Amended telecom fraud law gives ASAP new legal footing

Participating firms expand to over 130

'Telecom carriers must take a more active role'

Kim Seong-ung, head of the Financial AI Security Research Institute at the Korea Financial Security Institute, speaks during an interview at the institute's Yeouido office in Seoul on Thursday.
Kim Seong-ung, head of the Financial AI Security Research Institute at the Korea Financial Security Institute, speaks during an interview at the institute's Yeouido office in Seoul on Thursday.

"Voice phishing is spreading because a single successful call brings in large sums of money, and the phone is a low-cost, low-risk tool for criminals," said Kim Seong-ung, head of the Financial AI Security Research Institute at the Korea Financial Security Institute.

Kim made the remarks in an interview Thursday, explaining why voice phishing shows no sign of abating. The Korea Financial Security Institute is a dedicated financial security body organized as a nonprofit association. Kim oversees operation of ASAP — the Voice Phishing Information Sharing and Analysis AI Platform — which aggregates suspicious account numbers, phone numbers and other data that member financial firms have individually collected, analyzes them using AI, and shares the results back with participating institutions.

As the crimes have grown more sophisticated, so has the response. An amended version of the Act on Special Cases Concerning the Prevention of Damage from Telecommunications-Based Financial Fraud and Refund of Damage took effect Aug. 4, with a key provision requiring prepaid service providers to share information. Previously, funds that entered a bank account could be frozen immediately upon a victim's report through a payment suspension order, but once fraudsters moved the money to a simple remittance platform, tracing and blocking it became far more difficult. Under the new rules, a financial institution that receives a fraud report and confirms that funds have been transferred to a prepaid service provider can request a transfer statement from that provider — effectively enabling payment suspension procedures on par with those applied to bank accounts.

The legal amendment also gave ASAP a firmer operational foundation. The platform had previously relied on relatively weak legal backing, such as advisory opinions from the Financial Services Commission, to justify its collection, sharing and analysis of information. Because the work involves pooling and analyzing personal data from multiple institutions, the absence of a clear legal basis had been a persistent constraint. "There is no precedent for a law that allows personal data to be used to this extent," Kim said. "It is the result of a broad social consensus built on a clear public-interest purpose and the sheer severity of the problem."

Participating firms have also grown, with second-tier financial institutions, securities firms, insurance companies and virtual asset businesses joining the platform, bringing the total to more than 130. Quantifying the results in hard numbers is still premature, however. "The law has been in effect for too short a time to produce comparable statistics — we will need another two or three months," Kim said, adding that the volume of information flowing through the platform has clearly increased and that he expects a corresponding improvement in fraud prevention.

A jointly developed AI model is set to be integrated into ASAP in October. The voice-phishing detection model was built by Kakao Bank, K bank and Toss Bank using federated learning — a technique that trains a single model by combining the learning outputs of each institution rather than pooling their transaction data in one place, allowing multiple firms' data to be used without exposing customer information externally. Once the model is deployed, financial firms that lack their own AI systems will be able to query the Korea Financial Security Institute's infrastructure and receive results. "Because the model was trained on transaction data from the three internet banks, other financial firms should treat it as a reference tool," Kim said. "We plan to keep expanding the model going forward."

The institute is also looking to broaden the data fed into the system. On top of data from financial firms, police and telecom carriers, it is reviewing plans to incorporate intelligence gathered from online communities where criminals discuss tactics and trade victims' phone numbers. "The new law has removed many of the restrictions," Kim said.

Kim reserved his strongest emphasis for the role of telecom carriers. "The very name of the law starts with 'telecommunications,'" he said. "By the time fraud reaches the financial stage, the entire scheme has already played out — and because it is the victim themselves who ultimately transfers the money, it is extremely difficult to stop at that point." Detection and intervention, he argued, must happen earlier, at the telecommunications stage.

Kim also identified global cooperation as a challenge. With multilateral bodies bringing together police, financial firms and telecom carriers in various countries to work on prevention, he added that he hopes the international cooperation efforts led by the Korean National Police Agency will become more substantive.


won@heraldcorp.com