
Chief executives of platform companies hit by recent hacking and data leak incidents — including Tving, Toss Payments and Gangnam Unni — appeared before a National Assembly audit and faced intense criticism. With breaches also continuing in the financial sector, opposition lawmakers leveled criticism at the Ministry of Science and ICT (MSIT) for what they called an inadequate response.
Rep. Lee Hoon-ki of the Democratic Party of Korea said at the Oct. 6 audit by the National Assembly's Science, ICT, Broadcasting and Communications Committee that Tving's revenue grew 26.2-fold over the past five years, from 15.5 billion won to 406.8 billion won, while its dedicated information security staff numbered only four. "The company focused solely on making money and growing, and neglected security investment to such an extreme degree that the structure made an incident inevitable," he said. Choi Joo-hee, chief executive of Tving, who appeared as a witness, apologized, saying, "As the person responsible, I am sorry to the public, and I have come to fully realize that we neglected security."
Toss Payments and Healing Paper, the operator of Gangnam Unni, also acknowledged lapses in management and pledged measures to prevent a recurrence, including compensation for victims and expanded security spending. Hong Seung-il, chief executive of Healing Paper, said, "I deeply feel the responsibility for failing to protect sensitive personal information," adding that the company would more than triple its security staff and raise security investment 2.5-fold. Lim Han-wook, chief executive of Toss Payments, said, "I believe there were shortcomings," and added, "We are compensating for damages by providing cash-equivalent gift certificates to merchants and others, and we are strengthening oversight of merchants as well as reviewing our internal systems."
Lawmakers also raised questions about the hacking incidents in the financial sector that surfaced this month. Responding to Rep. Seo Cheon-ho of the People Power Party, who said breach-response systems were fragmented across agencies with no government-wide body in place, Bae Kyung-hoon, deputy prime minister and minister of science and ICT, said the information protection budget had been increased 44% this year to 523.2 billion won from 363.4 billion won. "We will take the lead in developing a standard manual for managing and responding to the breaches that keep occurring, and will step up efforts to disseminate it to relevant companies and across ministries," he said. He added that a revision to the Information and Communications Network Act that took effect Oct. 1 allows on-site investigations based on signs of hacking alone, without a report from the company. "Through this, we will also impose stronger financial penalties on companies," he said.

Opposition lawmakers also questioned the results of the government's sovereign artificial intelligence initiative. They pointed to the government's plan to pursue a frontier, or top-tier, AI model project from next year, separate from the existing sovereign foundation model program, as grounds for doubting what the earlier program had achieved.
Bae said the sovereign foundation model project was developed to improve the use of AI in industry and the public sector. "The sovereign foundation model program will proceed as originally planned, but a frontier AI project is additionally needed to tackle humanity's unsolved challenges and to respond to cybersecurity threats," he said.






