Toss Payments announced today (Sept. 9) that it has confirmed a case where a portion of payment details at a specific merchant using its payment gateway (PG) service was accessed by a third party.
According to Toss Payments, authentication credentials for the payment integration platform on the merchant's website were exposed, allowing a third party to view transaction histories.
The incident affected 4,131 transactions involving 2,671 information subjects, according to the tally.
The accessed data consisted of receipt-level payment details, such as the buyer's name, masked card numbers, and authorization numbers. Critical payment information, including card passwords, expiration dates, and CVC codes, was not included.
Toss Payments also stated that the payment system itself was not compromised by hacking or vulnerability exploitation.
(Photo provided by Toss Payments, Yonhap News)