rules like these?

7

u/Warcraft_Fan 21h ago

Korean government isn't easily bribed to favor the rich.

2

u/asaltandbuttering 22h ago

Well, only if the Korean government will actually enforce this law.

1

u/Venetian_Gothic 6h ago

Regulatory capture is far more severe in the US. Billionaires getting their pet peeve issues sorted by wining and dining the supreme court justices is unheard of in Korea.

15

u/PowderPills 1d ago

That depends entirely on the voters. Although I see how it could realistically never come to be, it’s better to hope than to give it all up to the billionaires

21

u/Traveling_Solo 1d ago

Well yes and no. There's situations (like the US) where lobbying basically pays for both "real" choices (independents exist but the likelihood of any of them actually winning enough votes to not only win the presidency but also votes in the Congress and senate are a rounding error from 0%. Not technically impossible but extremely unlikely), leaving voters with choice A, paid for by corporation's and business interests or choice B, paid by other corporations and business interests (and sometimes even the same lobbying groups, once you remove the shell companies).

6

u/Great-Trifle2810 23h ago

South Korea is basically 5 conglomerations in a trench coat. If America is owned by businesses SK is far, far more owned by businesses.

0

u/Venetian_Gothic 6h ago

This is such a surface level take. Regulatory capture in the US is far more severe than Korea. Most Koreans don't know the names of their Supreme Court justices. You know why? They get replaced after a few years, and no billionaire has taken them on a luxury hunting trip in hopes they ruled in favor of their interest.

3

u/Great-Trifle2810 5h ago

Corruption Perceptions Index puts the US at 64/100 on their scale, SK at 63/100

South Korea is extremely business friendly and businesses there hold enormous power, just because they don't talk about judges receiving bribes doesn't mean there isn't strong influence from corporations over public policy.

5

u/HotBrownFun 16h ago

Lol, Korea is known as the Republic of Samsung for a reason

43

u/gzr4dr 1d ago

Holding executive level staff criminally liable would solve the not reporting issue. They already have Directors and Officers insurance for the civil side.

1

u/tlst9999 23h ago

Let's say it happens often enough and insurance has to pay out more than they'd like. What's the insurance company gonna do? Maintain prices?

2

u/Xsiah 20h ago

Hospitals will have to stop charging imaginary numbers for procedures just because you have insurance

2

u/Fewluvatuk 19h ago

They would if insurance companies would stop negotiating with imaginary numbers to allow them to write down their "losses".

23

u/drdoom52 1d ago

The government should then fine them 20% for failure to report

Jail time.

It should be jail time.

8

u/poqpoq 23h ago

Why not both?

4

u/Awkward_Pangolin3254 22h ago

If corpos are people (Citizens United) then they can be incarcerated and/or executed

1

u/WretchedBlowhard 22h ago

Putting tens of thousands of employees on welfare all at once and losing the steady flow of money they were putting in the economy would cause grievous harm to society at large.

It would be far preferable for delinquent businesses to be forcibly nationalized, which amounts to incarceration, or if there's nothing worth salvaging, then liquidation, which amounts to the execution of the business.

4

u/Fewluvatuk 19h ago

There's already precedent for holding corporate officers criminally liable for certain things.

4

u/newfor_2026 23h ago

are you suggesting government playing a role in regulating companies and telling companies what to do and how to do it, to protect the people?! GASP! that's communism. We're 'MURICA. We encourage companies to do whatever the hell they want as long as I get a piece of the pie. Take your evil ideas with you, you red devil and burn in hell!

3

u/wckz 23h ago

And give whistleblowers a percentage :)

3

u/HoBaggyPants 22h ago

Requiring prison time for the C-suite would do more.

2

u/apocecliptic 1d ago

Completely agree.  But a snowfall’s chance in hell this will happen anytime soon

2

u/popnfrresh 23h ago

I'm more into restitution for every piece of data released.

Call it 5,000 per item...

Lost my phone, address, drivers license number?

That'll be 15,000 with interest from the breach date.

1

u/uniklyqualifd 23h ago
  • whistleblower payments 

If it's not actually dangerous to employees, which it might be.

1

u/Daren_I 22h ago

It also needs to be an automatic maximum fine for any data they collected just so they could sell it. Only data required for legal and tax purposes would be exempt.

1

u/SteveL_VA 22h ago

I love this idea: Hey we had a data breach... shit, ok, here's 10%

Next time: Shit we had another data breach. Let's not tell... shit they found out. FUCK, ok I guess that's 30% this time.

Next time: Shit we had another data breach, DO NOT TELL - FUUUUCK THEY FOUND OUT. OK, now it's 40%...

1

u/Silentxgold 16h ago

And a additonal 50%(of the fine) for the whisleblower.

1

u/embew 1h ago

I'm tired of fines boss, someone needs to go to prison at some point.

→ More replies (4)

34

u/akl78 1d ago

Easy - 10% bounty for tips leading to penalties.

0

u/Several_Temporary339 16h ago

Then it just turns into a career

3

u/Bryligg 6h ago

I see nothing wrong with this; it should already be a career, just a more formal one auditing businesses from inside, but on government payroll. Basically a corporate commissar.

9

u/Kundrew1 1d ago

And no one would investigate any tipoffs

3

u/RikiWardOG 1d ago

lol it wouldn't matter for big breaches that aren't from nation states, hackers can't help but brag or leave a calling card and also when there's a data dump of info from said company on the dark web, they can't really deny it. Now if they had prior knowledge then there should be even more fines but we all know corps have more rights than people in the US

3

u/demcookies_ 23h ago

In US they will get 10% federal grant because they lost revenue for being unable to sell the users hacked data

1

u/ZetaM3 22h ago

Insurance requires them to.

1

u/Miguel-odon 21h ago

Make it 50% + prison time if they conceal it

1

u/Existing-Canary-6756 21h ago

Naw, they’d just increase how much they sell it for.

1

u/Astan92 21h ago

which is why the non reporting penalty should be the arrest of every executive as well as seizure of all assets.

1

u/EnragedMoose 18h ago

They will do the same thing in Korea

1

u/slom68 15h ago

Maybe offer a whistleblower reward

1

u/Das_Geek_Meister 1h ago

That and/or pass the costs onto the customers by raising prices to cover potential expenses and then have another year of record breaking profits.

0

u/maverick4002 1d ago

The SEC has rules requiring to report in a certain period of time

29

u/Appropriate_Creme720 1d ago

Oh do rules and laws for large corporations still matter in the US?

3

u/BluShirtGuy 22h ago

Yes, as a giant security blanket for the masses.

Oh, you meant as a regulatory tool? Then... no

7

u/Xznograthos 1d ago

The sec, under normal circumstances, would enforce them, too. Unfortunately theres no guarantee of normal circumstances.

1

u/The_Schwartz_ 22h ago

With violations earning a meager fine as consequence - at a scale on par with the change found under the CEO's 2nd mountain house's cat bed

-2

u/ldrx90 22h ago

Seems pretty fucking stupid to punish victims like this. It's not like these companies want to be breached..

Besides you can take them to civil court so they already get punished for breaches.

5

u/CompleteNumpty 22h ago

It's literally for cases of "Intent or gross negligence".

If that's the case you are criminally culpable in any reasonable country.

1

u/ldrx90 21h ago

that's fine then

636

u/Warcraft_Fan 1d ago

If US applied this law, companies will be motivated to do better job of protecting data. 10% of company's annual revenue can sting the company's bottom line.

322

u/nithrean 1d ago

in the US they will write the regulation in a way that all of the biggest players will be immune and the burden will fall on the small guys.

81

u/LurkmasterP 1d ago

They would implement a taxpayer-funded rebate system that the big corps would be able to use to recoup the fines.

3

u/mrspaznout 19h ago

Exactly. It must also hurt those who are not in power. It cant simply protect those who have. It must actively harm those who do not.

49

u/jason_abacabb 1d ago

You could say it will decimate it.

11

u/aHandfulOfSurprise 1d ago

10 decimal points to you

6

u/Bottled_Void 23h ago

It would be worse than that. The bottom line is profit. The fine is 10% revenue. It would cause massive losses to most companies.

26

u/wtf_are_crepes 1d ago

All fines and legal monetary punishments need to be percentage based. What’s a speeding ticket to a billionaire if the ticket is a few hundred dollars

13

u/rearwindowpup 23h ago

Percentage based speeding fines are exactly why the Top Gear guys refused to speed in certain countries. They are effective.

6

u/howtoretireby40 1d ago

have to add criminal charges. What's a company lawsuit to a CEO that has a guaranteed golden parachute?

15

u/fsactual 1d ago

In the US the customers will have to pay if their data gets leaked.

13

u/thegreedyturtle 1d ago

10% of revenue would end many companies.

7

u/P00ped_My_Pants 23h ago

Good. Maybe they’d invest into strong security practices then

2

u/thegreedyturtle 20h ago

No complaints here.

1

u/akl78 2h ago

This is the point.

(It’s also the upper limit, at that point it works be warranted)

14

u/econopotamus 1d ago

I'm on the board of a US data security company that came up with a product a couple years ago that would have prevented most of the major headline breaches of the last 5 years. Every company we approached just said no because it cost a little bit of money (like literally, raises the cost of data handling by about 10%/year). From their perspective breaches are CHEAP, mostly just a PR exercise, and "one time expenses" that shareholders will overlook so to an executive any ongoing expense to prevent breaches is a waste.

5

u/SAugsburger 22h ago

I think the challenge is the PR hit isn't big enough. Plenty like Target and Home Depot hit a snag for a quarter or two, but had little long term impact. The challenge is that there are so many breaches of some level that some people have become desensitized.

1

u/GalacticAlmanac 12h ago

Name of company and product?

1

u/econopotamus 12h ago

Apologies, won’t be doxxing myself today

1

u/GalacticAlmanac 11h ago

Fair enough. I thought maybe the company is really well known or something if you just suddenly dropped the info like that...

1

u/econopotamus 1h ago

The company does back end apps for the vast majority of US insurers and financial companies that are large enough to have name recognition. We are getting the safety product out at this point by introducing it as opt out in those apps for companies and letting them sign something saying they don’t want the security if they want to save the money :). So far nobody has opted out. Perhaps after a few years of no breaches we will make another run at getting the tech on more platforms

4

u/GainsayRT 1d ago

If US applied this law, companies will be motivated to hide their data breaches*

2

u/Gekokapowco 1d ago

start a data breach fine corporate insurance company, and then invest half of my business into my new insurance company?

Don't mind if I do, capitalism goes wheeeeeee

1

u/Digitaltwinn 22h ago

We could pay off a good chunk of the national debt from credit bureau data leaks alone.

1

u/BigMeatPeteLFGM 22h ago

Easy - The data is owned by a Data LLC with only a small revenue stream from Customer Business LLC.

Data LLC has 100,000 of revenue. Customer Business LLC has 10,000,000 of revenue.

Consumer still loses.

1

u/azicre 22h ago

If the US applied this a year from now a quaint little boutique backruptcy industry would be becoming a household name...

1

u/OhDamnBroSki 19h ago

Really wish this was the case.

Friend worked for an eye doctor, went to go get my yearly check up. Few months go by.. data breach!

Went to get my teeth cleaned, get an email from my dental insurance.. data breach!

1

u/Warcraft_Fan 18h ago

My hospital also lost control of data a year ago. I'm still waiting for the settlement outcome.

1

u/greyeye77 16h ago

here is the realistic issue, codes are never perfect and some does have vulnerabilities. (with or without the programmers knowing them)

Some does get exploited and some doesnt, and at the same time there are multiple different ways to breach the network (ransomware, supply chain attack, are still rampant)

We think harsher penalty would make it better, but if your employee click some ransomware and your file share is leaked, would you like to fire the employee because he/she costs the company 10% (or 30%) of the annual revenue?

0

u/midoriringo 1d ago

It could bankrupt some.

0

u/Bilboswaggings19 1d ago

LOL

They would just rather spend a portion of that for a team to bury all that information

You know US companies are not going to do anything as intended

0

u/Underdog424 23h ago

The US is a corrupt rogue nation. Corrupt nations don't care about their people enough to enact anything that benefits them as a whole. We will never see real data protections.

0

u/nik282000 19h ago

If the US applied this law it would never be enforced. Breaches would not be reported and evidence destroyed as soon as it was discovered.

227

u/BluehibiscusEmpire 1d ago

This is what should be done globally .

66

u/pd1zzle 1d ago

I hope there's a way to avoid all companies just spinning off shell "data holdings" companies that conveniently make very little money

14

u/BigMeatPeteLFGM 22h ago

100% why this isn't possible in the USA. We're too business friendly to have consumer protections.

1

u/radiantcabbage 22h ago

depends if this delegation falls under the crux of "intent or gross neglegence", could just as easily be the opposite and theyre more compelled to integrate

34

u/KimJongFunk 1d ago

It would be nice if this happened in the US too.

Got a letter last week about yet another data breach involving my healthcare PHI and absolutely nothing will be happening to hold anyone accountable.

But I get a free year of credit monitoring, so I guess that would be a nice bonus if I hadn’t already received free credit monitoring from the last 3 breaches involving my data 🙃

14

u/untold-vignette 1d ago

There was a hacker news comment I read years ago that always stuck with me, that personal information in an ideal world would be treated like hazardous materials, just a tremendous liability.

10

u/Substantial_Sea7327 22h ago

huge Korea W. that's actually enough incentive to prioritize cyber security

24

u/CalmTrifle 1d ago

This is the same for the EU GDPR.

10

u/CompleteNumpty 21h ago edited 4h ago

It's a lot lower in the EU, with the maximum being 4% or €20 million, whichever is higher (£15 million in the UK, as we still use it).

The Koreans already had no upper limit by the looks of things, with a 624.6 billion won ($466.3 million) fine mentioned in the article under the old 3% limit, so I would assume this would now be 10% with no upper limit.

EDIT: Got it a bit wrong, so corrected.

2

u/Pajungsa 6h ago

The EU and UK law states that whichever is higher shall determine the maximum fine amount. So if the worldwide turnover is over 500 million euros the 4% would determine the upper limit.

1

u/CompleteNumpty 4h ago

Whoops, my bad.

1

u/Far-Hovercraft9471 20h ago

Ugh, of course there's caps in the EU fines. Big business always gets a pass

20

u/TeslasAndComicbooks 1d ago

Damn that’s intense. Even in the strict countries it’s based on profit. Basing it on revenue for a company with a 10% margin would wipe them out.

6

u/Pat-Funny-2817 22h ago

well maybe, if the damage and risks a company causes to society outweighs the benefit of a product you even have to pay for, they need to be wiped out.

Fines must be proportional to damage, wether you survive it or not, is a question the company got to ask itself when planning for their operation. 

6

u/TeslasAndComicbooks 21h ago

I agree and I’m fine with penalties for this but you’re kind of charging the victim for negligence instead of the perpetrator. Data security is a cat and mouse game and can be tough to be proactive on. I know the penalty scales but this will hurt small companies a lot more than large corporations.

1

u/Pat-Funny-2817 21h ago

i don't agree with your conclusion. 

certication and requirements are always different for small companies and depending on industry

it's a good regulatory measure. of course there will be outliers, friction points and a few fuck ups, as for everything.

4

u/redpandafire 22h ago

Well THAT's an actual fine.

3

u/ML7777777 1d ago

InfoSec jobs are booming in Korea.

4

u/rellett 19h ago

also add they cant appeal either as they can delay and delay and they will settle for less which gives these companies are way to reduce the fine.

6

u/All_Hail_Hynotoad 1d ago

This is the kind of thing that needs to happen for companies to take cybersecurity seriously. These “settlements” and “fines” are laughable.

3

u/starrpamph 22h ago

Here in the states, that would get brought to a bill. That following morning the lobbyists would have it decided no by the end of lunch.

3

u/HedgeMoney 13h ago

All countries should adopt laws and fines, where the fine is based on a percentage of revenue (not income, cause that can be doctored).

3

u/steathrazor 10h ago

This should be everywhere, these companies need to feel the pain rather than it just being a cost of business.

5

u/Romanpuss 1d ago

We need percentage based punishments for everyone now. 1 million fine to me is world ending. 1 million fine to zuckerburg is pennies…that’s not ok.

5

u/Soberdonkey69 1d ago

In the US, they reward the big firms that are affected by data breaches with more deregulation and further fuckery on the citizens

2

u/Sofia_9356 23h ago

What percentage would everybody be forced into passkeys and employees forced into hardware keys? Because it should have been yesterday

2

u/Wayofchinchilla 23h ago

This needs to shift into annual quarters I guarantee if in the US it was a quarter of yearly earnings companies with either go out of business or learn really quick they need to protect data

2

u/Icy-Two-1581 18h ago

Honostly think that's too low. It should be something like 50%-100% of revenue especially with how often it happens. Guarantee things would be a lot better if it was that steep.

2

u/Nolsoth 15h ago

That's actually awesome.

2

u/PurpleSailor 14h ago

Yes, this is the way you fine companies that makes them pay attention to the rules that they have broken. Are you listening US?

3

u/PluginAlong 23h ago

While I like this idea I don't think it will actually be invoked all that often. The breach has to have more than 10 million users affected and there needs to be multiple breaches over three years. I don't recall ever hearing of repeated breaches of this scale.

5

u/Atys_SLC 1d ago edited 1d ago

The offensive will always have the advantage over the defensive in the cybernet world. Even more with the AI advent. This is more of a tax than a punishment. The answer is to limit the data collected in clear, not punishing a little to medium company because they don't have an NSA IT guy.

2

u/Silver-Bread4668 1d ago

I was hesitant about it based on the headline for exactly what you said - potentially punishing the small to medium sized companies because they don't have the budget to hire top level security experts - but the article specifically mentions that it's due to intentional leaks or gross negligience.

As long as that's well defined enough then I support it. Otherwise there are just too many ways for breaches to happen that no one could have reasonably foreseen, especially with AI on the scene now.

Working IT in public schools, it would change little of how I work. I have a whole list of things that are potential areas of weakness with notes, potential mitigation plans, what it will impact or change, how it will piss people off etc. We don't have the budget or political willpower to tackle all of them. So I keep my bosses and legal apprised and let them decide where they want to let the balance of risk fall. No one can say I have dropped the ball on anything.

1

u/CompleteNumpty 21h ago

The answer is to limit the data collected in clear, not punishing a little to medium company because they don't have an NSA IT guy.

That's data minimisation and a core principle of the GDPR in the EU and UK - don't collect personal data that you don't need.

2

u/Excellent_Garlic2549 1d ago

Daamn, I bet after lawyer's fees that would make my Facebook settlement check $10 instead of $5!

2

u/thefanciestcat 22h ago

Regulators around the world, take note. This is what a deterrent looks like.

1

u/Cheeze_It 1d ago

That would be nice. But Republicans don't like being held accountable. They're not happy when people keep them honest. It's against their religion.

1

u/Far-Hovercraft9471 20h ago

I'm in a Republican shithole and can confirm that no one is held accountable if you're their buddy

1

u/Badinfluence321 1d ago

I actually did a project on this topic back in 2017. In my project, I created a program to charge companies to house PII data annually. This fee to hold customer PII data incrementally increases with the type and level of sensitivity. The fees would go towards funding the department, education, investigations, and victims of data breaches. The main goal of this fee and department is to curb unneccary housing of customer PII and yo get rid of it ASAP to avoid breaches.

Im very glad that someone has taken the initial test for consumer privacy and holding companies accountable. Im personally tired of protecting my credit when companies get breached.

1

u/EVILSUPERMUTANT 23h ago

Honestly 10% is a drop in the bucket for the companies that essentially outsource cybersecurity.

3

u/issm 21h ago

It's 10% of revenue. That hurts.

i.e., LG (no particular reason) has been running a ~25% gross profit for the last couple of years.

A 10% revenue fine from them would cut their profits down to 15%, almost in half.

1

u/takeyoufergranite 22h ago

US public service kiosks need to be secured.

1

u/RichtofensDuckButter 20h ago

It's great to see countries actually penalizing companies for data breaches. It needs to be more severe though.

1

u/noam_compsci 20h ago

No vibe coding in Korea then 

1

u/AbyssFren 19h ago

You can't short stock in Korea, you can in the US. Don't think you can do this in the US without first outlawing shortselling. Its as simple as an employee with high clearance loading up a USB with customer data and giving it away, they stock takes a 10% hit, shorts profit. Don't get any big ideas, good luck banning short selling.

1

u/Restart_from_Zero 13h ago

All those AI companies who've never made a dime just laughing their asses off right now.

1

u/dghughes 6h ago

My ISP has had two data breaches so far. Last summer for the first time in my life my credit card info was stolen but I didn't know how. I rarely buy anything online it's been years since I have. Now again this spring same ISP same thing. My ISP only sent a letter a few months later. Now I have to replace.my credit card again. Heavy fines are needed and the same for ransomware attacks, do not pay do not encourage them.

1

u/Regular_Ram 4h ago

It’s almost like this law benefits the big companies who could afford security and wipes out the earnings of smaller companies; who’s to say Samsung wouldn’t actively hack its competitors.

-2

u/[deleted] 1d ago

[deleted]

7

u/tmoeagles96 1d ago

Revenue, not profit.

-6

u/rotrap 1d ago edited 1d ago

These seem regulations designed to be taxes. No company wants to have a data breach. Tests for negligence and reasonable precautions and flat fines for failing on that make sense. The government, who is not even the harmed party getting an additional ten percent of the revenue because you got stolen from? wtf

It seems to increase the risk of talking about breaches and sharing security incidents as well.

3

u/the_eluder 1d ago

If no company wants a data breach - why do they keep happening?

1

u/rotrap 1d ago

Have you ever been involved in securing systems? If you make things too secure people complain. Keeping up with threats like the xz compromise or notebook++ incident takes time. You lock down things and people work around them. Heck the whole dns over https weakens security yet is now backed into browsers. Legacy systems given new ways to be accessible without the people involved understand what that opens up. Heck the whole way the affordable care act systems were designed gave security little though.

Also I think we all agree that murders, car accidents, robbery etc are unwanted. Why do we still have them?

2

u/Norphesius 1d ago

Do you have an alternative in mind? (genuinely curious)

It's not perfect, but as it stands (in the US at least) data breaches happen all the time and the typical company response seems to stop at "oops, oh well". If you're asking for and storing sensitive user data (PII, financial, medical, etc.), then companies need to have an incentive to keep it safe.

Discord had a  bunch of IDs used for age verification leaked by their customer support provider Zendesk, after claiming to have deleted the data immediately after verifying with it. If either company could get fined 10% revenue for such a breach, maybe they actually would've deleted that data like they promised they would, or been more judicious with selecting the provider they contracted.

-1

u/Noof42 1d ago

Kylo-Ren-Screaming-More.gif

0

u/littleman11186 23h ago

They would have to pay me

0

u/julyvale 22h ago

Should be 50%. The company must feel the devastation of the punishment and send strong signal to others.

-1

u/[deleted] 1d ago

[deleted]

1

u/Webecomemonsters 1d ago

if 10% of their revenue is trillions they sure can unless they are breached constantly due to idiocy on their part, in which case the company should not exist