As the possibility emerged that credit card information held by a domestic payment gateway (PG) company was leaked due to hackers believed to be Chinese, the Financial Supervisory Service launched an inspection.
Financial Supervisory Service (FSS) said on the 9th that it shifted to an inspection while conducting on-site checks of Coem Payments and Toss Payments.
According to Coem Payments, hacking attacks occurred between 8:13 a.m. on the 30th of last month and 5:34 a.m. on Sept. 1, and Coem Payments recognized this at 8 a.m. on Sept. 2. A Coem Payments official said, "There is a possibility that the leaked information included the card number, card expiration date, date of birth, and even the card PIN," and added, "We are confirming the exact details with the relevant authorities."
Regarding this, Toss Payments said, "This was not a hack of our system, but a leak of payment information from merchants that use the Toss Payments PG service," and added, "The leaked information is receipt-level payment details such as the buyer's name, a de-identified (masked) card number, and an approval number." It went on, "With this information alone, neither payments nor cancellations are possible, and there have been no confirmed cases of fraudulent payments to date."
Toss Payments has blocked the route used for the information leak and completed individual notifications to affected customers.
An Financial Supervisory Service (FSS) official said, "Tracking IP addresses and other data suggests they are Chinese, but there are so many IP-masking methods that it is hard to say for sure."