Financial Supervisory Service Inspects Two PG Companies, Including Toss and Coem Payments
Card Numbers, Expiration Dates, and Portions of PINs Also Leaked
Authorities and Victim Companies Unaware... Chinese Hacker Disclosed the Breach First

Financial authorities have launched an inspection after confirming that a Chinese hacker attacked domestic electronic payment gateway (PG) companies, resulting in the leak of tens of thousands of credit card records. The suspected leaked information amounts to thousands of records per card issuer, totaling tens of thousands of records overall, and it has been determined that some customer information from nearly all card companies has fallen into the hands of the hacker.


[Exclusive] Card Numbers and Passwords Stolen Without Detection... FSS Conducts On-Site Inspection at Two PG Companies After Tens of Thousands of Card Records Leaked View original image

In particular, the hacker not only targeted PG firms, but also simultaneously attacked various domestic companies. There are rising concerns within the financial industry that the hacker may have utilized generative artificial intelligence (AI). Given the rapid advancement of AI, some worry that hackers can further enhance their capabilities and regularly exploit the weakest links in the security chain.


Card Number, Expiry Date, Even PIN Leaked... Financial Supervisory Service Conducts On-site Inspection at Toss Payments and Two Other PG Firms

According to financial authorities on September 9, the Financial Supervisory Service is currently conducting on-site inspections at two PG companies affected by the hacking attack: Toss Payments and Coem Payments. The financial watchdog is reportedly focusing on scrutinizing the current status of the information leak and the specific routes of the breach.

[Exclusive] Card Numbers and Passwords Stolen Without Detection... FSS Conducts On-Site Inspection at Two PG Companies After Tens of Thousands of Card Records Leaked View original image

An official from the Financial Supervisory Service stated, "We are carrying out on-site inspections because there have been cases where the cardholder's name and card number were leaked through PG companies," and added, "Some PG firms have already disclosed the relevant facts, and as we further understand the situation, we will ensure that the PG companies take appropriate action, such as sequentially notifying customers."


Financial authorities are paying particular attention to the fact that, in this incident, the hacker did not attack the card companies' networks directly, but instead targeted vulnerable points within the payment network at relatively smaller PG companies. PG companies act as intermediaries between online merchants and card issuers. The data obtained by the hacker included sensitive payment information such as the cardholder's name, card number, expiration date, and the first two digits of the PIN. The suspected leaked information is spread across most card companies, with thousands of cases per company.


Given that card numbers, expiration dates, and even part of PINs have been leaked, authorities do not rule out the possibility of secondary damages such as fraudulent transactions overseas. In response, both the financial authorities and the industry have activated the Fraud Detection System (FDS) to closely monitor suspicious transactions and prevent further damage.


Through the on-site inspection, the Financial Supervisory Service is also expected to investigate whether PG companies have been properly storing and managing card information. Accordingly, the adequacy of their information protection systems and internal controls will also be central issues in the investigation.


[Exclusive] Card Numbers and Passwords Stolen Without Detection... FSS Conducts On-Site Inspection at Two PG Companies After Tens of Thousands of Card Records Leaked View original image

Victim Companies Unaware of Hack—Chinese Hacker First to Report the Breach

One particularly notable aspect of this incident is that the hacker reported the breach before either the financial authorities or the affected companies became aware of it. The Chinese hacker reportedly contacted the Korea Internet & Security Agency (KISA) and others, directly sharing information about the attack and the compromised data. The list of victims reportedly includes not only financial companies such as PG firms but also numerous small and micro businesses.


It is known that until the hacker’s report, financial authorities and some of the affected companies, including PG firms, were unaware of the breach. Based on the tip-off, the Financial Supervisory Service began investigating the extent of the damage and is comparing the information provided by the hacker with actual customer data from PG firms and card companies to verify the leak.


The government and related agencies have now identified the attacker as a Chinese national and are continuing their investigation into the precise breach routes and the scope of damages for each affected company.


Are Hackers Targeting the "Weakest Link"—Low Entry Barriers to Hacking Due to AI

The financial industry is closely monitoring this incident as it reflects changing cyber threats amid the spread of generative AI. Since AI can assist with vulnerability discovery as well as attack code analysis and generation, even hackers with less expertise can now enhance the speed and efficiency of their attacks. The possibility that AI was leveraged in the attack by the Chinese hacker is also being given significant consideration within the financial sector.


The major concern is that as AI lowers the barrier to entry for hacking, small- and medium-sized financial institutions or subcontractors with relatively weaker security investment and defense capabilities can become prime targets for hackers. Even when major financial firms have robust security defenses in place, this incident demonstrates that customer data can still be leaked if a connected but weaker company, such as a PG firm, is compromised. Additionally, there is criticism that the effectiveness of guardrails (safeguards) put in place in some Chinese AI models, such as DeepSeek, to restrict responses to unethical or malicious requests—including hacking—may be limited.


A source in the financial industry commented, "In the past, the main cyber threats were from highly skilled hacking groups or state actors, but now, the spread of generative AI is creating an environment where even low- or mid-skilled hackers can rapidly enhance their capabilities." The source emphasized, "With hacking incidents expected to increase through relatively insecure small- and medium-sized financial companies or partners, it is urgent to develop countermeasures that support these firms in adopting AI for their own security as well."



This content was produced with the assistance of AI translation services.

© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.

Today’s Briefing