Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

Angry South Koreans Flood Banks After Massive Data Leak

SEOUL – Tens of thousands of South Koreans flooded banks and call centers Tuesday to cancel credit cards following the unprecedented theft of the personal data of at least 20 million people.

SEOUL – Tens of thousands of South Koreans flooded banks and call centers Tuesday to cancel credit cards following the unprecedented theft of the personal data of at least 20 million people.

Since Monday, more than 1.15 million victims of the country’s largest-ever leak of private financial information have cancelled their credit cards permanently or requested new ones, according to the Financial Supervisory Service (FSS).

The panic has its roots in the arrest earlier this month of an employee from personal credit ratings firm Korea Credit Bureau, on charges of stealing and selling data from customers of three credit card firms while working as a temporary consultant.

South Korea 

On Sunday financial regulators announced that at least 20 million people — in a country of 50 million — had been victims of the data theft.

The data stolen from the internal servers of KB Kookmin Card, Lotte Card and NH Nonghyup Card included names, social security numbers, phone numbers, e-mail addresses, credit card numbers and expiration dates.

The three firms deployed thousands of extra workers to branches and call centers to handle the complaints and cancellations that poured in when the extent of the scam became apparent.

“We’ve been totally overwhelmed for the past two days,” said one official at KB Kookmin Card.

Social networking sites and major Internet portals were deluged with complaints about the long wait at bank branches and problems with paralysed websites and call centers.

Advertisement. Scroll to continue reading.

“I tried the call centre for more than six hours with no success, and eventually had to go to the bank to wait nearly an hour to cancel my credit card,” said one NH Nonghyup customer.

“I’m at Lotte Card (office) to cancel my card. They say I have to wait six hours!” tweeted another angry customer, @casiopea1027.

All special call centers run by the three firms were busy Tuesday and some of their websites could not be accessed at all.

Dozens of their top executives have tendered their resignations, while the government is expected to announce special measures aimed at preventing a similar crisis in the future.

Regulators have launched investigations into security measures at the affected firms.

“We will hold them fully responsible for the data leak if their sharing of client data among affiliates and lax internal control turn out to be the cause,” FSS chief Choi Soo-Hyun was quoted as saying by Yonhap news agency.

President Park Geun-Hye has called for strong punitive measures against those responsible for the data theft amid growing concerns among customers that their information could fall into the hands of scammers.

The three firms have said they would fully cover financial losses if their customers fell victim to scams related to the latest data theft.

Official data showed more than nine million clients have logged on to the websites of the three firms to check whether their personal information was stolen.

Many major South Korean companies have seen customers’ data leaked in recent years, either by hacking attacks or their own employees.

An employee of Citibank Korea was arrested last month for stealing the personal data of 34,000 customers.

In 2012 two South Korean hackers were arrested for stealing the data of 8.7 million customers at the nation’s second-biggest mobile operator.

In November 2011 Seoul’s top games developer Nexon saw the personal information on 13 million users of its popular online game MapleStory stolen by hackers.

In July the same year, personal data from 35 million users of Cyworld — the South’s social networking site — was stolen by hackers.

Related: 20 Million People Fall Victim to South Korea Data Breach

RelatedInsider Steals Data of 2 Million Vodafone Germany Customers

Written By

AFP 2023

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Shay Mowlem named CMO of runtime and application security company Contrast Security.

Attack detection firm Vectra AI has appointed Jeff Reed to the newly created role of Chief Product Officer.

Shaun Khalfan has joined payments giant PayPal as SVP, CISO.

More People On The Move

Expert Insights

Related Content

Application Security

Cycode, a startup that provides solutions for protecting software source code, emerged from stealth mode on Tuesday with $4.6 million in seed funding.

Cybercrime

A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the...

Cybercrime

The changing nature of what we still generally call ransomware will continue through 2023, driven by three primary conditions.

Data Protection

The cryptopocalypse is the point at which quantum computing becomes powerful enough to use Shor’s algorithm to crack PKI encryption.

Cybercrime

As it evolves, web3 will contain and increase all the security issues of web2 – and perhaps add a few more.

Cybercrime

Luxury retailer Neiman Marcus Group informed some customers last week that their online accounts had been breached by hackers.

Artificial Intelligence

The CRYSTALS-Kyber public-key encryption and key encapsulation mechanism recommended by NIST for post-quantum cryptography has been broken using AI combined with side channel attacks.