HeadFlash

Privacy

GS Retail fined $9.3M over leak of 1.66M customers

South Korea fines GS Retail, a rushed school tool leaks records, Bandai's ring skips tracking, and ChatGPT reads iMessage threads.

Listen

This edition was produced with artificial intelligence. Text and voice are generated automatically.

South Korea fines GS Retail $9.3M over 1.66M-customer data leak

South Korea’s Personal Information Protection Commission fined GS Retail 12.8 billion won ($9.3 million) on Aug. 31 after an unidentified hacker infiltrated GS SHOP and the company’s convenience store chain between 2024 and 2025. The attacker repeatedly injected large numbers of user IDs and passwords to bypass login systems, compromising personal data of 1.58 million GS SHOP users and 79,128 GS25 customers. Leaked data included names, gender, dates of birth, contact numbers, home addresses, and email addresses. GS Retail operates GS25 convenience stores and the GS SHOP home shopping platform. The PIPC found that GS Retail failed to detect abnormal signs, including a sharp spike in login attempts and failures from identical IP addresses within a short time frame, which allowed the unauthorized access to continue undetected over a prolonged period. At the time, the company lacked a dedicated privacy-protection office. The PIPC ordered GS Retail to devise concrete preventive measures, such as advanced security policies capable of identifying abnormal connections, and to appoint dedicated privacy-protection personnel.

GS Retail fined $9.3 million over personal data leak of 1.66 million customers →

Treasury warned on rushed school tool before breach exposed 276 records

Treasury warned the Government not to rush the new school assessment tool months before a security flaw exposed the records of 276 students. The Student Monitoring, Assessment and Reporting Tool (Smart) runs twice-yearly reading, writing and maths assessments for Year 3 to 10 students. Smart was rolled out nationally on March 23, three days after final security sign-off. A security flaw made the records of 276 students accessible. The warning from Treasury and the timing of the rollout point to a compressed approval process for a system holding student assessment data. The incident shows the potential consequence of launching such a tool before the pace of the deployment has been fully assessed.

Treasury warned Government not to rush new school assessment tool before data breach →

Bandai’s Tamagotchi ring is a virtual pet wearable that doesn’t track you

Bandai has developed a Tamagotchi ring: a full-color virtual pet in a 28mm-tall, 23mm-wide wearable with a 0.56-inch display and the familiar three-button layout. It does not track the wearer; instead, the wearer cares for the creature on the ring. The device took two years to develop and uses 64 components, compared with 116 in Tamagotchi Paradise. It includes more than 30 Tamagotchi characters, including secret evolutions based on how well the pet is cared for. The ring charges through a dedicated charging case instead of an onboard charging port, a first for the Tamagotchi series. The ring is a little over half the height of the 1996 original, which measured about 50mm; Bandai’s first color model grew to 68mm in 2008 because the color screen required more power and larger batteries. In Japan, the Tamagotchi ring costs ¥7,700, about AUD$70, with release expected in February 2027. Australian retailer The Gamesmen has listed it at AUD$109.95, with availability currently slated for April 2027; Bandai has not said where it will be available in Australia. The original Tamagotchi launched in Japan at ¥1,980 in 1996, about AUD$22 then and roughly AUD$45 in today’s money, so the ring costs well over twice as much in inflation-adjusted terms. Bandai will offer the ring in pink, gold, and black.

Bandai Put a Tamagotchi in a $110 Smart Ring That Doesn’t Track You →

ChatGPT plugin can search Apple Messages, raising hidden-access concerns

OpenAI released a plugin in August 2026 that lets ChatGPT on Mac search Apple Messages directly, catch up on threads, summarize group chats, and send replies without copy-paste. The installing user must explicitly grant access, but everyone else in affected conversations has no way of knowing the plugin exists, according to OpenAI. One security researcher said: “Every person messaged through iMessage will never know a third party is inside that application, and will never be notified.” Critics are split: some reject the “spyware” label because the feature is off by default and requires consent, while even measured critics say enabling it introduces risk to a channel long treated as relatively private. OpenAI says the plugin reads messages only when a user’s request specifically calls for it, does not build a standing index of message history, and stores conversations locally on the Mac by default rather than uploading them to a server. The central objection is that one participant unilaterally decides on behalf of everyone in a conversation. A privacy-focused technology company’s analysis said exposure is not limited to ChatGPT users; someone who never opened the app or accepted a terms-of-service agreement can still have years of private conversations searched because the person on the other end allowed it. Unresolved questions include consent, liability, and the nature of AI-assisted exchanges.

When your AI reads someone else’s messages too - opinion →