The South Korea Financial Services Commission reviewed cybersecurity risks and incident response arrangements across payment gateway providers following a recent breach, with particular attention to threats enabled by artificial intelligence. The review extends the commission’s broader strengthening of payment gateway oversight and user protection, reflecting the risk that breaches at providers handling personal and payment data could lead to large scale data leaks and fraudulent card transactions. Payment gateway providers were urged to address vulnerabilities in their own systems and at connected merchants, minimize the personal and payment information they process, and strengthen breach detection and response. If card data are compromised, providers should rapidly share information with card issuers and relevant authorities to support fraud detection, enhanced transaction monitoring, customer notification, card replacement and full compensation for consumer losses. The commission encouraged providers to use government initiatives supporting AI based security capabilities, including the Financial AI Security Research Institute and Support Center and forthcoming financial AI security guidelines. It will also examine the sector’s security and consumer protection arrangements and identify potential regulatory improvements.