Grand Pinnacle Tribune

Intelligent news, finally!
Business · 5 min read

KakaoPay Faces Police Raid Over Massive Data Leak

South Korean authorities investigate KakaoPay after millions of users’ personal information was allegedly transferred to China’s Alipay for Apple’s risk scoring model, raising alarms about privacy and oversight in fintech.

South Korea’s fintech sector has been thrust into the spotlight after police launched a sweeping investigation into KakaoPay, the country’s leading mobile payment platform, over the alleged unauthorized transfer of personal data belonging to roughly 40 million users to China’s Alipay. The probe, which reached a dramatic milestone with a two-day search and seizure operation at KakaoPay’s Seongnam headquarters on July 6 and 7, 2026, is sending shockwaves through the tech and finance industries—and raising pressing questions about data privacy, corporate responsibility, and international business practices.

According to multiple reports, including those from IMBC, Gyeonggi Ilbo, and Electronic Times, police from the Gyeonggi Southern Provincial Police Agency’s Anti-Corruption and Economic Crime Investigation Unit executed the search as part of their first forced investigation into KakaoPay since the Financial Supervisory Service (FSS) requested a criminal probe in March 2026. Investigators are scrutinizing whether KakaoPay violated the Credit Information Act and the Electronic Financial Transactions Act by transmitting a staggering 54.2 billion pieces of personal data—spanning phone numbers, payment records, and more—to Alipay between 2018 and May 2024.

The data transfer came to light during a January 2025 investigation by the Personal Information Protection Commission (PIPC), which revealed that the personal information was provided to Alipay to construct the so-called “NSF score” model. Commissioned by Apple, the NSF score is used to assess the risk that a user may default on payments for Apple services—a kind of creditworthiness score, but for digital payments. The data transfer was triggered during the process of registering KakaoPay as a payment method on Apple iPhones, making the scope of the data sharing particularly vast.

The magnitude of the incident is hard to overstate. As Gyeonggi Ilbo reported, “KakaoPay is suspected of illegally transmitting personal information of about 40 million users, totaling 54.2 billion data points, to China’s Alipay from 2018 through May 2024.” The financial and reputational fallout has already been severe: in January 2025, the PIPC imposed a fine of approximately 5.968 billion KRW (about $4.5 million), while the FSS followed up in February 2025 with a warning, a fine of about 12.976 billion KRW (roughly $10 million), and an additional penalty of 480,000 KRW. These punitive measures underscored the gravity of the alleged violations and set the stage for the current criminal investigation.

But the story doesn’t end with regulatory fines. KakaoPay has maintained that the data transfer was a legitimate part of a business consignment arrangement—a routine outsourcing of services necessary for global payment operations. The company insists that the information was encrypted or anonymized, and that the process was in line with international payment network standards. In the words of a company spokesperson, as cited by Electronic Times, “It was a lawful business consignment.”

Regulators and the courts, however, have so far disagreed. The PIPC and FSS both concluded that KakaoPay’s actions constituted an unauthorized third-party provision of sensitive personal data, requiring explicit user consent. The Seoul Administrative Court echoed this view in a landmark ruling on June 11, 2026, when it dismissed KakaoPay’s administrative lawsuit challenging the PIPC’s penalties. The court stated, “It is difficult to see that the data subjects specifically and clearly consented to their information being used for the calculation of the NSF score for Apple’s payment risk assessment.”

For police, the investigation is now focused on the internal decision-making process at KakaoPay. Who knew about the data transfer? Who signed off on it? Was it a simple clerical error, or did it pass through the company’s legal and compliance checks? Authorities have secured a trove of electronic documents and are now analyzing them to determine whether the company’s executives and staff acted knowingly or negligently. Once this analysis is complete, witness and suspect interviews—including with current and former KakaoPay employees—will follow.

As SJSori notes, the case isn’t about a shadowy hacker stealing data from the outside, but rather about a company’s structured decision to provide customer information to an external business partner for a specific purpose. This distinction is crucial: it shifts the focus from technical vulnerabilities to questions about internal governance, risk management, and the adequacy of customer consent procedures. One financial sector insider told SJSori, “This incident should be seen not as a simple data accident, but as a structural issue in how financial platforms handle data and internal controls.”

The repercussions are already rippling through South Korea’s fintech industry. With the police probe intensifying, other financial technology firms are being forced to re-examine their own practices around customer consent, overseas data transfers, third-party data sharing, and the use of credit information. The case has sparked debate about whether current regulations are sufficient to protect consumers in an era where digital payment networks routinely cross international borders and involve multiple intermediaries.

For its part, KakaoPay is appealing the court’s decision, seeking to overturn the ruling that it failed to obtain clear user consent. The outcome of this appeal—and the ongoing criminal investigation—could have far-reaching implications not just for KakaoPay’s reputation and business model, but for the entire Korean fintech sector and its global partnerships.

Meanwhile, for the millions of users whose data was shared, there are lingering questions. How much did they know about their information being used to build Apple’s NSF score? Did they ever truly consent, or was the fine print too fine to notice? And as regulators tighten the screws, will other companies be caught in similar crosshairs?

As the investigation unfolds, one thing is clear: the line between business necessity and personal privacy is under intense scrutiny, and the outcome could reshape digital finance in Korea for years to come.

Sources