기사 메일전송
Card and telecommunication hacking shocks continue... insufficient joint security system exposed
  • Yonhap News
  • September 18, 2025 at 11:58 AM
기사수정

Card and Telecommunications Hacking Incidents Cause Shock... Weaknesses in Joint Response System Exposed


Financial Sector Managed by FSC, Non-Financial by KISA... Vulnerable to Multi-faceted Hacking Response


Choi Soo-jin: "Integrated Cybersecurity Control Tower Needed"


'9.6 Million Members' Lotte Card Hacking Damage 'More Serious Than Expected''9.6 Million Members' Lotte Card Hacking Damage 'More Serious Than Expected' (Seoul=Yonhap News) Reporter Kim In-cheol = As the damage from the 'hacking incident' at Lotte Card, which has approximately 9.6 million members, is assessed to be much more severe than expected, speculation is emerging that the number of victims could range from hundreds of thousands to millions. The photo shows the Lotte Card headquarters in Jongno-gu, Seoul, on the 17th. 2025.9.17 yatoya@yna.co.kr


With large-scale hacking incidents occurring at Lotte Card following those at mobile carriers, calls are mounting for a government-level overhaul of the cybersecurity joint response system.


According to industry sources on the 18th, hacking and information leakage incidents in the financial sector are currently handled by the Financial Security Institute under the supervision and oversight of the Financial Services Commission (FSC). This is because the Financial Security Institute is designated as the incident response agency under the FSC's notice on electronic finance supervision regulations.


In contrast, security incidents occurring in the private sector outside of the financial industry are handled by the Korea Internet & Security Agency (KISA) under the Ministry of Science and ICT, in accordance with laws such as the Act on Promotion of Information and Communications Network Utilization and Information Protection, etc. and the Act on Information Protection Industry.


The problem is that while hacking damage occurs indiscriminately in both the financial and non-financial sectors, the oversight and response authorities are bifurcated, creating potential gaps in information sharing and initial response.


There are reports that in the early stages of the unauthorized small-value payment incident involving KT [030200], coordination regarding the responsible agency was not smooth due to the specificity of monetary damages incurred.


In the case of the Lotte Card hacking incident, while the FSC and the Financial Supervisory Service hold oversight and disciplinary authority, concerns are being raised about potential deficiencies in technical response capabilities such as incident cause analysis and digital forensics.


As of May, KISA had 133 incident response personnel, but it is unable to accept reports or conduct investigations into incidents occurring within financial companies.


Due to these structural limitations, the call for the establishment of an integrated cybersecurity control tower at the inter-ministerial level and for institutional improvements is growing.


Choi Soo-jin, a member of the National Assembly's Science, ICT, Broadcasting and Communications Committee from the People Power Party, emphasized, "There is a need to actively consider institutional improvements, such as mandating information sharing for hacking response among ministries like the Ministry of Science and ICT, FSC, Ministry of the Interior and Safety, and the National Police Agency, designating KISA as the technical analysis and international response window for all domestic hacking incidents, and shifting the FSC's role to focus on oversight and sanctions." Yonhap News



What do you think of this article?
recommend
0
great
0
moved
0
정기구독배너
Go to Mobile Site