South Korea's Financial Services Commission ordered Lotte Card to suspend parts of its business for 1.5 months and imposed a KRW 5 billion fine after hackers obtained the credit information of 2.97 million customers in August 2025. The suspension, the first imposed in South Korea over a hacking incident, runs from Aug. 1 to Sept. 15, 2026. An inspection found that Lotte Card had failed to patch information systems, encrypt resident registration numbers and passwords, and install antivirus software in its online payment environment. During the suspension, the company cannot issue credit, debit or prepaid cards to new customers, subject to limited exceptions such as public-purpose cards. Existing customers may continue using card services, obtain replacement cards, increase limits and apply for card loans, cash advances and revolving credit, but cannot receive additional new cards. The financial authorities will monitor the suspension's effect on consumers and support legislation introducing punitive fines of up to 3% of total sales for serious security incidents and strengthening the authority of chief information security officers.