Translating into Русский. The English version is shown until it is ready.
Tving, telecom and bank security chiefs face lawmakers at Korea cyber audit
Коротко
South Korea's National Assembly science and ICT committee audited the Ministry of Science and ICT on Oct 6, calling in executives from companies hit by data breaches. Tving CEO Choi Joo-hee appeared over a breach involving 39.54 million account records, while telecom and platform security chiefs were also questioned. Opposition lawmakers criticised the government's response to suspected AI-agent hacking at major banks, and the minister said the ministry would lead the response.
Читать полностью 3 мин чтения
South Korea's National Assembly Science, ICT, Broadcasting and Communications Committee audited the Ministry of Science and ICT on Oct 6, calling in executives and security officers from companies that have suffered data breaches and focusing on the government's response to recent cyber incidents. Asia Economy reported that the hearing opened with criticism over a series of suspected AI-related hacking incidents in the financial sector and demands for a rapid response. [ 2 , 3 ]
Tving CEO Choi Joo-hee appeared as a witness over a breach at the streaming company. Hankook Ilbo reported that a joint public-private investigation found the late-May incident exposed 39.54 million account records, including duplicates. According to the same report, the committee was expected to ask why Tving exposed access keys in source code or stored them without encryption, how it controlled access rights to development and operating environments, whether it recognised and fixed known vulnerabilities, whether its compensation of points and insurance matched the scale of the damage, and how it would schedule and measure promised increases in information protection spending. [ 1 ]
The chief information security officers of the three major telecoms also took the witness stand: Lee Jong-hyun of SK Telecom, Lee Sang-woon of KT and Hong Gwan-hee of LG Uplus. Hankook Ilbo reported that the committee intended to check whether the security measures the carriers announced after last year's incidents led to real system improvements, including whether higher security spending and more specialist staff shortened detection and response times. Witnesses also included Park Su-kyung of Duo, Hong Seung-il of Healing Paper, which runs Gangnam Unni, Lim Han-wook and Shin Yong-seok of Toss Payments, Kim Jin-a of Meta Korea, Kim Jung-hoon of Woowa Brothers and Brett Anthony Matthis of Coupang. [ 1 , 2 ]
Much of the political criticism concerned banks. Asia Economy reported that suspected AI-agent-related data leaks occurred at major commercial banks including Shinhan, KB Kookmin and Hana ahead of the audit, that the Financial Services Commission and Financial Supervisory Service are investigating, and that the Ministry of Science and ICT has run a 24-hour emergency response system. The report noted the financial sector falls under the National Assembly's Political Affairs Committee, but that lawmakers also questioned the responsibility of the science ministry and the Korea Internet and Security Agency as the bodies that oversee cyber incident response. [ 2 ]
Representative Choi Hyung-doo of the People Power Party said the ministry was treating the bank hacking as the financial regulator's business, arguing that inter-agency barriers that a cross-government information protection plan was meant to remove still exist, Seoul Economic Daily reported. Representative Seo Cheon-ho said the ministry should recognise its responsibility as the lead hacking-response body and criticised the absence of a government-wide response structure, according to the same outlet. [ 3 ]
Deputy Prime Minister and Science Minister Bae Kyung-hoon responded that the ministry would take the lead in managing and responding to breach incidents and in sharing information with companies and across government, Seoul Economic Daily reported. He said the ministry had increased its information protection budget by 44% year on year, that enforcement under the amended Information and Communications Network Act took effect on Oct 1, allowing on-site investigation even without a company's own report, and that punitive and economic sanctions would be strengthened. Asia Economy reported that Bae also said frontier AI model development and the “AI for All” service would proceed on schedule, with the service to be launched by the end of the year. [ 2 , 3 ]
Почему это важно
The hearing puts personal-data security practice at major Korean platforms, telecoms and banks under parliamentary scrutiny, and the committee is examining whether promised security investment and staffing produced real system improvements. It also tests how responsibility is divided between the science ministry, financial regulators and the Korea Internet and Security Agency at a time when AI-assisted attacks are being investigated in the banking sector.
Ключевые факты
- The National Assembly's Science, ICT, Broadcasting and Communications Committee held an audit of the Ministry of Science and ICT on Oct 6, focused on recent data breaches and cyber incidents. [ 2 , 3 ]
- A joint public-private investigation found that a breach at Tving in late May exposed 39.54 million account records, including duplicates, according to the Hankook Ilbo. [ 1 ]
- Tving CEO Choi Joo-hee attended the audit as a witness. [ 1 , 2 ]
- The chief information security officers of SK Telecom, KT and LG Uplus — Lee Jong-hyun, Lee Sang-woon and Hong Gwan-hee — attended. [ 1 , 2 ]
- Witnesses also included executives and security officers from Duo, Healing Paper (Gangnam Unni), Toss Payments, Meta Korea, Woowa Brothers and Coupang. [ 1 , 2 ]
- Suspected AI-agent-related data leaks occurred at major commercial banks including Shinhan, KB Kookmin and Hana ahead of the audit, with financial authorities investigating. [ 2 ]
- Opposition lawmakers said the ministry was shifting responsibility and that inter-agency silos remain. [ 2 , 3 ]
- Deputy Prime Minister and Science Minister Bae Kyung-hoon said the ministry would lead the response and that its information protection budget rose 44% year on year. [ 3 ]
Подтверждено несколькими источниками
- The science and ICT committee held an audit of the Ministry of Science and ICT on Oct 6 at which companies that suffered data breaches were represented by witnesses. [ 1 , 2 , 3 ]
- Tving CEO Choi Joo-hee and the chief information security officers of SK Telecom, KT and LG Uplus attended as witnesses. [ 1 , 2 ]
- Opposition lawmakers criticised the government's response to recent hacking incidents, including in the financial sector. [ 2 , 3 ]
- Deputy Prime Minister and Science Minister Bae Kyung-hoon said the ministry would take the lead in responding to and coordinating on breach incidents. [ 2 , 3 ]
Пока неясно
- Whether the banking-sector data leaks were actually carried out using AI agents. Asia Economy says the leaks are suspected to have used AI agents and that investigations by the Financial Services Commission and Financial Supervisory Service are ongoing; no document confirms the cause.
- How many customers or accounts were affected at each of the banks. Only Asia Economy mentions the banks, and it gives no figures.
- Whether the audit will produce binding measures on compensation standards and third-party data management. Hankook Ilbo frames this as an open question about whether the hearing will go beyond criticism; no outcome is reported.
Что пишут местные СМИ
Хронология, местное время
- Hankook Ilbo publishes a preview of the Oct 6 audit, listing the witnesses and the expected lines of questioning. [ 1 ]
- Asia Economy reports from the audit, including opposition criticism of the response to AI hacking in the financial sector. [ 2 ]
- Seoul Economic Daily reports further opposition criticism and the minister's response on budget and sanctions. [ 3 ]
- Amended Information and Communications Network Act takes effect, allowing on-site investigation when hacking signs are detected without a company's separate report. [ 3 ]
- The Tving breach occurs; a joint public-private investigation later finds 39.54 million account records were exposed. [ 1 ]