FSC Launches Emergency Security Inspection of PG Operators After Toss Hacking... "Thorough Preparation for AI Hacking Threats"
Emergency Review of Response Systems After Toss and CoM Payments Hacking
Minimizing Data Collection by PG Operators and Strengthening Coordination with Card Companies
The financial authorities have launched an emergency inspection of security risks in the payment gateway (PG) sector after recent hacking incidents led to the leakage of credit card information from electronic payment companies such as Toss Payments. Amid growing concerns that artificial intelligence (AI) technology may be misused for hacking and other illegal activities, the authorities intend to ensure that financial firms are thoroughly prepared to respond to security threats leveraging frontier AI.
On September 16, the Financial Services Commission held its 6th Frontier AI Emergency Response Team meeting, presided over by Yoo Youngjun, Director-General of Digital Finance Policy. The meeting reviewed recent hacking trends in the financial sector, examined the security risks faced by PG operators, and discussed future response measures. Representatives from the Financial Supervisory Service, Financial Security Institute, Credit Finance Association, Fintech Industry Association, credit card companies, and PG operators attended the meeting.
This meeting was prompted by hacking incidents at two PG companies—Toss Payments and CoM Payments—in which tens of thousands of payment records were compromised. PG operators act as intermediaries for electronic transactions between card companies and merchants, handling personal and payment information. Therefore, security breaches can result in data leaks or fraudulent card transactions, leading to consumer damage.
On this day, authorities focused on reviewing the current status of the retention and management of personal credit information in the PG sector, major types of security breaches, and response systems in the event of information leakage. In particular, there has been a recent surge not only in attacks exploiting vulnerabilities in the PG companies' own systems, but also in indirect attacks exploiting the weaker security of merchants connected to the PG service.
Participants in the meeting agreed that it is essential to strengthen detection and response systems that encompass not only the internal systems of PG companies but also external points such as merchants. They also pointed out that to minimize secondary damages caused by information breaches, the scope of information collected and processed by PG operators should be kept to the minimum necessary.
It was also decided to enhance coordination among PG operators, card companies, and supervisory bodies such as the Financial Supervisory Service and Financial Security Institute when an incident occurs. Participants concurred that credit card information leaks need to be quickly shared, registered with the fraud detection system (FDS), and subjected to intensified monitoring for fraudulent transactions. In addition, measures to protect consumers—including customer notifications, card reissuance, and compensation—should be implemented promptly.
Director-General Yoo stated, "Since PG operators process large volumes of personal credit information and are connected to many financial companies and merchants, rigorous security measures are crucial. In the event of a security breach, close cooperation with card companies and related agencies is essential to enable immediate actions to prevent consumer harm, so we must continually review and supplement response systems." He added, "Given the high degree of system connectivity in the financial sector through APIs for open banking and MyData, all participants in the financial ecosystem must focus on reinforcing security."
He also called for proactive responses to AI-based cyber threats. "With AI-powered security threats becoming a reality, the PG sector must be well-prepared to address such risks," he said, urging the sector to actively utilize emergency network separation regulation relief (expanded to include electronic financial vendors), financial AI security research institutions and support centers, as well as financial AI security guidelines.
Hot Picks Today
"They Really Might Take No.1"... Nongshim Narrows Gap with Japan from 9.2% to 1.9% in a Year, Closing In on Market Leader
- "KRW 161 Trillion Jackpot Ahead? This Stock Soared 33% While KOSPI Rose Just 3%" [Stock of the Week]
- Japanese "Short Sleeper" Who Claimed to Be Fine on 30 Minutes of Sleep a Day Caught Napping During Live Broadcast
- "Please Take Off Your Shoes"—From Crawling onto the Bed to Changing Habits, Young Americans Lead the Shift
- "The Clothes My Dad Used to Wear"... Ralph Lauren, Beanpole, and Hazzys See Sales Surge as MZ Generation Embraces the Trend
The Financial Services Commission plans to use this inspection as an opportunity to closely examine the security and consumer protection frameworks of the PG sector and identify and review necessary institutional improvements.
© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.