proomt

Search

Search posts, papers, and topics

All posts

Hacker News front pageNews Team3 min readintermediate

Korea raises data breach fines to 10% of revenue

Summary

South Korea’s privacy regulator will fine companies up to 10 % of revenue for large‑scale data breaches, a jump from the previous 3 % cap. The rule applies to intentional or grossly negligent leaks affecting 10 M+ people, with reductions for proactive security investments and rapid breach response. Companies must also notify users within 72 hours of a high‑risk exposure.

  • Fines rise from 3 % to 10 % of total revenue for breaches affecting ≥10 M users, or for repeat intentional/gross‑negligent violations.
  • Fine reductions of up to 40 % are available for companies with documented security budgets, staffing, and rapid breach containment/reporting.
  • New “potential breach” rule forces 72‑hour notification when a high likelihood of exposure is identified, even without confirmed loss.
  • Large firms (≥180 B won revenue) processing ≥1 M users’ data must get board approval for chief privacy officer appointments and report changes to the regulator.

The regime turns data protection from a compliance checkbox into a financial risk driver, forcing enterprises to budget for security tooling, staff, and incident‑response processes. Early breach detection and reporting now have a direct monetary incentive, which should shift investment toward preve…

3/10

Related reading

  1. Rate limits on GitLab.com are changing

    GitLab.com will tie API rate limits to subscription tiers: free users (and unauthenticated IPs) get 60 req/hr, while Premium/Ultimate get higher per‑user and per‑group caps starting Oct 19 2026 (free) and Jan 2027 (paid). Authenticated requests use the plan’s limits; hitting a limit returns 429 with Retry‑After. Preview “brownout” windows on Oct 7 and 14 let you test the new caps. If you need mor…

    Hacker News front pagegitlab.com4 minHN174127
  2. 1 points

    What Stripe data shows about fraud at AI startups

    Stripe’s data shows AI startups face far higher fraud rates than other startups—up to 4.3× more attempted transaction fraud and a 40% rise in multi‑account abuse over six months. The post explains these patterns and how Stripe Radar’s network‑wide signals can block fraud early in the customer lifecycle.

    Stripestripe.com3 minHN2
  3. Analyzing rising fraud attempts among travel and leisure businesses on Stripe

    Stripe analyzed payment data from over 200k travel and leisure merchants and found that fraud attempts surged globally in 2024‑2025, especially in APAC and EMEA, while the share of successful fraud after payment stayed flat. Their AI‑powered Radar blocked more than two‑thirds of attempts, intercepting $3 billion in fraudulent volume, and targeted rules helped specific merchants cut dispute rates…

    Stripestripe.com5 min
  4. September 16, 2026 security incident: how we responded to a LiteSpeed zero-day attack

    Hostinger detected a zero‑day exploit in LiteSpeed Web Server on a Brazil server on Sep 16 2026, giving the attacker root access and compromising 399 accounts. The team isolated the server, coordinated with LiteSpeed to patch the vulnerability, rolled out the fix fleet‑wide, and restored affected sites from backups within the same day.

    Hostingerhostinger.com2 minpostmortem