SKorea credit card data theft highlights lapses

January 20, 2014 by Youkyung Lee
From left, NH Nonghyup Card head Sohn Kyung-Ik, Lotte Card CEO Park Sang-hoon and KB Kookmin Card CEO Shim Jae-oh, bow to offer an apology over a data theft during a news conference in Seoul, South Korea, Monday, Jan. 20, 2014. A massive theft of customer data from the three major credit card firms in the country has shown security lapses in the financial industry. Financial Services Commission Chairman Shin Je-yoon said Monday the credit card companies had failed to ensure adequate security. (AP Photo/Kim Ju-sung, Yonhap)

A massive theft of customer data from three major credit card firms in South Korea has shown security lapses in the financial industry.

First revealed by prosecutors, the theft of information linked to 80 million such as salaries, monthly card usage, credit rating and card numbers has sparked widespread public concern. Cardholders are flocking to bank branches and overloading call centers and service websites to find out if their information was stolen.

Local media said the theft may have affected most credit card holders in a country of 50 million people. Prosecutors and the financial regulator said no financial losses have been reported.

Financial Services Commission Chairman Shin Je-yoon said in a statement Monday that the credit card companies had failed to ensure adequate security.

The chief financial regulator urged the companies to be vigilant about data theft not only by hackers but also by employees and contractors. South Korean financial firms, media companies and governments have fallen victim to cyberattacks in the past with local authorities blaming North Korea as a culprit in some cases.

But the latest data breach exposed how confidential was poorly managed by financial firms.

Prosecutors said last week that an employee of Korea Credit Bureau, a contractor, stole the data beginning 2012 by copying data to a USB device.

Prosecutors said the worker, who was responsible for the development of new software to detect , sold the data to a loans company.

The stolen data from Lotte Card and the credit card units of KB Financial Group and NongHyup Bank was unencrypted, according to Cho Sung-mok, a director at the Financial Supervisory Service.

He said the companies were unaware of the theft until prosecutors began an investigation.

NongHyup Bank's card division did not notice the data breach for more than a year while KB was unaware for over six months.

Chiefs at credit card firms apologized and authorities have vowed to beef up security measures.

Explore further: Target: 40M card accounts may be breached (Update 2)

Related Stories

Target: Customers' encrypted PINs were stolen

December 27, 2013

Target said Friday that debit card PIN numbers were among the financial information stolen from millions of U.S. customers who shopped at the retailer earlier this month.

Neiman Marcus is latest victim of security breach

January 12, 2014

Luxury merchant Neiman Marcus confirmed Saturday that thieves stole some of its customers' payment card information and made unauthorized charges over the holiday season, becoming the second retailer in recent weeks to announce ...

Recommended for you

Nevada researchers trying to turn roadside weed into biofuel

November 26, 2015

Three decades ago, a University of Nevada researcher who obtained one of the first U.S. Energy Department grants to study the potential to turn plants into biofuels became convinced that a roadside weed—curly top gumweed—was ...

Glider pilots aim for the stratosphere

November 20, 2015

Talk about serendipity. Einar Enevoldson was strolling past a scientist's office in 1991 when he noticed a freshly printed image tacked to the wall. He was thunderstruck; it showed faint particles in the sky that proved something ...


Please sign in to add a comment. Registration is free, and takes less than a minute. Read more

Click here to reset your password.
Sign in to get notified via email when new comments are made.