Wednesday, October 7, 2026

“Financial-sector hacking: Are you sitting on your hands, saying it’s the FSC’s job?” ... MSIT’s response draws criticism

Input
2026-10-06 16:54:45
Updated
2026-10-06 16:54:45
Deputy Prime Minister and Minister of Science and ICT Bae Kyung-hoon answers lawmakers’ questions at a National Assembly audit of the Science, ICT, Broadcasting and Communications Committee (covering the Ministry of Science and ICT and other agencies) in Yeouido, Seoul, on the 6th. Newsis
[Financial News] The government’s response to personal information breaches in the financial sector came under scrutiny at a National Assembly audit by the Science, ICT, Broadcasting and Communications Committee on the 6th. The opposition urged the government to break down interagency silos, saying the Ministry of Science and ICT (MSIT), which oversees cybersecurity, should not shirk responsibility on the grounds that the matter falls under the financial authorities’ jurisdiction. Deputy Prime Minister and Minister of Science and ICT Bae Kyung-hoon stressed that the government would strengthen punitive surcharge penalties and improve its capacity to respond to security threats.
Rep. Choi Hyung-du of the People Power Party, the opposition’s ranking member on the committee, said at that day’s audit of MSIT, “Recent hacking incidents in the financial sector are not matters for the Financial Services Commission or the Financial Supervisory Service; under the government’s system, they are MSIT’s responsibility.” He added, “MSIT, the lead agency responsible for cybersecurity, must not claim that an issue on which even the president has called for a thorough investigation falls under the FSC’s jurisdiction.”
He added, “The interagency silos that last year’s comprehensive, pan-government information security plan said it would eliminate are still there,” and stressed, “If MSIT sits on its hands, citing jurisdiction in the age of AI hacking, it is giving up its own qualification as the lead ministry.”
Choi called for a pan-government response, saying cyberattacks were spreading to the telecommunications, financial and public sectors. His point was that MSIT should take the lead in directing investigations and responses, rather than stopping at action by individual ministries within their respective jurisdictions.
Bae said, “We will strengthen punitive surcharge penalties,” adding, “We will boost our response capabilities by developing AI models specialized in security and through international cooperation, and announce the ‘Master Plan for Building a National AI Safety Ecosystem’ this coming December.”
Criticism also continued at the audit over allegations that LG Uplus covered up a hacking incident and concerns about TVING’s inadequate protection of personal information.
In response to a question from Rep. Cho Kyung-tae of the People Power Party about whether subscribers should be exempted from early termination fees if an LG Uplus hacking cover-up is confirmed, Bae said, “If it is established that there was deliberate destruction of evidence or various forms of obstruction of the investigation, then of course we should call for subscribers to be exempted from the fees.” He added, “The government will also take an active role in ensuring fee waivers are implemented if serious service disruptions or violations of core contractual obligations are uncovered.”
Rep. Han Jun-ho of the Democratic Party of Korea pressed the company on why its operating system (OS) was reinstalled after the Korea Internet & Security Agency (KISA) notified it of signs of a cyber incident, when the submitted server images were created, and whether the originals had been preserved. Hong Kwan-hee, chief information security officer (CISO) at LG Uplus, said the company had submitted server images created after KISA’s notification, but declined to provide details, citing the ongoing investigation.
TVING faced criticism for not adequately addressing vulnerabilities identified before the incident. Rep. Lee Hoon-ki criticized TVING for not completely removing a hard-coded vulnerability even after it was flagged in 2024.
TVING CEO Julie Choi replied, “Our investment has increased, but we haven’t examined whether it is at a sufficient level,” and added, “We will expand staffing and investment to establish a security system based on Zero Trust.”
[email protected] Yoon Hong-jip Reporter