Two South Korean payment gateway (PG) companies were hit by hacking attacks that exposed tens of thousands of sensitive payment records, including credit card numbers and expiration dates. The Financial Supervisory Service (FSS) has launched on-site inspections of Toss Payments and Coem Payments, and the attacker is believed to be a Chinese hacker. Particularly striking is that the hacker reported the breach to government agencies before either the affected companies or regulators were aware of it, raising concerns about the overall security framework.
According to financial authorities on September 9, the FSS converted its preliminary on-site review of the two PG companies into a formal inspection that day. A senior FSS official said, “We were conducting an on-site review of the two PG companies and converted it into a formal inspection starting today.”
The suspected leaked information amounts to thousands of records per card issuer, totaling tens of thousands overall, with customer data from nearly all South Korean card companies partially compromised. The data obtained by the hacker reportedly includes cardholder names, card numbers, expiration dates, and the first two digits of card passwords.
Breach Path and Scope of Damage
According to a notice posted on Coem Payments’ website, the hacking attack occurred between 8:13 a.m. on August 30 and 5:34 a.m. on September 1. The company became aware of the incident at 8:00 a.m. on September 2.
Coem Payments stated, “We currently do not possess the individual transaction details and card information acquired by the attacker, so we cannot yet identify the specific transactions and data subjects affected.” The company added, “Given the structure of payment request messages processed in the compromised system, card numbers and expiration dates may have been included, and for certain payment methods, birth date-related information and the first two digits of card passwords may also have been included. We are working with relevant agencies to confirm the exact details.”
In the case of Toss Payments, a merchant client is believed to have been the target of the hacking attempt. According to Toss, an external party presumed to be a hacker queried payment records of shopping mall customers, but no evidence of data exfiltration has been confirmed to date.
Financial authorities are paying close attention to the fact that the hacker targeted vulnerable points in the payment network — relatively small PG companies — rather than directly attacking card issuers’ computer systems. PG companies act as intermediaries between online merchants and card issuers. This case demonstrates that even when large financial institutions maintain robust security, customer information can still be compromised if relatively vulnerable vendors connected to the payment network are breached.
Hacker Reported the Breach First
A particularly notable aspect of this incident is that the hacker alerted authorities to the breach before financial regulators and the affected companies had detected it. The Chinese hacker, claiming to have attacked multiple South Korean companies, directly reported the victims and the information obtained to the Financial Services Commission, the FSS, the Ministry of Science and ICT, and the Korea Internet & Security Agency (KISA).
The list of victims reportedly includes not only financial-related companies such as PG firms but also numerous small and micro businesses. Financial authorities and some affected PG companies were reportedly unaware of the breach until the hacker’s tip-off. The FSS launched an investigation based on the report and is cross-referencing the information provided by the hacker with actual PG and card issuer customer data to verify whether the leaked information indeed originated from this breach.
However, financial authorities caution that it is premature to definitively identify the attacker as Chinese. An FSS official said, “Based on IP address tracing so far, the attacker is presumed to be of Chinese origin, but given the many ways to route around IP tracking, it’s difficult to say with certainty.” The government and relevant agencies are currently proceeding with the investigation under the working assumption that the attacker is Chinese, examining the exact infiltration path and the scope of damage at each company.
Preventing Secondary Damage and Inspection Focus
With card numbers, expiration dates, and partial passwords leaked, the possibility of secondary damage such as fraudulent overseas transactions cannot be ruled out. Financial authorities and the industry have activated fraud detection systems (FDS) to intensively monitor suspicious transactions and prevent further damage.
The FSS is expected to use the on-site inspections to closely examine the scope of the data leak and the specific breach path, while also verifying whether the PG companies properly stored and managed card information. The adequacy of information security systems and internal controls is likely to be a key focus.
An FSS official said, “We are conducting on-site inspections because there have been cases where cardholder names and card numbers were leaked through PG companies. Some PG companies have already issued public notices, and we plan to ensure they take necessary measures, including notifying customers sequentially as additional facts are confirmed.”
AI Lowers the Barrier to Hacking
The financial sector is watching this incident closely in the context of evolving cyber threats driven by the spread of generative AI. AI can assist with vulnerability discovery and the analysis and writing of attack code, enabling hackers with relatively low expertise to increase the speed and efficiency of their attacks. The financial industry considers it plausible that AI was used in the Chinese hacker’s attack process.
A particular concern in the financial sector is that as AI lowers the barrier to entry for hacking, small and mid-sized financial firms and their vendors — which have relatively limited security investment and defensive capabilities — could become prime targets for hackers. There are also observations that certain Chinese AI models, such as DeepSeek, may have less effective guardrails in restricting user requests that could be leveraged for unethical and malicious purposes, including hacking.
A financial industry source said, “In the past, the main threats came from organizations with advanced hacking capabilities or state-backed actors. Now, with the spread of generative AI, an environment is emerging where mid- and low-skilled hackers can rapidly enhance their attack capabilities.” The source stressed, “Breach incidents through security-vulnerable points such as small and mid-sized financial firms and their vendors could increase, so it is urgent to develop countermeasures, including enabling these entities to leverage AI for their own security.”
Click Here For The Original Source.
