A data breach at Shinhan Bank has raised concerns about the security and privacy management systems within the banking sector. The incident, which involved the leak of loan-related information, has heightened fears of secondary damage targeting customers' financial data.
According to the financial sector on October 1, the Financial Supervisory Service (FSS) has been conducting an emergency on-site investigation into the customer data breach since the previous day. Shinhan Bank confirmed that unauthorized external individuals accessed certain services through abnormal methods to leak customer information.
In a public apology, Shinhan Bank CEO Jung Sang-hyuk stated, "I sincerely apologize on behalf of all Shinhan Bank employees for the worry and inconvenience caused to our customers." He promised to fully compensate any damages incurred by customers due to the breach.
As of now, approximately 25,000 customers have been identified as affected by the data leak. The leaked information includes customer names, phone numbers, annual income, and personal credit information related to loan applications. Additionally, 66 cases of resident registration numbers and 97 cases of linked information (CI) have also been confirmed as leaked. The exact extent of the damage is still being assessed, and the scale of the leak may increase based on the investigation's findings.
The breach is believed to have occurred through a simple inquiry service used by loan solicitors. The FSS is investigating the specific methods of the attack, the circumstances surrounding the data leak, and the extent of the breach. The possibility of a 'credential stuffing' attack has not yet been confirmed.
This incident raises concerns about potential secondary damage, as not only names and phone numbers but also financial information such as annual income and loan limits were leaked. There is a risk that the leaked information could be used to impersonate bank officials or approach customers regarding their loan eligibility. However, no actual cases of secondary damage have been confirmed so far.
In July, Woori Bank disclosed a data breach involving customer information from an external developer participating in the construction of an NFT platform. A total of 17,551 pieces of information were leaked, including user nicknames and linked information (CI). The incident was attributed to the information management processes of the external company involved in the platform's development. The bank apologized to customers and stated it would compensate for any damages resulting from the breach.
Immediately after recognizing the incident, Shinhan Bank established an emergency response team and implemented urgent measures, including blocking external IPs, suspending related services, and applying new security policies. A menu has been created on the bank's website to check for data leaks, and related features will be added to the 'Shinhan SuperSOL' app later today. A dedicated consultation center for reporting damages and inquiries is also being operated.
Shinhan Bank plans to conduct a comprehensive review of its personal credit information protection system and will work on improving operational procedures and security policies, as well as enhancing employee training to prevent future incidents.
* This article has been translated by AI.
Copyright ⓒ Aju Press All rights reserved.
