South Korea to Strengthen Measures Against Data Breaches After Major Incidents

Seoul: South Korea will revamp policies to enhance punishments for companies that fail to properly manage personal data while coming up with fundamental measures to prevent breaches by inducing businesses to expand investment in cybersecurity, the government said Friday.

According to Yonhap News Agency, Second Vice Minister of Science Ryu Je-myung made the remark during a joint press conference with the Financial Services Commission (FSC) following recent data breach cases at SK Telecom Co., KT Corp., and Lotte Card Co. Ryu emphasized that the science ministry, along with leading security experts, will conduct a comprehensive review of the existing security system to establish fundamental measures, rather than just temporary actions.

The announcement comes a day after President Lee Jae Myung instructed his aides to develop fundamental measures to minimize damage from hacking attacks. Ryu stated that the government aims to strengthen punishments for companies that intentionally delay notifying authorities of data breaches and to pave the way for launching investigations even without disclosure.

Ryu also mentioned that the government intends to introduce incentive measures to encourage businesses to voluntarily increase investment in security. Meanwhile, FSC Vice Chairman Kwon Dae-young highlighted the government's efforts to adopt punitive policies against companies experiencing security breaches by imposing fines that reflect the "consequences to society."

Kwon underscored the importance of collaboration among the government, financial companies, and related organizations in establishing a solid security system to avoid being trapped in hacking incidents as South Korea strives to lead in the artificial intelligence sector.

KT Corp. disclosed on Thursday that the number of victims of a mobile payment breach since early August has increased to 362, up from the initially reported 278, with total damage estimated at 240 million won (US$173,000). Lotte Card Co., the country's fifth-largest card issuer, also reported that personal data of approximately 3 million customers had been leaked in a hacking incident last month.

Kwon stated that the government will closely monitor and supervise Lotte Card to ensure it takes necessary protection measures for customers without delay. He added that if the FSC's investigation finds any violations, strong punitive measures will be taken to set an example.

In April, SK Telecom Co. reported that private data of its entire user base may have been leaked in a cyberattack on its network servers, with a hacking group allegedly attempting to sell client data through Telegram earlier this week.