En.Sedaily Bank Must Repay 50 Million Won Due to Phishing Scam Error
Article Content
- •The bank must return 50 million won to the son due to an employee error.
- •The mother was a victim of a voice phishing scam that led to the account closure.
- •The financial firm is held liable for breaching its duty of care.
A South Korean financial firm is required to return 50 million won to a customer’s son after an employee mistakenly closed his account during a voice phishing incident. The Financial Supervisory Service (FSS) ruled that the bank breached its duty of care by closing the son's account instead of the mother's. The incident occurred in September 2024 when the mother, deceived by a scammer, requested to close her account. The employee closed the wrong account and issued a check to the mother, who later lost the funds to the scammer. The FSS determined that the financial firm must repay the son, as he was the legitimate account holder. The ruling also stated that the bank cannot claim the money back from the mother, as she was under the influence of the scammer at the time of the transaction.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Financial Supervisory Service in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What was the bank's error?
What is the current status of the funds?
Can the mother be held liable for the funds?
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Sets Oct. 11 Deadline for Patching Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after they were exploited by the China-linked group Flax Typhoon. Federal agencies must patch or retire the affected software by October 11, 2026. The vulnerabilities…