Toss Payments: "No Fraudulent Payments Confirmed... Authorities Notified"

Toss Payments announced on September 9 that it had confirmed that payment records at one of its merchants using its online payment gateway (PG) services had been accessed by a third party.


4,131 Toss Payments Merchant Transactions Exposed... 2,671 Individuals Affected View original image

According to Toss Payments, it was found that a third party accessed payment records after authentication information (integration key) for the payment integration platform on the merchant's website was exposed.


The scale of the damage resulting from this incident has been confirmed as 4,131 payment transactions involving 2,671 individuals.


The accessed information includes the buyer's name, masked card number, and approval number. Card PINs, expiration dates, and security codes (CVC) were not included.


Toss Payments explained that the company's own system was not subject to hacking or vulnerability attacks.



A Toss Payments representative stated, "So far, there have been no confirmed cases of fraudulent payments," and added, "As soon as the incident was identified, we immediately blocked the compromised access path, notified the affected customers, and reported the situation to the Financial Services Commission and the Financial Supervisory Service."


This content was produced with the assistance of AI translation services.

© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.

Today’s Briefing