← Blog

Kakao Pay Raid: 40M Profiles Sent to Alipay, Police Move In

Share on X

July 9, 2026: South Korean police raided Kakao Pay headquarters in Seongnam after regulators concluded the fintech giant handed personal and financial data on roughly 40 million users to China's Alipay—in 5.42 billion cumulative transfers from 2018 through May 2024—without the consent required under Korean privacy law. It is one of the largest state-enforced personal-data cases in the country's fintech history, and it is still unfolding in criminal court.

What happened — and what did not

This is not a classic "hackers broke the firewall" ransomware story. Investigators describe a authorized-looking data pipeline that should never have existed: Kakao Pay allegedly transmitted payment and identity-class information to Alipay Singapore so Alipay could build NSF (non-sufficient funds) risk scores used when Apple routes KakaoPay transactions through Apple Pay on iPhone.

The Personal Information Protection Commission (PIPC) fined Kakao Pay, Apple, and Alipay in January 2025, finding violations of the Personal Information Protection Act (PIPA) for overseas transfers without valid consent—including data from Kakao Pay users who were not Apple customers. The Financial Supervisory Service (FSS) added an institutional warning and fines totaling about 12.98 billion KRW; PIPC's Kakao Pay fine was about 5.968 billion KRW, per DataGuidance and Inside Retail Asia.

Kakao Pay challenged the PIPC decision in court and lost the first trial in June 2026, then continued appealing. That loss set the stage for criminal escalation.

The police raid

According to Chosun (July 9, 2026), the Anti-Corruption and Economic Crime Investigation Unit of the Gyeonggi Nambu Provincial Police Agency searched Kakao Pay's Bundang offices July 6–7, 2026 on suspicion of violating the Credit Information Act and Electronic Financial Transactions Act.

Police began the probe in March after an FSS referral and, per Chosun, secured internal decision documents and electronic records tied to Alipay data sharing. The headline scale: ~40 million people and 5.42 billion data transfers—a volume that reflects repeated scoring and reconciliation, not a one-time export.

Why Apple and Alipay are in the chain

Apple Pay in Korea relies on local wallet rails. Kakao Pay integrates with Apple's payment stack; Alipay was contracted for payment-system integration and NSF modeling. PIPC found Apple failed to disclose outsourcing and did not obtain proper consent for overseas processing, while Alipay used the data to train models without consent.

For ordinary users the practical risk is not "someone drained my wallet overnight." It is silent profiling: creditworthiness and payment-behavior scores built from your transaction metadata, shared across borders, retained for years, and used in ways the app store screenshot never explained.

What data categories regulators cite

Public enforcement summaries describe financial and payment records, personal identifiers, and credit-related information tied to Kakao Pay accounts—enough to reconstruct spending patterns and risk profiles. Exact field lists live in Korean administrative decisions not fully reproduced in English press, but the PIPC's January 2025 findings are explicit that transfers included non-Apple Kakao Pay users, widening the blast radius beyond iPhone owners.

Who is at risk

Anyone who held an active Kakao Pay wallet between 2018 and May 2024 should assume their data participated in the NSF pipeline unless Kakao Pay later publishes a narrower scope. Apple Pay users in Korea who linked KakaoPay are the most visible cohort, but regulators say the harm is not limited to them.

What you should do

  1. Read official notices from Kakao Pay and PIPC/FSS—not Telegram "leak checker" bots claiming to sell Korean payment rows.
  2. Review Kakao and bank alerts for unauthorized transfers, new devices, or password-reset prompts.
  3. Enable MFA on Kakao, banking, and email accounts tied to the wallet.
  4. Document complaints if you receive coercive lending or identity-verification calls citing real transaction history—that is a common follow-on scam after financial-metadata spills.
  5. Watch the criminal case; additional penalties or remediation orders may force broader user notification than the 2025 fines alone.

Why this matters beyond Korea

Every country with a dominant super-app wallet faces the same structural risk: a local fintech becomes the choke point for identity, payments, and government ID verification—and a single vendor decision can export a nation's spending graph to a foreign processor. Regulators treated this as a compliance catastrophe first; police are now treating it as a potential crime. For BreachHistory, that is a verified mega-incident even without a ransomware group: the victims are real, the counts are attested, and the remediation is not finished.

Canonical record

Kakao Pay Alipay transfer scandal (2025–2026).

Sources: Chosun, DataGuidance (PIPC), Inside Retail Asia.