SBS NEWS

Exclusive Service for Loan Originators Breached... Shinhan Bank's Security Flaws Exposed


Add SBS News to Google preferred sources
Main image - SBS News

▲ Shinhan Bank

The customer information leak incident at Shinhan Bank reportedly occurred through the Shinhan mobile homepage service used by loan originators.

Critics point out that this has exposed Shinhan Bank's security vulnerabilities, as the hacking incident bypassed a pathway that does not exist at other banks.

Shinhan Bank CEO Jung Sang-hyuk stated in an apology posted on the homepage today (Oct. 1), "We have confirmed that an unauthorized external party leaked customer information from some services through abnormal methods."

The leaked information includes customer names, phone numbers, annual incomes, and loan limits, as well as 66 resident registration numbers and 97 connecting information (CI) items for some customers.

Customers affected by the leak amount to approximately 25,000.

Unlike other banks, Shinhan Bank loan originators can easily check the processing status of loans they have submitted through the mobile homepage "M Shinhan." The bank explains that an unauthorized external party accessed this pathway without going through normal identity verification procedures.

The bank explained that the attacker hacked the "telecommunication message structure" (code) of this originator-exclusive service, broke in, made random substitutions for inquiry input values to call up information, and then pilfered other information such as contact numbers using the customer numbers thus secured.

However, Shinhan Bank emphasized that applications directly used by customers, such as "Shinhan Super SOL," are unrelated to this incident.

A bank official repeatedly drew a line, stating, "This incident is a homepage information leak and has nothing to do with customer-facing banking apps that require formal authentication."

The Financial Services Commission and the Financial Supervisory Service reportedly convened an emergency response meeting this morning, and the Financial Security Institute has been on-site since yesterday investigating the cause of the incident.

It is expected to take several months until the final investigation results are announced.

Shinhan Bank has formed an emergency countermeasures committee and is operating an enterprise-wide emergency response system.

The bank also reported that emergency measures, such as blocking external IPs, suspending related services, and applying new security policies, have been completed.

This incident marks the second time this year that customer personal information has been leaked from a major commercial bank.

In early July, an incident occurred at Woori Bank where 17,551 items of personal information arbitrarily stored by an external development company were leaked due to negligence by an employee of that company.

(Photo: Yonhap News)

※

※ Please note: This article was translated by AI and may contain errors.
Copyright Ⓒ SBS & SBSi. All rights reserved.
Copying, redistribution, and unauthorized use in AI training are strictly prohibited.
Min Gyeongho View More Articles
AD
AD
AD
AD