Shinhan Bank Says Personal Information of More Than 25,000 People Leaked
TECHWORLD · · 4 views
✦ Resumen de IA
Shinhan Bank said it had identified signs of hacking through abnormal bypass authentication in some services and posted an apology for the personal information leak.
The leaked information was personal data related to loan applications, including names, phone numbers, 97 CI records, annual income, and calculated loan limits. So far, information for more than 25,000 people and 66 cases of resident registration number exposure have been confirmed.
The bank activated an enterprise-wide emergency response system, blocked external IPs, suspended related services, and applied new security policies, while credential stuffing has been raised as a possible attack method.
A personal information leak occurred in some Shinhan Bank services. On the 1st, Shinhan Bank posted an apology for the leak on its official website and said it had identified signs of hacking through abnormal bypass authentication in some services, with customer personal information leaked in the process. Credential stuffing was raised as a possible method of attack.
The bank said the leaked information was personal data related to loan applications. The leaked items included names, phone numbers, 97 CI records, annual income, and calculated loan limits. So far, customer information confirmed to have been leaked covers more than 25,000 people, and 66 cases of resident registration number exposure were also confirmed in some cases.
In relation to the incident, caution is needed regarding password management and the prevention of secondary damage. After recognizing the leak of personal information, Shinhan Bank activated an enterprise-wide emergency response system.
As emergency measures, Shinhan Bank completed blocking external IPs, suspending related services, and applying new security policies. It is currently confirming the exact cause of the incident and the extent of the damage.
The industry has raised the possibility that credential stuffing was used in the Shinhan Bank personal information leak. However, the specific attack method has not yet been confirmed.
If it is confirmed as credential stuffing, this would be a case in which account information leaked from other services was used to attack financial services. The industry says the risk deserves attention.
Credential stuffing involves securing IDs and passwords leaked from other websites and services, then indiscriminately trying them on other websites and financial services to attempt logins.
The targets of this attack are users who use the same ID and password across multiple services.
As a response measure, it is recommended to first suspect any unexpected contact from a bank. Users should also use unique passwords and activate multi-factor authentication.
In addition, users should check whether other credentials have been exposed and refrain from clicking links in emails or text messages indiscriminately.
As a response to the incident, monitoring financial accounts closely and using a VPN on untrusted networks were suggested.
Hwang Seong-ho, country manager of NordVPN Korea, said that if the cause of the incident is credential stuffing, it is a case that once again confirms the risk of using the same password across multiple websites. He explained that login information compromised in one service can lead to the automated theft of credentials for many unrelated accounts.
This incident is characterized by the fact that both personal information and financial information were leaked at the same time. Because of this, concerns have been raised that the leaked information could be used and lead to secondary damage.
In particular, it was pointed out as a concern that the leaked phone numbers could be combined with income and loan limit information. Such combined information has been analyzed as potentially being used for targeted phishing or financial fraud aimed at victims.
Hwang Seong-ho, country manager of NordVPN Korea, said that while a phone number alone has limited value, when it is linked with income information and a potential loan limit, it creates the context needed for personalized fraud. He added that if generative AI is used, impersonation using information about individual victims could become easier, stressing the need to be cautious about fraud exploiting data leaks.
Source: TECHWORLD · Kim Hye-jin
Original: https://www.epnc.co.kr/news/articleView.html?idxno=407738
References
This article was produced with the help of an automated content generation algorithm.
Source: TECHWORLD
Ver originalThis article was summarized and organized by BizCrush based on the original article from TECHWORLD. For exact quotations and full details, please refer to the original article.