News / Korea / yonhap_finance
Toss Payments Reports Data Leak Affecting 2,671 Users at Third-Party Merchant
Technology Services · Data Processing Services · yonhap_finance · 2026-09-09
Toss Payments confirmed that payment details for 2,671 users were accessed by unauthorized parties due to an authentication leak at a specific merchant.
What Happened
Incident Overview: Toss Payments has confirmed that payment records for 2,671 users were accessed by unauthorized third parties due to an authentication leak at one of its affiliated merchants. The breach involved 4,131 individual payment transactions.
Nature of Data: The exposed information was limited to receipt-level details, such as customer names, masked card numbers, and approval codes. Crucial financial data, including card passwords, expiration dates, and CVC codes, remained secure and were not compromised.
System Integrity: The company clarified that the incident was not the result of a direct hack or vulnerability within its own payment infrastructure. To date, there have been no reports of fraudulent transactions or financial losses resulting from this exposure.
Response Measures: Toss Payments has successfully blocked the unauthorized access path and notified both the affected customers and financial regulators. The firm is currently reviewing its merchant security protocols to prevent similar incidents in the future.