On Oct. 6, Toss Payments CEO Lim Han-wook (임한욱), third from left, waits to respond after appearing with other witnesses at a National Assembly Science, ICT, Broadcasting and Communications Committee audit. [Photo: Yonhap]

Toss Payments said it acknowledges shortcomings in its management related to a recent data leak and will expand the scope of security management and oversight to cover merchants.

Toss Payments CEO Lim Han-wook (임한욱) appeared as a witness on Oct. 6 at a National Assembly audit of the Ministry of Science and ICT by the Science, ICT, Broadcasting and Communications Committee.

Asked about the data leak, Lim said, "We also think there were insufficient parts," and added, "We are implementing various improvement measures to resolve this."

Earlier, Toss Payments said on Sept. 9 that payment information had been viewed externally at a specific merchant using its payment gateway service.

The company explained that an "integration key," authentication information used for a payment integration platform, was exposed on the merchant's website, and a third party used it to view the merchant's payment history. Toss Payments said it did not confirm hacking of its own systems, vulnerability attacks or intrusion attempts.

The number of confirmed views at the time was 4,131 payment records involving 2,671 people. The information viewed included receipt-level details such as buyers' names, masked card numbers and approval numbers.

Toss Payments said information needed for actual payments, such as card passwords, expiration dates and CVC codes, was not included, and that additional payments or cancellations were impossible with the information alone. It said there were no confirmed fraudulent payment losses at the time. The Financial Supervisory Service began an on-site inspection into the incident.

At the audit on the day, lawmakers raised criticism over whether Toss Payments' anomaly detection system worked properly during the incident.

Lee Jung-heon (이정헌), a lawmaker from the Democratic Party, asked Lim whether his view remained the same that the merchant exposed the integration key and was breached.

Lim responded, "No," and said, "We also think there were insufficient parts."

Lee also pointed out that "while the hacker was scraping payment receipts in large quantities, Toss' anomaly monitoring network did not operate even once."

Toss Payments said it is also implementing measures for relief and to prevent a recurrence.

Lim said, "For relief, the merchant is providing coupons and Toss Payments is directly providing cash-equivalent gift certificates," and added, "To prevent recurrence in the future, we are not only inspecting internal systems but also strengthening management and oversight up to merchants."

Toss Payments said it plans to inspect its internal security system and strengthen management and oversight of merchants in the wake of the incident.

Keyword

#Toss Payments #Lim Han-wook #Financial Supervisory Service #National Assembly #payment gateway
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.