Shinhan Bank hit by data breach affecting 25,000 customers

Shinhan Bank's headquarters in Jung District, Seoul / Courtesy of Shinhan Bank

Shinhan Bank's headquarters in Jung District, Seoul / Courtesy of Shinhan Bank

Shinhan Bank apologized Thursday after personal information belonging to about 25,000 customers was leaked in a data breach, as financial regulators launched an urgent inspection into the incident.

According to the bank, the leaked information includes customers' names, phone numbers, annual income and loan eligibility limits, as well as other personal and credit information submitted for loan applications.

The data also included 66 cases involving resident registration numbers and 97 cases involving connected information.

The breach occurred as an unauthorized external party gained access to some of its services through an abnormal method that bypassed authentication.

Shinhan Bank CEO Jung Sang-hyuk apologized and said the bank will take full responsibility for any losses.

"We take full responsibility for the fact that an information breach occurred at a financial institution entrusted with protecting our customers' valuable assets and information," Jung said in a statement.

Shinhan Bank CEO Jung Sang-hyuk attends a meeting at the Korea Federation of Banks' headquarters in Seoul, Jan. 20, 2025. Korea Times photo by Lee Han-ho


"I sincerely apologize for causing concern and inconvenience to our customers. We will devote all resources to address any damage, preventing a recurrence and regaining customers' trust," he added.

Shinhan said it activated an emergency response team immediately after detecting the breach and took a series of measures, including blocking external IP addresses and suspending affected services.

It said it will conduct a review of its personal information protection system, improve security policies and strengthen employee training to prevent similar incidents.

The bank has also set up a dedicated page on its website where customers can check whether their information was leaked. The feature is also available on the bank's mobile app. A dedicated call center has been established to handle reports related to the data breach.

The bank's announcement came as financial regulators launched an urgent investigation into the incident.

Earlier in the day, the Financial Supervisory Service (FSS) conducted an on-site inspection of Shinhan Bank after receiving a report from the bank that some customer information related to loan applications had been leaked.

The FSS and the Financial Services Commission held an emergency meeting to discuss the circumstances surrounding the breach and follow-up measures.

Some have raised the possibility that the attack involved so-called credential stuffing, a technique in which attackers use account credentials obtained through other means to repeatedly attempt to gain access to another service.

The main target of the attack was a platform used by loan brokers to store customer information as part of the loan application process. The breach could have wider impact, as the platform handles sensitive data such as borrowers' credit profiles and information related to their loans.


Interesting contents

Taboola 후원링크

Recommended Contents For You

Taboola 후원링크