A hacker, whose identity remains unknown, has attacked a domestic electronic payment processing company (PG), raising concerns about a potential leak of credit card information. In response, financial authorities have initiated an on-site inspection.
According to the financial authorities on September 9, the Financial Supervisory Service (FSS) is conducting inspections at two companies, Coem Payments and Toss Payments. The inspections are focused on identifying the specific breach methods and the extent of the information leak.
An FSS official stated, "The hacker reported the incident to relevant agencies, including the Korea Internet & Security Agency (KISA), allowing us to understand the situation. We are currently investigating the scale and types of data that may have been leaked."
According to a notice posted on Coem Payments' website, the hacking incident occurred between 8:13 a.m. on August 30 and 5:34 a.m. on September 1. Coem Payments became aware of the breach at 8 a.m. on September 2.
While specific transactions and affected individuals have not been identified, there are concerns that the hacking attack on Coem Payments may have resulted in the exposure of card numbers, expiration dates, birthdate-related information, and even card passwords.
Coem Payments explained, "Due to the structure of the payment request data processed by the compromised system, it is possible that card numbers and expiration dates were included. In some payment methods, there is also a possibility that birthdate-related information and the first two digits of card passwords were exposed, and we are currently verifying the details with relevant authorities."
In the case of Toss Payments, it was revealed that authentication information for a merchant's website payment integration platform was exposed, allowing a third party to view transaction details. A total of 4,131 transactions were affected, involving 2,671 individuals.
The information accessed included the buyer's name, masked card number, and approval number, but did not contain essential payment information such as card passwords, expiration dates, or CVC codes. Toss Payments has blocked the route used for the information leak and has individually notified the affected customers.
A Toss official stated, "The authentication information (integration key) used for payment integration on the website of a specific merchant utilizing Toss Payments PG services was exposed, allowing a third party to access the merchant's transaction details without authorization. We immediately blocked the access route upon confirming the facts and reported the scope and details to the authorities. We will also cooperate fully with the ongoing inspections."
* This article has been translated by AI.
Copyright ⓒ Aju Press All rights reserved.