▲ Shinhan Bank
A large-scale hacking incident has occurred at Shinhan Bank, resulting in the leakage of customer information for approximately 25,000 individuals.
Financial authorities have launched an emergency on-site inspection, and Shinhan Bank CEO Jung Sang-hyuk issued a public apology.
Shinhan Bank confirmed yesterday (September 30) that a hacking incident had taken place, leading to the leakage of loan-related customer information.
In an apology posted on the bank's website today, CEO Jung stated, "We have confirmed that unauthorized external parties recently used abnormal methods to leak customer information from some of our services."
He explained, "Personal (credit) information related to loan applications has been leaked, including customer names, phone numbers, connection information (CI), annual income, and calculated credit limits," adding, "It has been confirmed that information belonging to approximately 25,000 customers has been leaked so far."
Specifically, the bank stated that the leaked information includes 66 instances of resident registration numbers and 97 instances of CI.
CEO Jung said, "As soon as we became aware of the personal information leak, we activated an enterprise-wide emergency response system and completed necessary urgent measures, including blocking external IP addresses, suspending related services, and applying new security policies."
He continued, "We offer our deepest apologies for causing concern to our customers," and promised, "Should any customers suffer damages, we will take full responsibility and compensate them entirely."
CEO Jung added, "We take this information leakage situation very seriously," and vowed, "We will completely overhaul our personal credit information protection system from scratch, improve business processes, and strengthen employee training frameworks."
Some raise the possibility that the personal information was leaked via a "credential stuffing" attack technique.
Credential stuffing is a hacking method in which an attacker acquires account and password information through certain means and indiscriminately attempts logins on other sites until successful.
However, it is reported that the login authentication-based banking service itself was not hacked.
The Financial Supervisory Service (FSS) launched an emergency on-site inspection today regarding the leakage of Shinhan Bank customer information.
The Financial Services Commission and the FSS held an emergency response meeting this morning to discuss the circumstances of the incident and follow-up measures.
(Photo: Yonhap News)
※
Copying, redistribution, and unauthorized use in AI training are strictly prohibited.