2025–2026 Kakao Pay — regulator-confirmed unauthorized Alipay transfers; ~40M users; police raid Jul 2026
Data compromised
PIPC and FSS findings: financial/payment records, personal identifiers, and credit-related data for ~40 million Kakao Pay users transferred to Alipay; 5.42 billion cumulative data transfers cited in July 2026 police reporting
Technical writeup
Verified regulatory and law-enforcement disclosure — not a classic external hack, but a sustained unauthorized personal-data pipeline. South Korea's Personal Information Protection Commission (PIPC) fined Kakao Pay, Apple, and Alipay in January 2025 after finding Kakao Pay transmitted personal information of approximately 40 million users to Alipay Singapore for NSF (payment risk) score models used in Apple Pay on iPhone, including data from non-Apple Kakao Pay users, without valid consent for overseas transfer under PIPA. The Financial Supervisory Service separately issued an institutional warning and fines totaling roughly 12.98 billion KRW. PIPC imposed about 5.968 billion KRW on Kakao Pay; Kakao Pay lost its first administrative-court appeal in June 2026 and continued appealing. Chosun (July 9, 2026) reported Gyeonggi Nambu Provincial Police raided Kakao Pay headquarters in Bundang, Seongnam, July 6–7, 2026, seizing internal decision documents and electronic records after an FSS referral; police cited roughly 5.42 billion instances of personal information provision to Alipay from 2018 through May 2024. BreachHistory uses PIPC's ~40 million affected-user figure as the headline victim scale.
Root cause
Unauthorized overseas transfer of ~40 million users' personal and payment data to Alipay (2018–May 2024) without consent for NSF risk-scoring models; PIPC and FSS enforcement; criminal investigation and HQ raid July 2026