Sign up
Subscribe
Home / news / Toss Payments adds extra authentication after data leak as executives face South Korea audit
news

Toss Payments adds extra authentication after data leak as executives face South Korea audit

Toss Payments adds extra authentication after data leak as executives face South Korea audit

Toss Payments has introduced an additional authentication step for viewing sales slips and transaction history certificates after an external hack exposed payment information. The change matters because the leak was not just a security incident; it exposed a weak access model that let anyone with a link view payment details without separate authentication.

  1. Starting on the 30th of last month, Toss Payments added a new verification layer for links to credit and debit card sales slips and transaction history certificates. Before that, a link alone was enough to open the document. Now users must pass authentication using one of four methods: purchaser name and payment amount, email, card number, or approval number, payment amount, and payment date.
  2. The new control applies both to newly generated links and to existing links. In other words, this is not a forward-looking fix only; it closes off old links as well, which is the part PSPs usually care about when a disclosure turns into an operational headache.
  3. The leak came to light during the Financial Supervisory Service’s inspection of payment gateway (PG) firms such as Coem Payments. On the 7th, the FSS confirmed that credit information had been leaked, then moved two days later to an on-site inspection. During that process, it found that Toss Payments payment information had been leaked due to an external hacking attack.
  4. The incident affected 4,131 payment cases and 2,671 customers. Toss Payments said the attack was not a hack of its own system, but a leak of payment information from merchants using the Toss Payments PG service. The company said the exposed data was receipt-level payment details such as the buyer’s name, a de-identified card number, and an approval number, and said that with this information alone neither payment nor payment cancellation is possible. It also said there have been no confirmed cases of fraudulent payment to date.
  5. The Financial Supervisory Service is said to have recommended improvements to Toss Payments’ existing system, specifically the part that allowed access to sales slips and transaction history certificates with only a link and no separate authentication. Separately, Toss Payments executives are set to appear as witnesses at the National Assembly’s Science, ICT, Broadcasting and Communications Committee audit in connection with the incident.

For high-risk PSPs, the useful detail here is simple: link-based document access is a control gap until it is treated like one. Once payment data leaks through merchant-facing flows, regulators tend to look not only at the breach itself but also at whether the access model made exposure easier than it needed to be.

Weekly high-risk digest

Regulation, sanctions and payment news across your verticals — once a week, free.

Please check your inbox and click the link to confirm your subscription.

Please enter a valid email address!