Shinhan Bank Data Breach Hits 25,000 Customers

Names, Annual Income and Approved Loan Limits Exposed in Loan Application Records Bank Blocks External IP Addresses and Suspends Affected Services Online Lookup Menu Added to Website for Customers to Check Exposure

Finance|
|
By Shin Joong-sup and Do Hye-wonjseop@sedaily.com, dohye1@sedaily.com
||
A view of Shinhan Bank's headquarters. Shinhan Bank - Seoul Economic Daily Finance News from South Korea
A view of Shinhan Bank's headquarters. Shinhan Bank

Personal and credit information tied to loan applications from about 25,000 customers has been leaked from Shinhan Bank, prompting financial regulators to launch an emergency on-site investigation. The bank said it will fully compensate customers for any confirmed losses.

Shinhan Bank said on the 1st that an unauthorized outside party accessed certain services between the 29th of last month and the early hours of the 30th, using an abnormal method that bypassed authentication, and extracted customer information.

The leak identified so far covers about 25,000 people, and the exposed items include customer names, phone numbers, annual income and approved loan limits tied to loan applications. Resident registration numbers for 66 customers and 97 connecting information (CI) records were also confirmed to have been leaked.

Shinhan Bank has set up a separate lookup menu on its website so customers can check directly whether their own information was exposed and what was involved. Customers can check through the customer center on the website by selecting "Security Services → Privacy Policy → Customer Information Leak Lookup." The bank also plans to add a lookup menu to its Shinhan Super SOL app later in the day. It is operating a dedicated call center to handle damage reports and other inquiries.

Shinhan Bank said it will fully compensate customers for any confirmed losses from the leak and will concentrate its resources on protective measures and follow-up steps to minimize harm. The bank first became aware of the leak after detecting unusual signs through its own internal monitoring. Immediately after identifying the breach, it formed an emergency task force and activated a company-wide emergency response system, and it has completed urgent measures including blocking external internet protocol (IP) addresses, suspending related services and applying new security policies.

null - Seoul Economic Daily Finance News from South Korea

So far, banking services that require login authentication were not hacked, and some information was leaked through a simplified lookup service on the web, according to the bank. Some observers have raised the possibility of a "credential stuffing" attack, in which account names and passwords obtained elsewhere are entered repeatedly across multiple sites, but the specific method of attack has not yet been confirmed.

Shinhan Bank President Chung Sang-hyuk said in a public apology on the same day, "We feel the heavy weight of our responsibility that an information leak occurred at a financial company that must protect customers' valuable assets and information." He added, "We promise to take full responsibility and provide full compensation if customers suffer losses."

Shinhan Bank plans to prepare measures to prevent similar incidents from recurring and to improve its security policies to raise the overall level of customer information protection. The president said, "We will re-examine our entire personal credit information protection framework from the ground up and strengthen our work processes and employee training systems." He stressed, "We will mobilize all of our capabilities on damage recovery and prevention so that customers can use the bank with confidence."

The Financial Supervisory Service received a report from Shinhan Bank the previous day that information related to loan solicitation had been leaked and launched an emergency on-site investigation. The Banking Examination Department II and the IT Examination Department are investigating at the site how the incident occurred and the types and scale of the leaked information. On the morning of the 1st, the FSS held a review meeting with the Financial Services Commission to discuss follow-up steps such as customer notification. The specific extent of the damage is still under investigation.

An official at the financial authorities said, "Investigators handling banking and IT matters have been deployed to the site and are working to grasp the overall picture, including which personal information items were leaked and the scale."

Original reporting by Shin Joong-sup and Do Hye-won for Seoul Economic Daily.

AI-translated from Korean. Quotes from foreign sources are based on Korean-language reports and may not reflect exact original wording.

Watch · Seoul Economic Daily

More →
4:17

AI KEY

Preview
Korean Corporate Intelligence HubKOSPI · KOSDAQ · 12 sectors

A live, cap-weighted view of every KOSPI and KOSDAQ sector, with same-day Korean reporting distilled by company — built for foreign investors, correspondents and analysts who need to scan Korea before the next session.

Korea Company Atlas

Preview
Market Ontology · The Feedback LoopKFTC 2025 · 92 groups · 121,954 articles

An English ontology of the Korean market — how companies, the media, the government and the National Assembly move each other in a loop. Korea's named controlling persons and designated business groups are a mechanism, not a risk to be priced blind.

SIGNAL

Now live
English Edition · Capital MarketsM&A · IPO · PE · Fund Flows

SIGNAL English Edition is live — Korea's deal desk reporting in English. M&A, IPOs, private equity and fund flows, covered daily for global institutional investors. Browse free; subscriber-only scoops at the 50% intro rate.