[Photo: Toss]

Toss Payments said its systems were not hacked in connection with an incident involving the viewing of merchant card information. It said the incident occurred after authentication information for a payment integration platform was exposed at one merchant. The impact confirmed by the company was 4,131 payment records involving 2,671 people.

Toss Payments issued a statement on Wednesday to explain the facts regarding reports published that day about the viewing of merchant card information.

The company said the incident did not result from hacking or an attack exploiting vulnerabilities in Toss Payments' systems. It said a "linkage key," which is authentication information used for a payment integration platform, was exposed on the website of one merchant that uses Toss Payments' PG service. A third party used it to collect additional information and then viewed the merchant's payment records, it said.

Toss Payments said no attempted intrusion into its systems had been confirmed.

The company said the affected scope was 4,131 payment records at the one merchant and 2,671 individuals. Toss Payments said it notified all affected people of the incident.

Regarding some reports that raised a scale of "tens of thousands" of cases, the company said, "It differs from the figures we confirmed." It said payment information of other merchants, the Toss app, affiliate services and customer information were also unrelated to the incident.

The company said the information viewed was at the level shown on receipts, including buyer names, masked card numbers and approval numbers. It said information needed for actual payments, such as card passwords, expiration dates and CVC codes, was not included.

Toss Payments said that additional payments or payment cancellations were not possible based on the information viewed alone, and that no cases of damage such as fraudulent payments had been confirmed so far.

Toss Payments said, "Immediately after confirming the incident, we blocked the access route and analyzed all access logs to identify the affected subjects and scope." It added, "We have completed customer notifications and reporting to the Financial Supervisory Service and the Financial Services Commission, and we are cooperating with the ongoing inspection."

Keyword

#Toss Payments #Financial Supervisory Service #Financial Services Commission #Toss app #PG service
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.