The Financial Supervisory Service ordered securities firms to reset trading-desk passwords every quarter and to confirm high-risk orders through registered phone callbacks after investigators linked two August voice-spoof incidents to the same synthetic-audio toolkit used in pig-butchering scams, extending internal-control rules written for email fraud after the LS Securities standing-proxy case.
What broke
In separate probes, mid-tier brokerages in Seoul and Busan released block trades and cash remittances when desk staff accepted short “compliance approval” calls that cloned a fund manager’s voice from clips scraped from investor roadshows. Neither firm’s core systems were breached; attackers paired caller-ID spoofing with generative audio trained on public YouTube briefings. Combined attempted outflows exceeded 41 billion won before wire desks froze accounts, FSS officials said in a circular distributed Thursday to chief compliance officers.
The pattern mirrors the LS Securities controversy, in which forged emails drove repeated orders for a foreign investor, except the channel shifted from inboxes to headsets. Police cyber units said one ring reused SIM farms that Shinhan Bank flagged in August mule sweeps, suggesting scam infrastructure is crossing from retail crypto on-ramps into capital-markets social engineering.
What FSS confirmed
FSS completed fact-finding on the LS matter earlier this year and had already urged standing-proxy desks to verify instructions out of band. The new guidance names voice as a distinct attack surface: any order above 500 million won, any password reset on a trading terminal, and any change to callback numbers must use numbers on file from the prior quarter, not numbers supplied on the same call or chat thread.
Quarterly password rotation applies to shared “break-glass” accounts on equity desks and to middleware consoles that bridge order-management systems to client portals. Firms must log reset events in tamper-evident audit stores reviewable during autumn inspections. The Korea Financial Investment Association will publish sample scripts for desk staff to refuse “urgent” approvals that arrive only through voice or messaging apps.
Who is liable
Legal teams told InfoHandle the circular does not create a new statute but tightens expectations under the Financial Investment Services and Capital Markets Act internal-control rules. If a desk executes on a cloned call without callback, examiners can cite deficient procedures even when criminals face criminal charges. Consumer advocates want mandatory recording of approval calls; FSS stopped short, citing privacy and union pushback, but encouraged firms to offer optional recorded lines for institutional clients.
Foreign investors using standing-proxy arrangements— the same service at the center of the LS lawsuit—are the most exposed. FSS said firms must refresh contact trees when proxy contracts renew and may not rely solely on email threads that attackers already forge.
Vendor and desk scramble
Order-management vendors in Yeouido reported a spike in requests for hardware security keys tied to desk logins rather than static passwords. Two banks that clear for smaller brokerages asked for extra settlement delays when voice approvals appear in ticket notes. Compliance trainers are rewriting September drills to include synthetic-audio samples so junior traders recognize flattened cadence and missing background noise.
Industry groups warned that quarterly resets could collide with Chuseok staffing gaps; FSS allowed emergency extensions only when chief compliance officers document on-call rosters. That carve-out is narrow—firms cannot use holidays to skip callbacks on large trades.
What desks should do now
FSS recommends desk leads publish a single published callback directory, freeze changes during market hours, and route all “CEO urgent” requests through legal before release. Firms should test whether their recorded roadshows and Korean-language IR podcasts expose enough phonemes to fuel clones; several listed companies already pulled long Q&A replays behind registration walls this week.
Police asked brokerages to share hashed metadata from spoofed calls through the joint FSS cyber tip line opened after the LS case. Investigators have not named suspects publicly, but said one Busan ring rented the same voice-model subscription used in romance-investment scams.
Timeline
Rules take effect 1 October, with first quarterly password resets due before the November earnings season when block volumes rise. Parliamentary hearings on financial AI fraud are scheduled for late September; opposition lawmakers may press for statutory penalties beyond supervisory guidance. For now, FSS is betting that disciplined callbacks cost less than another multibillion-won standing-proxy payout.
Limits of the order
The circular does not cover retail mobile banking voice phishing, which remains governed by separate authentication rules, and it does not mandate voice-print biometrics—a technology several vendors pitched but regulators deemed immature. FSS also excluded futures and FX desks pending a second notice; equity cash markets were the attack surface in both August cases.
What is known: systems were not hacked, but humans were. What is still unknown: how many dormant roadshow clips sit on public sites waiting for the next clone. Until then, quarterly password resets and stubborn callbacks are the house rule on Korea’s trading floors.








