Financial Services Commission Establishes Legal Grounds for Information Sharing

Financial Security Institute Designated as Information Sharing and Analysis Institution

Going forward, financial, telecommunications, and investigative information suspected to be related to voice phishing will be consolidated at an information sharing and analysis institution, establishing a system in which relevant agencies can jointly utilize this information.


Suspected Voice Phishing Information to Be Consolidated for Joint Use by Financial, Telecommunications, and Investigative Agencies View original image

The Financial Services Commission announced on August 4 that the revised 'Special Act on the Prevention and Refund of Financial Damages Caused by Telecommunication-based Financial Fraud (Telecommunications Fraud Damage Refund Act)' and its enforcement decree have come into effect.


Until now, the AI-based Voice Phishing Information Sharing and Analysis Platform (ASAP) has been operated based on banking sector data since October last year. However, due to insufficient legal grounds for information sharing, there were limitations in utilization such as the main participating organizations being limited to financial institutions.


With this revision, financial companies, telecommunications firms, and investigative agencies will be able to provide suspected voice phishing information to the information sharing and analysis institution without the need for individual consent from information subjects. Participating organizations that share information include the Financial Supervisory Service, Financial Intelligence Unit (FIU), electronic financial service providers (prepaid providers), virtual asset exchanges, and the Korea Information & Communication Promotion Association.


These participating entities can utilize information and analytical results from other organizations to take prompt action such as blocking phone numbers used in crimes and aiding criminal investigations. Shared information includes victim-related and suspected scam account details and transaction history, account holder information, telephone numbers and user information suspected to have been used for voice phishing, information related to malicious applications (apps), and suspected fraudulent transaction detection data from financial institutions.


To ensure the legal stability of information sharing, partial exemptions have been made to certain provisions that restrict information provision, such as the Real Name Financial Transactions Act and the Credit Information Act. Instead, control measures such as data retention periods, disposal, and deletion procedures have been established to prevent misuse or abuse of personal information.


On this day, the Financial Services Commission designated the Financial Security Institute as the information sharing and analysis institution. The Financial Security Institute will take on the role of the information sharing and analysis institution, leveraging its experience operating ASAP and expertise in financial security. In line with the implementation of the law, system integration with telecommunications firms and investigative agencies has also been completed to allow immediate sharing of suspected information.



An official from the Financial Services Commission stated, "The second-tier financial sector will also actively provide information equivalent to that of banks, and telecommunications and investigative information will also be shared on ASAP, further strengthening our ability to respond to voice phishing." The official added, "We will continuously monitor ASAP’s operation and steadily advance the platform through integration of AI-powered pattern analysis and other enhancements."


This content was produced with the assistance of AI translation services.

© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.

Today’s Briefing