Toss Payments Fully Adopts Post-Quantum Cryptography, First in Korea's Finance and IT Sectors
- Deployment completed across all segments, a proactive move aligned with the government's post-quantum cryptography master plan
- Blocks "harvest now, decrypt later" attacks at the source, securing the long-term confidentiality of financial data
Toss Payments, the payment gateway (PG) affiliate of Toss, announced that it has become the first company in Korea's financial and IT sectors to fully adopt post-quantum cryptography (PQC), completing its deployment across all segments of payment data.
Post-quantum cryptography is a next-generation security encryption system based on complex mathematical algorithms that cannot be broken even by quantum computers. Toss Payments adopted a hybrid key-exchange method based on "ML-KEM," a standard established by the U.S. National Institute of Standards and Technology (NIST).
The company completed the deployment across its entire infrastructure, including its own data centers and the AWS cloud, without infrastructure constraints. Most notably, it applied the technology to the payment window itself – the key point of contact between merchants and consumers.
On the latest browsers that support post-quantum cryptography, including Chrome, Edge, Safari, and Firefox, the protection is applied automatically, with no technical action or setting changes required, while existing compatibility is preserved.
The move is designed to counter "harvest now, decrypt later" attacks, in which hackers collect currently encrypted communications and store them to decrypt once quantum computers become widely available. Because financial data, such as card information and transaction records, retains its value even decades later, protecting its long-term confidentiality is essential.
This deployment is a proactive achievement that comes roughly ten years ahead of the plan by the National Intelligence Service and the Ministry of Science and ICT to transition the nation's critical infrastructure to post-quantum cryptography by 2035.
The transition was supported by the company's Technical Account Manager (TAM) organization, a dedicated technical support team that has provided tailored migration guidance for individual merchants and verified technical compatibility with a wide range of legacy environments, enabling a stable transition without service disruption.
The full adoption of post-quantum cryptography completes a four-year journey of security advancement. After becoming the first in the PG industry to adopt HTTP/3 in 2022 and fully deploying TLS 1.3 in 2025, Toss Payments has now built a security infrastructure at a global standard.
"The advancement of quantum computing technology is both a tremendous challenge and an opportunity for financial security," said Yong Seok Shin, CISO of Toss Payments. "Grounded in our sense of responsibility as an industry leader, we will establish a standard for 'future-ready security' that gives both merchants and consumers peace of mind."