"Merchant Breach Preceded Information Theft at Toss"... Financial Supervisory Service Probes Toss's Management Obligations Under Electronic Financial Transaction Act
Toss Denies "Direct Hacking,"
But "Hacker Extracted Payment Data from Toss via Merchant"
Key Issue: Compliance with Security Assurance Duty Under the Electronic Financial Transactions Act
Could Incident Become a Variable in Network Separation Reg
The Financial Supervisory Service, which is currently inspecting the credit card payment information leak incident at Toss Payments (Toss), a domestic electronic payment gateway (PG) provider, is focusing on whether the company complied with its 'security assurance obligation' under the Electronic Financial Transactions Act. Although Toss Payments maintains that its own system was not directly hacked, since actual payment information was leaked from the Toss side, authorities plan to hold the company accountable for management lapses if any violations are confirmed following the inspection.
As of September 10, according to comprehensive interviews with financial authorities and the banking sector, it has been determined that a Chinese hacker, who recently launched simultaneous attacks on domestic PG providers and public institutions, first attacked a Toss Payments merchant to obtain authentication information. The hacker is believed to have then used these credentials to access Toss Payments and extract payment information from its systems.
An official familiar with the financial authorities stated, "The security mechanism failed to function properly when the hacker accessed Toss Payments, and there were deficiencies in management as well. If no follow-up actions had been taken after the hacker's intrusion was reported, the situation could have escalated further," the official added.
Toss Payments claims that its own systems were not directly compromised. The company explained that authentication information (integration keys) necessary for payment integration was exposed on the merchant's website, and a third party used this to access the payment records of the merchant. It further stated that there was no indication of an intrusion exploiting vulnerabilities in its own systems.
However, the financial authorities believe that it is difficult to completely exempt Toss Payments from responsibility solely because the initial attack target was a merchant. Even if the authentication information was obtained from a merchant, since actual payment information was extracted from Toss Payments, the investigation is expected to strongly focus on whether the company's security system for detecting and blocking such incidents worked as intended.
Multiple officials from the Financial Supervisory Service said, "Through the inspection, we will confirm the actual intrusion route and the extent of information leakage, and check for any violations of the Electronic Financial Transactions Act and other relevant regulations."
The key issue is the obligation to ensure security under Article 21 of the Electronic Financial Transactions Act, which requires financial companies to exercise due care so that electronic financial transactions are handled safely. The crux of the matter is whether Toss Payments fulfilled its duty of care as a good administrator during the process in which the hacker attacked the merchant first and then extracted payment information from Toss Payments.
Since payment information was actually leaked, responsibility under the Credit Information Act could also be considered. According to a legal expert, "If credit card payment information was leaked due to hacking, another point of contention could be whether the company fulfilled its obligation under the Credit Information Act to adopt security measures for the protection of personal credit information."
Toss Payments also explained that the scope and scale of information leaked from its side was limited compared to another PG company, CoeM Payments, which was also attacked. According to a press release issued by Toss Payments the previous day, the number of payment records accessed in this incident was 4,131 cases, involving 2,671 customers. The information viewed included the buyer's name, masked card numbers, authorization numbers, and other transaction details. However, the information necessary to make unauthorized payments, such as card PINs, expiration dates, and CVC codes, was not included. This means the possibility of fraudulent payments is not present. In contrast, CoeM Payments experienced a much greater information leak; thus, since the scale of leaks at Toss Payments was limited to several thousand cases and the sensitivity of the leaked information was relatively low, some observers believe this may be taken into consideration in determining penalties.
However, within financial authorities, there is reportedly some discomfort with Toss Payments' emphasis on the fact that there was "no direct hacking" following the incident. Authorities believe that even if the initial credential information was leaked from a merchant, Toss Payments must recognize its substantial responsibility for information security. The fact that actual payment information was leaked from Toss Payments itself is viewed as a significant issue.
A financial industry source stated, "The Financial Supervisory Service shifted from on-site inspection on the 7th and 8th to a full inspection on the 9th after identifying possible violations. The prevailing sentiment among regulators is that, since Toss is expanding from fintech into broader financial services, it must take heavy responsibility for security incidents."
There is also an assessment that this incident could become a variable for Toss in the process of the authorities easing network separation regulations. The financial authorities are currently working to ease the network separation rule, allowing, for security purposes only, the use of external artificial intelligence (AI) and software-as-a-service (SaaS) solutions, and plan to extend these changes to the secondary financial sector and electronic payment service providers. By the end of the year, they are also considering a full lift of the network separation rule for financial companies with outstanding security and AI capabilities. Since a security incident has now occurred within a Toss affiliate, it is being analyzed that this could become a negative factor in the selection process for the network separation regulation exemption in the future.
Hot Picks Today
"Why Owners Spend Hundreds of Thousands to Replace Working Air Conditioner Refrigerant with the Old Type"
- "To Predict When AI Semiconductors Will Slow Down, 'Look Here': Korea Ratings Identifies New Risk Channel"
- Don Spike Announces Fresh Start After Release... "Reflecting on Mistakes from Four Years Ago"
- Jennie Faces Unexpected Backlash Over 'Year-Long Project' Launch: "Please Cut Ties"
- "The Flavor That Won Over Ahn Yujin" Now at Convenience Stores... 500,000 Units Sold Out in 5 Days, What's Behind the Craze?
Meanwhile, CoeM Payments, which joined Toss Payments as a target of the inspection following this hacking incident, is also facing scrutiny over the circumstances and legality of its handling and storage of payment information. CoeM Payments, reportedly not an eligible PG company, is believed to be restricted from retaining card information. Since highly sensitive data such as card numbers, expiration dates, and the first two digits of PINs was leaked in this incident, the financial authorities plan to thoroughly examine the company's information retention practices and management systems for possible violations of the Specialized Credit Finance Business Act and the Credit Information Act.
© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.