Cyber & AI intelligence
Wasteland.
Briefs indexed2950
Issues30
Published Mondays07:30 CT
▣ Breach SHINHAN-BANK-CUSTO 2026-10-01

Shinhan Bank: Authentication Bypass Exposes Loan Data of 25,000 Customers

"Shinhan Bank, one of South Korea's largest commercial lenders, has confirmed that an unauthorized outside party took personal and credit information belonging to about 25,000 customers. The data came from the bank's…"

Shinhan Bank, one of South Korea's largest commercial lenders, has confirmed that an unauthorized outside party took personal and credit information belonging to about 25,000 customers. The data came from the bank's loan application process and includes names, phone numbers, annual income and calculated loan limits. A small subset of records also contains resident registration numbers and Connecting Information (CI) identifiers. The bank's president published an apology on October 1 and promised full compensation for any customer who suffers losses. The Financial Supervisory Service (FSS) has opened an emergency on-site inspection, and the Financial Services Commission (FSC) held an emergency meeting on follow-up measures (Korea Times, Chosunbiz). Parent company Shinhan Financial Group has also reported the incident to US investors in a Form 6-K filing (summarised by StockTitan). No threat actor has been named, and nobody has publicly claimed the attack.

What Happened

Shinhan Bank says it confirmed the incident on September 30. In its words, "an unauthorized external party leaked customer information from some services using abnormal means" (Asia Business Daily, SBS, Chosunbiz). Most outlets report the confirmation date as September 30. The Herald Business and Korea Times describe the confirmation as taking place on Thursday, October 1, which is probably the date the bank disclosed it publicly.

Reports also differ on when regulators arrived. The Seoul Economic Daily says the FSS sent staff to the bank on the afternoon of September 30. The Herald Business and Chosunbiz describe the inspection as starting on October 1. The Herald Business adds that two FSS units are involved: Bank Inspection Bureau 2 and the IT Inspection Bureau. The Korea Times says the inspection followed a report filed by Shinhan Bank itself.

The bank says it set up an emergency response team as soon as it found the breach and switched on a company-wide crisis system. Its containment steps included:

The bank also opened a self-service leak lookup on its website, under Security Services, then Personal Information Protection Policy, then Customer Information Leak Inquiry. It is adding the same lookup to its mobile app; the Herald Business calls the app "Shinhan Super SOL" and Yonhap Infomax calls it "Shinhan SOL." A dedicated hotline is open at 1544-2946 (Herald Business).

Sources do not agree on the executive's name. The Asia Business Daily renders it as "Sung Hyuk Jung, President." SBS and the Korea Times give "Jung Sang-hyuk, CEO." In his statement he said the bank "take[s] full responsibility for the fact that an information breach occurred at a financial institution entrusted with protecting our customers' valuable assets and information" (Korea Times). He also pledged to rebuild the bank's personal credit information protection system "from scratch" (SBS).

The 6-K summary does not give a record count. It says Shinhan Bank is investigating the cause, scope and impact "with relevant authorities and external cybersecurity experts." It adds that the bank cannot yet reasonably quantify any financial effect and will make further disclosures if it finds matters material to investors.

What Was Taken

Every source that gives a number puts it at about 25,000 affected customers. No source offers a competing figure. Chosunbiz warns that the total "could rise depending on the investigation," and the bank says it is still working out the full scope.

The leaked data is personal credit information gathered during loan applications:

Most of the 25,000 records contain contact details plus financial profile data, not full identity credentials. Even so, a name and phone number combined with known income and a pre-approved loan limit is a strong starting point for targeted fraud. The 66 records with resident registration numbers carry the highest long-term risk.

Why It Matters

This data is ideal for phishing. Korea has a long-running problem with voice phishing ("boiseu-pising"), and loan scams are one of its most common forms. An attacker who knows a victim's name, number, income and approved loan limit can pose as a loan broker or bank officer and sound very convincing. Defenders should expect follow-on social engineering, not direct account takeover.

The likely entry point was a low-profile system. Chosunbiz reports, citing financial sector and regulatory sources, that the breach happened in a "simplified information system used by loan brokers." According to that report, the system stores personal information of borrowers who got Shinhan loans through brokers. The same report says login-authenticated banking services "do not appear to have been hacked." Instead, data appears to have been taken "through a simple inquiry service on the web." The bank has not confirmed any of this, and only one source reports it. If it holds up, it is a familiar pattern: a secondary or partner-facing portal, built for convenience, ends up holding regulated data without the controls applied to the core banking platform.

Regulators are treating this as serious. The FSS sent both a banking unit and an IT inspection unit, and the FSC called an emergency meeting. Both point to scrutiny that could reach beyond Shinhan to how other Korean lenders secure their broker and partner channels.

The financial impact is still open. The bank has promised full compensation and filed a 6-K, but has not yet quantified the cost. Regulatory penalties under Korea's Credit Information Use and Protection Act and Personal Information Protection Act remain possible.

The Attack Technique

Technical detail is limited, and nothing below comes from a forensic report. Here is what the sources say:

Taken together, the reporting is consistent with an attacker repeatedly querying a lookup endpoint that had weak or missing authorization checks, collecting records one at a time. This is a broken-access-control or IDOR-style pattern, not a network intrusion. This is an analytical inference, not a confirmed finding. The FSS and Shinhan say the attack route and method are still under investigation. No malware, threat actor or ransom demand has been reported.

What Organizations Should Do

  1. Inventory partner-facing and "lite" portals. List every broker, agent, affiliate and inquiry interface that can return customer data. Apply the same authentication, authorization and logging standards used on core banking systems. Convenience portals are often where those standards slip.
  2. Enforce server-side object-level authorization. Every request for a customer record should be checked against the caller's identity and entitlement on the server, not only at login. Test explicitly for IDOR and parameter-tampering bypasses.
  3. Rate-limit and alert on enumeration. One source pulling thousands of distinct customer records through a lookup function is a clear signal. Set per-client query thresholds, flag sequential identifier access, and alert on unusual volumes from new IP ranges.
  4. Minimise data in secondary systems. Ask whether broker-facing systems need to hold full income, credit limit or national ID data. Tokenise or truncate where you can so that a breach of the edge system exposes less.
  5. Prepare customers for follow-on fraud. After a leak like this, tell affected customers proactively that the institution will never ask for credentials or transfers by phone. Work with telecom and anti-fraud partners to flag impersonation campaigns that use the leaked attributes.
  6. Keep breach-response tooling ready. Shinhan's self-service lookup and dedicated hotline are worth copying. Have these ready before an incident so disclosure, containment and customer support can happen within hours.

Sources: Shinhan Bank Apologizes for Customer Data Leak: "Grave Responsibili... | Shinhan Financial reports Shinhan Bank data incident SHG SEC Filin... | Shinhan Bank CEO Says 25,000 Customers' Data Leaked, Pledges Full C... | Customer Information of 25,000 Shinhanc Bank Clients Leaked... Fina... | Shinhan Bank data breach exposes personal information of 25,000 cus... | Shinhan Bank Apologizes for Data Breach Affecting 25,000 Customers... | Shinhan Bank hit by data breach affecting 25,000 customers - The Ko... | Shinhan Bank data leak hits 25,000 as Korea watchdog launches probe...