"Mithos AI Turned into a Hacker Weapon"... FSC Reviews Security Risks in the PG Sector
- Input
- 2026-09-16 15:00:00
- Updated
- 2026-09-16 15:00:00

The meeting focused on recent hacking trends in the financial sector, the PG sector’s handling and management of personal credit information, major types of security breaches, and response systems in the event of an incident. Participants pointed out that PG companies process various types of personal information, including names, dates of birth and payment details, meaning that information leaks could cause significant consumer harm, such as unauthorized payments. They also noted that bypass attacks exploiting security vulnerabilities at merchants, in addition to vulnerabilities in PG companies’ own systems, have recently become more frequent.
An official in the financial security industry said, "Hacking attempts believed to have used Mithos are still uncommon," adding, "Even without Mithos-level capabilities, attempts to use AI agents to neutralize the security networks of companies that have failed to patch already identified vulnerabilities have become more frequent."
Participants agreed on the need to establish comprehensive detection and response systems that consider not only threats arising from PG companies’ own systems but also those emerging at external points of contact, given that PG companies are connected to multiple financial companies and merchants. They also raised the need to minimize the information processed by the PG sector and prevent unnecessary or excessive data collection in order to avert secondary harm that consumers may not recognize when card information or other data is leaked.
Participants agreed that rapid prevention of consumer harm requires close cooperation among PG companies, card issuers, the Financial Supervisory Service, the Financial Security Institute and other relevant institutions when an information leak occurs. In the event of a card information leak, they emphasized proactive consumer protection measures, including rapid information sharing with card issuers, registration in fraud detection systems (FDS), strengthened monitoring of unusual transactions and unauthorized payments, prompt customer notifications, card reissuance and full compensation for consumer losses.
Yoo Young-jun, director general of digital financial policy, said, "Although PG companies are relatively small compared with financial companies, they are connected to numerous financial companies and merchants and process large volumes of personal credit information. Thorough security management is therefore essential to prevent consumer harm caused by security incidents." He urged them to "review and improve response systems so that immediate measures can be taken to prevent consumer harm through close cooperation with card issuers and relevant institutions when a breach occurs." He added, "Because financial-sector systems are highly interconnected through APIs, including Open banking and MyData, all participants in the financial ecosystem need to work to strengthen security."
[email protected] Park Moon-soo Reporter