my timesThe Korea Times

Lotte Card launches around-the-clock customer hotline following cyber breach

Listen

Financial watchdog orders full compensation for victims

Lotte Card headquarters in Seoul / Yonhap

Lotte Card headquarters in Seoul / Yonhap

Lotte Card will operate an around-the-clock hotline center to help relieve customer concerns over personal data protection and extend service hours to assist them, the card issuer said Wednesday.

The measure comes after the country's financial watchdog directed the company to immediately implement support for customers affected by a cybersecurity breach in mid-August. An estimated 1.7 gigabytes of customer data were compromised.

The card firm said the breach happened at 7:21 p.m. on Aug. 14, when hackers first infiltrated its online payment server.

The attack went on for two more days, during which files were exported twice. Another hacking attempt was made Aug. 16, but was reportedly unsuccessful.

However, the company was not aware of the breach until Sunday, 17 days after the initial attack.

Criticism mounted after it only notified the Financial Supervisory Service (FSS) on Monday, more than 24 hours after internally discovering the incident.

Lotte Card said it began operating an automated system at the call center to respond to data breach inquiries, and help customers set new passwords, issue new cards and close accounts.

It also provided mobile app links where customers can block overseas transactions.

However, account closure requests must be processed in person, after settling unpaid card spending, as well as any unused points and mileage.

Lotte Card also pledged to provide advanced compensation for fraudulent transactions caused by the data breach.

“We deeply apologize for the inconvenience this breach has caused,” the firm said. “We are strengthening monitoring efforts and mobilizing all available resources to protect our customers.”

FSS Gov. Lee Chan-jin on Tuesday called for an on-site investigation of the card issuer.

“This sheds light on how the IT sector of the financial sector remains vulnerable to hacking. Financial entities must take swift action to prevent similar incidents," Lee said.

Officials from the FSS and Financial Security Institute are in the process of identifying the source of the breach, its timeline and the volume of customer data stolen.

Lee said Lotte Card will fully compensate the affected users.

The FSS also urged all financial firms across the country to make sure their cybersecurity functions are robust and adequately maintained, warning that system failure due to negligence will be met with harsh penalties.