Korea’s popular digital wallet Payco hit by signature key hijacking

2022. 12. 6. 10:09
글자크기 설정 파란원을 좌우로 움직이시면 글자크기가 변경 됩니다.

이 글자크기로 변경됩니다.

(예시) 가장 빠른 뉴스가 있고 다양한 정보, 쌍방향 소통이 숨쉬는 다음뉴스를 만나보세요. 다음뉴스는 국내외 주요이슈와 실시간 속보, 문화생활 및 다양한 분야의 뉴스를 입체적으로 전달하고 있습니다.

이 기사는 언론사에 의해 수정되어 본문과 댓글 내용이 다를 수 있습니다.

The signature key of South Korea’s popular payment app Payco with more than 10 million downloads has been leaked, raising serious cyber security concerns about personal information outflow and fake installation of malicious apps.

According to multiple sources from the financial industry on Monday, security solution firm Everspin Co. sent out an emergency notice to 30 of its Korean clients, including KB Kookmin Bank, NH Nonghyup Bank, and KakaoBank, to warn that 5,144 malicious apps have been installed across Payco users’ devices with the digital wallet’s stollen certification key between Aug. 1 and Nov. 30

It warned of numerous financial accidents related to signature key management and voice phishing.

NHN headquarters [Courtesy of NHN]
Payco - managed by NHN Payco Corp. - was aware of the leak on Aug. 10 but had not informed its clients until media report by Maeil Business Newspaper. Payco said it had not made the signature key leak public because it has not found any attack on the Payco app itself.

The app certified with the Payco signature key does not need a security check as it is recognized as a legit app made by Payco. This means any voice phishing app with the same signature value as with Payco app can be installed easily at any device as a certified app, according to Everspin.

The Everspin found out that 18 apps including Hangame OTP, Fortune Monastery Today, and Ticketlink use the same signature key with Payco, suggesting the certification key leak.

Everspin suspected that the leak could have been caused by either Google Play store account leak, manager PC hacking, or inattentiveness by other managers.

“Google account leakage or management PC hacking could lead to bigger damage such as financial information leak because a hacker can switch Google Play store app,” said an unnamed official from Everspin. “It is a very serious cybersecurity issue.”

Payco will carry out an app update using a new signature key this week, said an unnamed official from Payco.

“We are devising measures to invalidate malicious app operation.”

Copyright © 매일경제 & mk.co.kr. 무단 전재, 재배포 및 AI학습 이용 금지

이 기사에 대해 어떻게 생각하시나요?