The Korean government is second to none when it comes to the speed with which it patches up a crisis. Barely five days have passed since the news broke out about the unprecedentedly huge theft of private data, but officials announced “comprehensive” measures to prevent its recurrence Wednesday.
Unfortunately, the rough-and-ready policy package ― mostly a retread of previous measures supplemented by sharply toughened punishment ― seems to be far short of keeping potential cyber thieves from committing crimes similar to what recently happened.
Besides making it more difficult to collect private information and share it among credit card firms, their affiliated banks and other businesses, the package calls for raising penalties on violators from 6 million won ($5,600) to 5 billion won ($4.68 million) and extending the period of business suspension from three to six months, as well as sacking the financial firms’ CEOs instead of just admonishing them as in the past.
Yet it is hard to think even the sharply raised fine of 5 billion won would rectify the loose security mindset of the three credit card companies, whose annual sales amount to trillions of won and whose operating profits alone range from 130 billion won to 990 billion won. Nor do consumers have any interest in whoever takes the top posts at these companies. In terms of punishment, anything less than punitive damages that can cripple their normal operations won’t do the job.
More importantly, the makeshift package is lacking in technical steps to prevent another nationwide data breach, such as obligating financial firms to activate in-house cyber security units, instead of leaving it to subcontractors. Given the theft was made by an insider, not outside hackers, they also ought to drastically limit the access to data by encrypting it.
Most of all, the regulator authorities themselves must shift their policy priorities from the industry to consumers. Not long after the incident broke out, Deputy Prime Minister Hyun Oh-seok said, “Fools try to first find out who is responsible whenever incidents occur,” scolding not the card companies but cardholders. The economic czar of President Park Geun-hye even added fuel to the fire while trying to appease seething consumers, saying, “I just wanted to stress consumers are also responsible, in part.”
People could understand why the government has patched up similar but smaller breaches in the past with only slaps on the wrist.
Financial Services Commission Chairman Shin Je-yoon also emphasized there have been no cases of “secondary damages” reported thus far. That’s fortunate, but what matters is the fact that someone stole people’s most private data, not what he has done with it. A survey shows about 40 percent of Koreans are suffering stress with frequent spam messages and all kinds of sales pitches made based on such stolen data.
The government should investigate and root out the “black market of big data,” and the National Assembly ought to enact a far tougher law protecting personal information. They must not waste any more time if for no other reason than restoring the badly compromised reputation of Korea as a global IT power.
Depending on how Seoul handles this incident, the cyber thief could ― and must ― become the “Snowden of Korea,” albeit inadvertently.