Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Tracking & Law Enforcement

South Korean Credit Card Firms Punished for Data Leak

SEOUL – South Korean regulators Sunday suspended some operations of three credit card firms as punishment for the unprecedented theft of financial data on more than 20 million people.

SEOUL – South Korean regulators Sunday suspended some operations of three credit card firms as punishment for the unprecedented theft of financial data on more than 20 million people.

The country’s largest-ever theft of personal financial data from KB Kookmin Bank, Lotte Card and NH Nonghyup Card involved more than 40 percent of the country’s 50 million population.

South KoreaThe case provoked fury when revealed by prosecutors last month, with thousands flooding the firms’ branches for days to cancel credit cards or get new ones.

The three credit card companies will be banned from issuing new credit cards for three months until May 16, the Financial Supervisory Commission (FSC) said Sunday.

“These firms neglected their duties…to prevent the leak of customers’ information and (to comply with) internal controls,” it said in a statement.

Operations involving existing cardholders will be unaffected, the FSC said, adding each of the three firms will also be fined six million won ($5,640).

The data was stolen by an employee from personal credit ratings firm Korea Credit Bureau who once worked as a temporary consultant at the three firms. He was arrested last month.

The stolen data included names, social security numbers, phone numbers, e-mail addresses, home addresses, credit card numbers and even personal credit ratings.

Millions of affected customers have since cancelled cards or applied for new ones.

Advertisement. Scroll to continue reading.

Credit card usage is particularly high in South Korea, where the average adult has four or five cards.

The three-month ban on accepting new customers is the heaviest state penalty in the South’s competitive credit card market, where customers often switch cards to get more benefits or rewards.

Many major South Korean companies have seen customers’ data leaked in recent years, either by hacking attacks or their own employees.

An employee of Citibank Korea was arrested last December for stealing the personal data on 34,000 customers.

In 2012 two South Korean hackers were arrested for stealing data on 8.7 million customers at the nation’s second-biggest mobile operator.

In November 2011 Seoul’s top games developer Nexon saw the personal information on 13 million users of its popular online game MapleStory stolen by hackers.

In July the same year, personal data from 35 million users of Cyworld — the South’s social networking site — was stolen by hackers.

RelatedAngry South Koreans Flood Banks After Massive Data Leak

 

RelatedInsider Steals Data of 2 Million Vodafone Germany Customers

Written By

AFP 2023

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Shay Mowlem has been named CMO of runtime and application security company Contrast Security.

Attack detection firm Vectra AI has appointed Jeff Reed to the newly created role of Chief Product Officer.

Shaun Khalfan has joined payments giant PayPal as SVP, CISO.

More People On The Move

Expert Insights

Related Content

Cybercrime

Daniel Kelley was just 18 years old when he was arrested and charged on thirty counts – most infamously for the 2015 hack of...

Cybercrime

No one combatting cybercrime knows everything, but everyone in the battle has some intelligence to contribute to the larger knowledge base.

Cybercrime

The FBI dismantled the network of the prolific Hive ransomware gang and seized infrastructure in Los Angeles that was used for the operation.

Ransomware

The Hive ransomware website has been seized as part of an operation that involved law enforcement in 10 countries.

Privacy

Employees of Chinese tech giant ByteDance improperly accessed data from social media platform TikTok to track journalists in a bid to identify the source...

CISO Strategy

The SEC filed charges against SolarWinds and its CISO over misleading investors about its cybersecurity practices and known risks.

Cybercrime

A global cyber espionage campaign has resulted in the networks of many organizations around the world becoming compromised after the attackers managed to breach...

Cybercrime

A look into recent cryptocurrency tracing and recovery operations by the FBI and UK’s Metropolitan Police