Security

Shinhan Bank Says 25,000 Loan Records Leaked; FSS Launches On-Site Probe

IT DAILY ·

A view of Shinhan Bank headquarters in Jung-gu, Seoul [Photo: Shinhan Bank]

✦ Resumen de IA

Shinhan Bank said in a notice on its website on the 1st that an external unauthorized party had infiltrated its systems and that a leak of customer information had been confirmed in some services.

The estimated scope of the leak is about 25,000 people, and it includes personal credit information related to loan applications as well as customers' names, phone numbers, CI, annual income, and assessed limits.

The Financial Supervisory Service has launched an emergency on-site inspection to determine the scale of the damage, and the Financial Services Commission and the FSS plan to hold a meeting and conduct an emergency inspection to review the situation.

A personal data breach has occurred at Shinhan Bank. In a notice on its website on the 1st, the bank said an external unauthorized party had infiltrated its systems and that a leak of customer information had been confirmed in some services.

Shinhan Bank activated an emergency response system immediately after becoming aware of the incident. It then moved to block external IPs and suspend related services.

The estimated scale of the leak is about 25,000 people. The leaked information was identified as personal credit information related to loan applications.

The leaked items included customers' names, phone numbers, CI, annual income, and assessed limits. As the scope of the leak became clear, the Financial Supervisory Service launched an emergency on-site inspection.

Regarding the Shinhan Bank personal data breach, Shinhan Bank CEO Jeong Sang-hyeok said the bank would fully compensate customers for any damage caused by the leak. Jeong said all Shinhan Bank executives and employees are treating the situation with the utmost seriousness, and stated that the bank would do its best to protect customers and restore trust. He also said the bank would work to ease customer anxiety and restore a state in which customers can use Shinhan Bank with confidence.

Jeong also said the bank would mobilize all its capabilities to recover losses and prevent a recurrence. As the bank's CEO, he once again apologized on behalf of all executives and employees.

According to the financial sector, the FSS began an emergency on-site inspection on the day. The FSS is confirming the scale of the damage from Shinhan Bank's personal data breach. Some are raising the possibility of Credential Stuffing as the cause of the leak.

Credential Stuffing is a hacking method in which an attacker repeatedly tries stolen account and password information until a login succeeds. In January, GS Retail also experienced a Credential Stuffing attack in 2024-2025. At the time, the victims were 1,581,025 GS Shop members and 79,128 GS25 members, and the leaked information included personal data such as names, genders, dates of birth, contact numbers, addresses, and email addresses.

While it is known that the banking service itself was not the target of the hack, the Financial Services Commission and the FSS plan to hold a meeting to confirm the situation and also carry out an emergency inspection.

Source: IT DAILY · Kim Ho-jun
Original: https://www.itdaily.kr/news/articleView.html?idxno=241958

References

This article was produced with the help of an automated content generation algorithm.


Source: IT DAILY

Ver original

This article was summarized and organized by BizCrush based on the original article from IT DAILY. For exact quotations and full details, please refer to the original article.