주메뉴바로가기본문바로가기
비즈한국 비즈한국

'The Most Sensitive Personal Information' AI Call Summaries Trigger Security Warning

This article was automatically translated by AI. There may be errors compared to the original Korean article.  Read original in Korean →

[비즈한국] As a data leak incident involving user call content occurred on LG Uplus032640’s AI call app ‘ixi-o’, concerns have been raised regarding the safety of AI services that utilize sensitive data. Because AI call apps operate based on highly sensitive information such as a customer’s call history, usage patterns, schedules, and interests, security trust is a critical prerequisite for the business. Customers who used the service for its convenient features are now questioning its server storage structure and internal management system. With a call app that touted security as a strength revealing vulnerabilities just about a month after introducing AI assistant functions, strengthening security and restoring trust have emerged as urgent tasks.

An incident occurred where some call information from LG Uplus's AI call app, ixi-o, was leaked. Photo=Yonhap News
An incident occurred where some call information from LG Uplus's AI call app, ixi-o, was leaked. Photo=Yonhap News

Customer Information Leak Just Over a Year After Launch

LG Uplus announced on the 6th that it had voluntarily reported to the Personal Information Protection Commission after customer call information was leaked from its AI call app, ixi-o. The company identified the cause of the accident as a configuration error in the temporary storage space (cache) by a server technician.

The accident occurred during server improvement work. According to LG Uplus, following operational improvements for the ixi-o service on the 2nd, a leak occurred over a 14-hour period starting at 8 PM, where the call summaries of 36 users were exposed to 101 users who had newly installed or reinstalled the app. The company stated that it became aware of the incident at 10 AM on the 3rd after receiving a report that "summaries of other people's calls are visible," and completed measures to block access to the leaked information over two days before reporting it to the Personal Information Protection Commission around 9 AM on the 6th.

ixi-o is an independently developed call app launched last November. A similar service is SK Telecom017670’s ‘A.’, which was released earlier. ixi-o evolved into a call assistant app last month by adding new AI assistant functions to its existing real-time voice phishing detection, call recording, and transcription/summary features. The ixi-o AI assistant is an on-device AI-based feature that provides immediate search information by understanding the context of a conversation when called during a call. For instance, if a user calls ixi-o while talking to a colleague or friend to ask about weekend weather or travel time from a subway station to a meeting spot, the AI voice searches for the information immediately and shares the results.

The information leaked in this incident included call summaries, the other party’s phone number, and the time of the call. It did not include unique identification information such as resident registration numbers, financial information, full call transcripts, or names stored with contacts.

The company emphasizes that this was an internal mistake, not a hack. However, critics point out that the structural issue of how sensitive call summaries could be exposed to others without encryption due to a mere configuration error must be examined. The view is that the fact that a management error led directly to an information leak reveals a structural vulnerability where multi-layered security devices were either absent or not functioning properly.

Hwang Seok-jin, a professor at Dongguk University’s Graduate School of Information Security, said, "When designing logic, if you rely only on the result values and neglect validation for small parts, operational errors can occur at any time. The structural approach of building double or triple safety nets in the process of handling data was insufficient."

Call Summaries Stored on Servers

Choi Yoon-ho, head of LG Uplus’s AI Agent Promotion Group, said at a press conference unveiling the ixi-o AI assistant service on the 13th of last month, "Call recordings and summaries generated in ixi-o are safely stored within customers' mobile phones." While LG Uplus has emphasized the safety of on-device AI, the fact that call summaries were stored on servers and that a server management mistake led directly to an information leak exposes the limitations of the "on-device" scope. In the ixi-o structure, on-device AI is primarily responsible for processing and recording voice files, while the leaked call summaries are stored and managed on servers.

LG Uplus headquarters in Yongsan-gu, Seoul. Photo=Bizhankook DB
LG Uplus headquarters in Yongsan-gu, Seoul. Photo=Bizhankook DB
This article was automatically translated by AI. There may be errors compared to the original Korean article.
강은경 기자

기술과 산업을 취재하고 씁니다.

gong@bizhankook.com
저작권자 ⓒ 비즈한국 무단전재 및 재배포 금지