According to a report by Nikkei BP [1], it appears that another massive leak of personal information has occurred in South Korea. This has happened many times before, but this time even financial credit ratings were apparently leaked.
Leaks of personal information and card details are generally discussed mainly in terms of “safety (security),” such as their use in bank-transfer scams or fraudulent card transactions. This time, however, financial credit ratings were also leaked. The incident therefore goes beyond the mere disclosure of personal information, reaching further into people’s private lives and having a greater impact on privacy.
As for how the data leaked, this was not an external hacking attack. An employee of the security company responsible for building the fraud-detection systems used by 3 credit card companies apparently stole customers’ personal information from October 2012 to December 2013, a period of more than 1 years, and sold it to a list broker. For every 1 million people, the sale price was reportedly 60 million won (approximately ¥5.88 million). The list broker then resold the data. A set containing one person’s name, resident registration number, credit card number, expiration date, and PIN reportedly cost around 15,000 won (approximately ¥1,470). It was apparently easy to buy.
How the data was stolen
The method used to steal the data was simple. Pretending to be developing the system, the employee accessed the database of customers’ personal information, copied the data to his own USB flash drive, and took it away. This raises several issues.
Failure to minimize data access (Violation of Data Minimization principle)
This employee’s task was to “build” the fraud-detection system. There was therefore no need whatsoever for him to be able to access the personal information database. In this incident, it appears that none of the three companies had an access-management system designed from this perspective. This means that ISO/IEC 29100 principle 4, “Data Minimization,” was not observed.
There are several possible countermeasures. First, there is the question of why a developer was accessing the production environment. Developers, deployment personnel, and operations personnel must be separated; otherwise, controls become difficult to enforce.
Next is the access control mentioned above. There are 2 aspects to this. The first is basic identity and access management (IAM): managing the identities of the people who access the system and imposing policy-based access restrictions. This alone could have prevented this incident.
Next is data encryption. Although this is not directly related to the present incident, backup operators and others must not be allowed to handle plaintext data. At a minimum, data used for backups must therefore be encrypted.
The fact that data could be written to a USB device is also a problem. In practice, however, the controls described above would have been sufficient, so this is probably a secondary countermeasure.
Ineffective monitoring
In this case, unauthorized access to the data continued for 1 years. Yet none of the companies detected it during that period. This means their monitoring was ineffective. That said, in this particular case they were in the very process of building a fraud-detection system, so to some extent this may have been unavoidable.
Lack of human resource security
ISO/IEC 27001 Annex A, section A.7, sets out human resource security requirements. In this case in particular, it appears that A.7.2.3 Disciplinary process was not functioning effectively. Conduct of this kind will eventually be discovered, at which point the offender will be punished. But if the expected cost of the punishment is lower than the expected gain from the crime, committing the crime becomes profitable and the incident becomes almost inevitable. Penalties can be criminal or civil, but the article does not say what penalties were in place. In any event, the gain from the crime was presumably considered greater. I am interested in what the wages and employment contract were like.
Incidentally, one reason banks employ staff on favorable terms is to make the expected loss of lifetime earnings caused by dismissal greater than the expected gain from crime. Such considerations may also be relevant for systems engineers.
Another possibility is that the employee joined the company with the intention of committing this crime from the outset. If so, ISO/IEC 27001 A.7.1 was likewise ineffective.
What happens next
According to the article, several measures are being implemented in response to this incident.
Financial Services Commission: formulation of “Measures to Prevent Recurrence of Customer Information Leaks at Financial Companies”
- Financial institutions that leak personal information will face surcharges of up to 5 billion won (approximately 400 million¥70 million) and suspension of operations for up to 3 months
- Financial institutions that use unlawfully leaked personal information for business purposes will face a punitive surcharge equal to 1% of their sales
- Restrictions will also be imposed on sharing customers’ personal information among affiliated companies
Financial Supervisory Service: “Measures to Block the Illegal Distribution and Use of Personal Information”
- Financial authorities (the Financial Supervisory Service and the Financial Services Commission), prosecutors, and police will jointly conduct an open-ended intensive crackdown on list brokers
- Brokers who are caught will face imprisonment of up to 5 years or a fine of up to 50 million won (approximately ¥4.9 million)
- The Financial Supervisory Service is considering establishing a center for reporting the illegal distribution of personal information and paying rewards of up to 10 million won (approximately ¥980,000) to people who report sellers of illegally obtained personal information or transaction sites and cooperate with investigations
It is unclear how much practical impact these measures will have. I would like to watch how the situation develops.
[1] http://business.nikkeibp.co.jp/article/world/20140128/258929/?P=1
Related posts
Information Leaked from The Asahi Shimbun via Winny
Personal Information Leaked from The Asahi Shimbun: Data on 170 Part-Time Workers Exposed via Winny On the 25th, The Asahi Shimbun Company announced that the personal…

Thoughts on the Benesse Personal Data Breach
It appears that children's and other personal data—up to 20.7 million records—was leaked[1] from Benesse. This is a thought-provoking incident in many respects. Let us consider…

Is It Dangerous When an “Identifier Number” Leaks?
We are entering a summer at the height of the My Number compliance bubble. How is everyone doing? As it happens, pension numbers have leaked on…
