News

Sharing of Suspected Voice Phishing Info Allowed Without Consent

Sharing of Suspected Voice Phishing Info Allowed Without Consent
▲ Voice phishing (File Photo)

Moving forward, when financial institutions, telecommunications companies, or investigative agencies detect suspected circumstances of voice phishing, the information can be shared with information-sharing and analysis organizations even without the individual consent of the information subject.

Previously, information sharing between agencies was difficult due to restrictions under laws such as the Real Name Financial Transactions and Guarantee Act and the Credit Information Use and Protection Act. However, through this revision of the law, rapid information sharing will now make it possible to block voice phishing crimes and damages.

The Financial Services Commission announced today (August 4) that it is implementing the enforcement decree and subordinate regulation amendments of the Special Act on Prevention of Losses from Telecommunications-based Financial Fraud and Refund of Damages containing these provisions.

Since October of last year, financial authorities have been operating the Voice Phishing Information Sharing and Analysis AI Platform (ASAP), centered mainly around the banking sector. However, due to a lack of legal grounds for information sharing, there were limitations in utilizing information from institutions other than financial firms.

With this amendment, the scope of information-sharing entities is expanded to include financial companies, telecommunications service providers, and investigative agencies, as well as the Financial Supervisory Service, the Korea Financial Intelligence Unit, electronic financial business operators, virtual asset exchanges, and the Korea Association for ICT Promotion (KAIT).

Under the new system, if an institution possessing suspected voice phishing information provides it to an information-sharing and analysis organization without the consent of the information subject, the data will be analyzed and disseminated to the target institutions for sharing.

Institutions that receive the shared information will be provided with information and analysis results supplied by other agencies to urgently block phone numbers used in crimes or directly utilize them for investigations.

In addition to transaction details of suspected fraudulent or damaged accounts, information to be shared includes phone numbers and user details used in voice phishing, malicious app data, and information on suspicious transaction detections by financial firms.

To ensure smooth information provision, the application of related laws such as the Real Name Financial Transactions Act and the Credit Information Act will also be excluded.

However, to prevent the misuse or abuse of personal information, separate control mechanisms have also been established, including data retention periods and methods for data destruction and deletion.

The Financial Services Commission has designated the Financial Security Institute as the information-sharing and analysis organization to operate ASAP, and the information-sharing system will go live simultaneously with the enforcement of the regulations.

The Financial Services Commission stated, "There are still many citizens suffering from voice phishing crimes," adding, "We will actively prevent crimes through information sharing among related organizations and continue to pursue the advancement of ASAP."
※ Please note: This article was translated by AI and may contain errors.
Copyright Ⓒ SBS. All rights reserved. 무단 전재, 재배포 및 AI학습 이용 금지

Most Read