Starting on the 4th, the Financial Services Commission will greatly expand the information-sharing system for combating voice phishing through the amended Special Act on the Prevention of Loss Caused by Telecommunications-Based Financial Fraud and Refund for Loss (Communications Fraud Refund Act). With telecom companies, investigative agencies, secondary financial institutions, and virtual asset exchanges joining ASAP, the voice phishing information-sharing platform that had been run mainly by the banking sector, a response that combines financial, telecommunications, and investigative information is expected to become possible.
ASAP has been operating based on banking-sector information since Oct. last year, but due to a lack of explicit legal grounds for information sharing, participation was limited to financial companies, creating limits on fully using information from related agencies.
In response, the government, together with the Office for Government Policy Coordination, the Ministry of Science and ICT, the Personal Information Protection Commission, the Korean National Police Agency, and other relevant ministries, has pursued establishing a legal basis for ASAP as a core task of the "comprehensive plan to eradicate voice phishing." As a result, an amendment to the Communications Fraud Refund Act that includes the basis for sharing suspicious information in the finance, telecommunications, and investigative fields passed the National Assembly on Jan. 15 this year.
Afterward, the Financial Services Commission, in consultation with related institutions such as financial companies, telecom companies, and investigative agencies, prepared an enforcement decree and subordinate regulations that set out the target institutions and scope of information to be shared, as well as the requirements and procedures for designating information-sharing analysis institutions.
The amended laws and regulations greatly expand the target institutions for information sharing and the items to be shared. They establish a legal basis that allows providers of suspicious information related to voice phishing—such as financial companies, telecom companies, and investigative agencies—to provide relevant information to the information-sharing analysis institution (the ASAP operator) without the individual consent of data subjects. Target institutions for information sharing include financial companies, telecommunications service providers, and investigative agencies, as well as the Financial Supervisory Service, the Financial Intelligence Unit (FIU), electronic financial business operators (prepaid issuers), virtual asset exchanges, and the Korea Information & Communication Promotion Association.
In addition, financial companies, telecom companies, and investigative agencies will not merely provide suspicious information unilaterally; they will also receive information provided by other institutions together with analysis from the information-sharing analysis institution, enabling use in emergency blocking of phone numbers used in crimes and in criminal investigations.
Information shared among institutions through ASAP includes account numbers, transaction histories, and account-holder information for accounts where damage occurred, accounts used for fraud, and suspicious accounts related to fraud; phone numbers suspected of being used for voice phishing and related user information; information on personal data collection programs such as malicious apps for voice phishing; and each financial company's detection information on suspected fraudulent transactions.
The amendment also includes explicit grounds to exclude the application of laws that restrict information provision, such as the Real Name Financial Transactions Act and the Credit Information Act, to enable swift information sharing among institutions. At the same time, to prevent the misuse or abuse of personal information, subordinate regulations established control measures such as retention periods and methods for destroying and deleting information.