IT·SCIENCE

Face verification curbs 'Odyssey' ticket scalping, but security lags behind

by
Cha Min-ju
Published : Sept. 9, 2026 - 17:40:00
    • Copy Completed!

View Korean Original

Toss's FacePass adopted by KT Wiz, Lotte Giants, NOL and others

No prior adequacy review filed with privacy watchdog yet

Experts say entire authentication process needs security checks

[Getty Images]
[Getty Images]

"Selling an 'Odyssey' movie ticket for 350,000 won ($261)" — from a post on a secondhand trading platform.

As scalpers increasingly turn to secondhand trading platforms to resell tickets for popular films at inflated prices, facial recognition services are spreading fast as a countermeasure. But while facial data carries far greater risk than ordinary personal information if leaked, critics say safeguards to prevent such leaks remain insufficient.

According to IT industry sources Wednesday, facial recognition services are expanding across sports stadiums and concert venues. This follows a rise in scalping, including the resale of tickets for the film "Odyssey" at inflated prices on secondhand platforms.

A leading example is FacePass, a facial recognition service from Toss. It lets users verify their identity using facial data they registered in advance, without needing a separate ticket or ID.

FacePass is spreading rapidly. Professional baseball team KT Wiz introduced the service this year to help manage fan entry. According to KT Corp, the service is being piloted among season ticket holders, with at least 500 fans currently using FacePass. Lotte Giants, ticketing platform NOL and hagwon platform EduOK have also adopted the technology, as its range of use continues to widen.

[Getty Images]
[Getty Images]

Toss had already expanded FacePass's scope in May, extending it beyond venue entry verification to age confirmation and point accumulation. Observers say the company is broadening its business beyond concert halls and gyms into offline merchant partnerships more generally.

The problem is that even as the service spreads, concerns persist that safeguards against personal data leaks remain inadequate.

A case in point is whether Toss has undergone a prior adequacy review by the Personal Information Protection Commission (PIPC). Toss has yet to submit an application for such a review. The prior adequacy review is a system under which the PIPC examines whether a company's new service risks violating the Personal Information Protection Act and establishes necessary protective measures.

"Toss has never applied for a prior adequacy review for FacePass," a PIPC official said.

FacePass faced the same criticism during a National Assembly audit in October 2025. Critics say the fact that no preventive measures were put in place despite a year of ongoing concern points to a passive approach to protecting personal information.

At the time, Lee Hae-min, then a Rebuilding Korea Party lawmaker, said, "According to the notice for NOL Ticket's face pass, the information is stored not by NOL Universe but by Toss for a year before being deleted. Users likely have no idea that their facial data will be kept by Toss, rather than NOL Ticket or HYBE."

[Getty Images]
[Getty Images]

Lee went on to say, "The prior adequacy review approval Toss received from the PIPC was for its face pay business, not its face pass business. Toss has explained that face pass and face pay use the same technology but are separate businesses — if that is the case, face pass should undergo its own adequacy review."

Toss maintains that there is no problem, saying personal information such as facial data is managed on a separate server. "Facial data is converted into 'feature information,' encrypted, and stored on a separate server. We do not share personal information with device manufacturers or service partners," a Toss official said.

Still, industry observers say the location where facial data is stored alone cannot guarantee the safety of facial recognition technology.

"The fact that facial data is stored inside the device alone cannot dispel concerns," said Hwang Seok-jin, a professor at Dongguk University's Graduate School of Information Security. "It needs to be verified what data is generated during on-site authentication, how it communicates with the server, and whether protective measures exist to prevent outside breaches."

He added, "The level of camera access granted to manufacturers, whether information temporarily remains on the device, and the security of remote maintenance and after-sales service access all need to be checked as well."

A facial recognition attendance-check service launched by BH Soft using Toss's FacePass
A facial recognition attendance-check service launched by BH Soft using Toss's FacePass

Experts say facial data carries greater risk than ordinary personal information if leaked, given its nature. That is why calls are growing for companies using facial recognition technology to establish more thorough safeguards.

"Unlike a password, facial data is, in effect, permanent information that cannot be changed once leaked," said Choi Kyung-jin, a professor of law at Gachon University. "If leaked, there is a high risk it could be misused in identification or authentication processes."

The government has also recently moved to tighten protection standards for biometric information such as facial data. Under the Standards for Ensuring the Safety of Personal Information, which the PIPC put into effect in July, businesses must apply security-verified encryption algorithms. This applies when storing or transmitting authentication information, including biometric data, over communication networks. In effect, this requires security management across the entire process by which information travels from a device to a server.


chami@heraldcorp.com
This content was produced with the assistance of AI translation services.

MOST READ