Anti-Vishing Information Sharing via ASAP Available for Financial, Telecom and Investigation DataAug 04, 2026

The Financial Services Commission announced that the recently revised rules under the Special Act on the Prevention of Loss Caused by Telecommunications-based Financial Fraud and Refund for Loss (“the Act” hereinafter) and its Enforcement Decree will take effect from August 4, 2026. With the revised rules in place, financial companies, telecom service providers, and investigation authorities will be able to more easily and quickly share voice phishing (vishing)-related information to more effectively cut off criminal activities.

 

With the introduction of the AI-based Anti-Phishing Sharing and Analysis Platform (ASAP) in October last year, the sharing of information among relevant authorities and organizations has been made easier. However, the ASAP was operating mostly with the information provided by banks and there were limits in terms of legal foundation and the scope of participation.

 

In this regard, the government prepared a revision bill for the Act to provide a legal foundation for allowing the sharing of financial, telecom, and investigation data through ASAP and the revised Act passed the National Assembly on January 15, 2026.

 

Since then, the FSC prepared a revision bill for the Enforcement Decree and subordinate statutes to provide details regarding the scope of participating entities and the types of information being shared, and the procedures for selecting an ASAP operator (information sharing and analysis agency).

 

Key Details

 

Expanding the scope of participation and types of information

 

Under the revised rules, financial companies, telecom service providers, and investigation agencies that provide suspicious data linked to vishing scams will be allowed to provide relevant data to the information sharing and analysis agency (ASAP operator) without the need to obtain consent from the data subject. The scope of information providing entities will include financial companies, electronic telecom service providers, investigation authorities, the Financial Supervisory Service (FSS), the Korea Financial Intelligence Unit (KoFIU), electronic financial service providers (prepayment service providers), virtual asset service providers, and the Korea Association for ICT Promotion.

 

Moreover, the revised rules will also allow information providing entities to actively make use of the data provided by other organizations to promptly cut off suspicious phone numbers and for investigation purposes.

 

The types of information eligible for sharing through ASAP include (a) account numbers, transactions history, and information about the accountholder, (b) phone numbers and user information, (c) information about malicious mobile apps, and (d) suspicious transactions activities identified by financial companies.

 

Exempting the application of restrictive rules

 

To make sure that the sharing of information between related organizations can take place swiftly, the revised rules will provide an exemption from legal barriers and restrictive rules that may stand in the way of doing so.

 

At the same time, the revised rules will also provide measures to prevent the misuse or abuse of personal data by establishing specific standards regarding the management and deletion of personal data.

 

Selecting an information sharing and analysis agency (ASAP operator)

 

The Financial Security Institute (FSI) was selected as the information sharing and analysis agency (ASAP operator) on August 4. Based on its operation experience and expertise, the FSI is expected to effectively carry out the role of ASAP operator.

 

A system upgrade has already been made to make sure that telecom service providers and investigation authorities can seamlessly and immediately share suspicious information linked to vishing scams with the implementation of the revised rules from August 4.

 

Further Plan

 

With the revised rules taking effect from August 4, nonbank financial institutions, telecom service providers, and investigation authorities will also be able to take part in the sharing of vishing-related information through ASAP, which will help to bolster the government’s anti-vishing response capacity.

 

As the scope of participating organizations expands and the types of information being shared broadened up, it is expected that suspicious transactions data provided by financial companies in conjunction with the telecom and investigation data provided by relevant organizations will help to better detect and prevent criminal activities. In the meantime, the FSC will closely monitor the operation of ASAP and continue to work on making improvements to ASAP.


* Please refer to the attached PDF for details.