South Korea's financial authorities carried out an urgent check of security vulnerabilities and incident response systems at electronic payment gateway (PG) firms, where breaches have recently occurred in succession. They also discussed expanding management beyond PG firms' own systems to include indirect attacks via merchants with weak security. Measures to strengthen information sharing with card companies and consumer protection steps in the event of personal data leaks were also discussed.
The Financial Services Commission said on Sept. 16 it held the sixth meeting of the "Frontier AI situation response team" chaired by Yoo Young-jun (유영준), director-general for digital finance policy. Attendees included the Financial Supervisory Service, the Financial Security Institute, the Credit Finance Association, the Fintech Industry Association, 2 card companies and 4 PG firms.
The meeting closely reviewed recent hacking trends in the financial sector, the status of personal credit information held and managed by the PG sector, major types of breaches and response systems in the event of information leaks.
PG firms handle personal credit information such as names, dates of birth and payment information as they mediate payments between financial companies and merchants. The financial authorities judge that incidents could lead not only to information leaks but also to direct consumer harm such as fraudulent card payments.
Attack methods are also becoming more complex. Along with methods that directly target vulnerabilities in PG firms' own systems, indirect attacks that access PG systems through merchants with relatively low security levels are increasing. Participants agreed that PG firms need detection and response systems that cover not only their own security but also risks that could arise at external connection points.
Participants also discussed ways to reduce the scope of personal data collection. An opinion was raised that information processed by PG firms should be minimised and unnecessary or excessive collection reduced, as additional harm can occur without users noticing if card information is leaked.
Participants also discussed strengthening post-incident responses. If card information is leaked at a PG firm, they discussed quickly sharing related information with card companies so it can be reflected in fraud detection systems (FDS) and monitoring of fraudulent payments strengthened. They also agreed that follow-up protection measures should be carried out, including customer notifications, card reissuance and full compensation for consumer losses.
Authorities will also respond to hacking threats that use AI. Financial authorities plan to encourage PG firms to use relevant policies, after expanding eligibility so that electronic financial service providers can also participate starting with the second round of urgent regulatory easing measures on network separation.
Yoo said, "PG firms are smaller than financial companies, but they are connected to many financial companies and merchants and process large volumes of personal credit information." He added, "Response systems should be continuously checked so that, when a breach occurs, card companies and related institutions can work closely together and immediate measures can be taken to prevent consumer losses."