The Financial Services Commission imposed a 420 million won fine on a mid-tier life insurer Tuesday and ordered every tied broker portal to disable bulk PDF downloads after investigators found 1,240 pension annuity illustration files exposed through agent accounts that lacked step-up authentication, a breach regulators said turned routine sales tools into an open directory of payout schedules and partial resident registration numbers.

What broke

According to an FSC enforcement notice reviewed by InfoHandle, the leak ran for at least eleven weeks through a wholesaler portal that let field agents pull “customer-ready” annuity PDFs for face-to-face sales. A misconfigured role flag let any logged-in agent enumerate other agents’ folders by incrementing document IDs in the URL. Crawlers indexed several hundred files before the insurer’s own security team noticed abnormal bandwidth on a staging subdomain shared with legacy broker software.

The PDFs were not full policy contracts but illustrated payout tables tied to real applicants—enough for fraudsters to craft convincing refund calls, FSS examiners said in a parallel briefing to chief privacy officers. At least 38 customers reported smishing attempts referencing exact monthly payout figures after the leak window; police have not tied those cases to a single ring.

What FSC confirmed

FSC’s secretariat said the fine reflects both delayed notification to the Personal Information Protection Commission and failure to encrypt stored illustrations at rest on the broker tier. The insurer must fund third-party monitoring for affected customers for twelve months and publish a corrective plan within thirty days. Broker portals nationwide must adopt one-time passcodes for any export above ten files per session—a rule the Korea Life Insurance Association had recommended as voluntary guidance since 2024.

FSS will inspect the insurer’s audit logs during autumn examinations and may escalate to business suspension if portal vendors miss a 31 October retrofit deadline. The commission did not name the company, citing ongoing criminal referral, but said it ranks among the top fifteen writers by pension annuity premium volume.

Who is liable

Legal analysts told InfoHandle the case tests whether insurers remain accountable when leaks occur on broker-hosted infrastructure rather than core policy systems. FSC argued the insurer owns the data classification and vendor contracts; blaming a portal integrator will not reduce fines under the Personal Information Protection Act if notification deadlines slip. Agents who shared deep links in KakaoTalk work rooms may face separate employment sanctions, though criminal charges require proof of intent to sell data.

Consumer groups want mandatory customer alerts by registered mail, not app push alone, because pension annuity buyers skew older than mobile-first banking cohorts. FSC stopped short of mail requirements but ordered call-center scripts acknowledging the leak for any inbound annuity inquiry.

What portals must change

Wholesalers told InfoHandle they are racing to move illustration storage behind signed URLs that expire within minutes, mirroring securities research portals. Several midsize insurers still run broker tools on shared subdomains with weak separation between test and production—a pattern FSS flagged after a 2025 variable-life illustration leak in Busan that never drew a public fine.

PIPC opened a parallel review of whether partial resident ID fragments in PDF headers require separate reporting thresholds. Insurers historically treated illustration IDs as internal reference numbers; regulators now say any field matching registry formats triggers the full breach clock.

What is still unknown

Investigators have not said whether indexed files were scraped from domestic IP ranges only or mirrored offshore. The insurer has not quantified how many PDFs included bank account numbers for auto-debit setup—a field some agents optionalize. Criminal referrals naming portal developers remain pending; FSC would not confirm whether a state-backed penetration test discovered the flaw or a customer complaint did.

What customers should do

FSS recommends annuity holders hang up on callers citing exact payout figures unless the insurer verifies through a callback number printed on the original paper policy. Customers should rotate portal passwords if they use the same credentials on insurer mobile apps—a common habit field agents encourage for convenience but regulators now discourage.

For the wider market, the lesson is narrow but costly: sales PDFs are personal data, not marketing collateral. Until broker portals treat downloads like wire transfers—with step-up auth and expiring links—pension illustrations will keep appearing in leak databases insurers assumed were private.

Timeline

Corrective plans are due mid-October; FSS follow-up inspections land before year-end closing season when annuity sales spike. Parliamentary audit questions on insurance IT outsourcing are scheduled for late September, giving opposition lawmakers a fresh example beyond banking app outages. FSC said it will publish anonymized indicators of misconfigured portal patterns once other insurers finish self-audits requested this week.