전자금융거래법 제9조에 따른 금융기관등의 책임-하급심 판결을 중심으로-
The Liability of Financial Institutions under the Article 9 of the Electronic Financial Transaction Act
강희주(법무법인 광장); 이상민(법무법인 광장)
15권 1호, 247~280쪽
초록
2006년 보이스피싱으로 대표되는 전자금융사기 수법이 우리 사회에 등장한지 8년 정도가 지났다. 그 동안 전자금융사기로 인한 누적 피해액은 약 4,000억원을 넘는다고 한다. 금융기관은 이를 방지하기 위하여 전산 및 보안시스템 구축에 천문학적인 투자를 하고 있으나, 전자금융사기는 여전히 줄어들지 않고 더 교묘한 수법으로 진화하고 있다. 전자금융사기의 가해자를 검거하는 것이 쉽지 않은 상황에서, 피해자들은 전자금융거래법 제9조를 근거로 금융기관들에게 전자금융사기로 인한 손해의 배상을 구하는 예가 늘어나고 있다. 최근 이와 관련된 금융기관의 책임에 관한 대법원 판결이 나왔으나 다양한 쟁점을 다루고 있지는 않으므로, 현재로서는 하급심 판결이 판시한 내용을 바탕으로 하여 관련 법적 쟁점을 살펴보아야 할 것이다. 근간에 전자금융거래법이 2013. 5. 22. 일부개정되어 2013. 11. 23.부터 시행되었다. 주요한 개정조항 중의 하나가 전자금융거래법 제9조이다. 개정 전 전자금융거래법 제9조 제1항은 “금융기관등 또는 전자금융업자는 접근매체의 위조⋅변조로 발생한 사고, 계약체결 또는 거래지시의 전자적 전송이나 처리 과정에서 발생한 사고로 인하여 이용자에게 손해가 발생한 경우에는 그 손해를 배상할 책임을 진다”고 규정하였다. 그런데 위 조항만으로는 개인정보 해킹, 피싱, 파밍, 공인인증서 해킹, 메모리 해킹 등 전자금융사기의 다양한 유형을 포섭하기 어렵다는 문제가 있었다. 이에 2013. 11. 23. 개정법에서는 “전자금융거래를 위한 전자적 장치 또는 정보통신망에 침입하여 거짓이나 그 밖의 부정한 방법으로 획득한 접근매체의 이용으로 발생한 사고”가 전자금융거래법 제9조 제1항에 추가되었다. 개정으로 인하여 금융기관의 손해배상책임의 범위가 확대되었으나, 그 범위에 대한 논의가 추가적으로 필요한 상황이다. 본 논문은 하급심 판례를 중심으로 전자금융사기의 유형에 따라서 금융기관의 책임을 검토하여, 전자금융거래법 제9조에 따른 금융기관의 책임에 대한 일응의 기준을 제시하고자 한다. 본 논문을 계기로 금융기관의 책임에 대한 논의가 활발해지기를 기대해 본다. 본 논문에서는 우선 다양한 전자금융사기의 형태를 유형별로 분류하고, 금융기관이 각 유형별로 전자금융거래법 제9조 제1항에 따른 책임을 부담하는지 여부를 살핀다. 나아가 금융기관의 면책사유인 피해자의 고의⋅중과실의 범위, 금융기관의 손해배상책임이 인정되는 경우 그 책임의 범위, 과실상계 인정 여부, 다른 손해배상책임과의 관계도 함께 검토한다.
Abstract
Approximately 8 years have now passed since the form of electronic financial transaction fraud known as “voice phishing” came to the fore as a significant problem in Korea. Reports indicate that the cumulative value of harm caused by such electronic financial transaction fraud during this period comes to approximately KRW 400,000,000,000. Financial institutions have been investing heavily in the establishment of computer and security systems designed to combat this problem, but the extent of electronic financial transaction fraud remains undiminished, as increasingly devious phishing techniques continue to evolve. Given the difficulties associated with making criminal arrests of perpetrators in cases involving electronic financial transaction fraud, instances of victims seeking compensatory damages, based on the provisions of Article 9 of the Electronic Financial Transaction Act (“EFTA”) are on the rise. Thus far there has been no direct ruling by the Supreme Court concerning the liability of financial institutions in this regard, but the number of lower court rulings on such issues has been steadily accumulating. The EFTA was partially amended on May 22, 2013 and the amendment became effective as of November 23, 2013. Prior to amendment, the EFTA provided, in Article 9, Paragraph 1, that: “financial institutions or other companies engaging in electronic financial business shall be liable for providing compensation for losses incurred by users due to incidents [of fraud] involving counterfeit/falsified means of access, or incidents involving errors in the handling of electronic transmission of instructions or execution of contracts.” This provision of the EFTA has proven to be problematical, however, as a result of leaving the door open to interpretations asserting that it does not include within its scope losses arising due to various forms of electronic financial transaction fraud such as phishing, pharming, hacking of signature verification hacking, memory hacking, etc. The above-mentioned amendment has therefore added the following language to Article 9, Paragraph 1 of the EFTA: “any incident [of harm or loss] arising due to the use of the means of access acquired through deception or other improper means and unauthorized accessing of electronic devices or telecommunications networks for electronic financial transactions.” As a result of this amendment, the scope of compensatory liability borne by financial institutions has been expanded. It has therefore become necessary to focus additional attention and discussion upon the ramifications of such expanded scope of liability. The purpose of this paper is to propose standards, primarily derived from an examination of available lower-court rulings concerning financial institution liability in relation to types of electronic financial transaction fraud, which will serve, for the time being, as a reasonably clear point of reference with regard to the liability of financial institutions under Article 9 of the EFTA. It is hoped that this paper will also provide an impetus for promoting more active general discussions of financial institution liability in this area.
- 발행기관:
- 한국증권법학회
- 분류:
- 법학