A Korean card issuer stopped taking new customers today, under the first business suspension its financial regulator has imposed over a hacking incident
The suspension started today.
South Korea's Financial Services Commission decided on Friday to stop Lotte Card issuing cards to new members for a month and a half, and to fine the company 5 billion won, over a hacking incident the company reported to the financial authorities on 1 September last year. The commission's release puts the credit information taken at 2.97 million customers. It also records something the sanction itself has never carried before, which is that this is the first business suspension imposed for a hacking incident.
What the inspection says it found
Lotte Card notified the authorities in September. The Financial Supervisory Service inspected from September to October, and the commission's account of that inspection lists three failures in the operation of the company's online payment system: patch work on the information processing system was not carried out, resident registration numbers and passwords were not encrypted, and virus vaccine software was not installed.
Those are the grounds cited under the Specialized Credit Finance Business Act and the Credit Information Use and Protection Act. The 5 billion won penalty is imposed under the second of them.
The length is the negotiated part
A month and a half is a specific number and the release explains where it came from. The commission says it weighed equity with existing sanction precedents, the company's remediation work after the event, and the effect on the financial market and on financial consumers, and arrived at one and a half months. The company made representations before the decision, and a subcommittee took the item first.
So the precedent is the suspension existing at all. The duration is the part that was argued.
Who is actually stopped
Nobody who already holds the card. The order confines itself to new members, on the stated reasoning that customers who bear no fault for the leak should not be the ones inconvenienced by the remedy.
Existing holders keep card payments, limit increases, renewal and replacement issuance, card loans, cash advances and revolving credit, and the attachment states they may start a card loan or a revolving balance even if they never signed up for one. New members cannot be issued a credit card, a check card or a prepaid card until 16 September. The exceptions are narrow and named: several public purpose cards, including a Busan subway card for older residents and a card for serving military personnel, plus corporate cards and staff welfare cards issued to employees.
Anyone whose application was completed by Friday still gets the card.
The number that is not 5 billion won
The last paragraph of the release is about what comes next rather than what happened. The commission says it will support passage of an amendment to the Electronic Financial Transactions Act that would introduce punitive penalties of up to 3 percent of total revenue for serious security incidents, and would strengthen the authority of the chief information security officer inside a regulated firm.
That is a different order of magnitude from the fine it has just levied, and the release places the two side by side deliberately.
Why this is running late
The resolution was taken on Friday afternoon in Seoul and is roughly two days old. It runs now because the order took effect this morning rather than on the day it was decided, because the operative document is the five page attachment rather than the announcement, and because that attachment has not been read out in English anywhere this desk can find.