
Personal and credit information tied to loan applications from about 25,000 customers has been leaked from Shinhan Bank, prompting financial regulators to launch an emergency on-site investigation. The bank said it will fully compensate customers for any confirmed losses.
Shinhan Bank said on the 1st that an unauthorized outside party accessed certain services between the 29th of last month and the early hours of the 30th, using an abnormal method that bypassed authentication, and extracted customer information.
The leak identified so far covers about 25,000 people, and the exposed items include customer names, phone numbers, annual income and approved loan limits tied to loan applications. Resident registration numbers for 66 customers and 97 connecting information (CI) records were also confirmed to have been leaked.
Shinhan Bank has set up a separate lookup menu on its website so customers can check directly whether their own information was exposed and what was involved. Customers can check through the customer center on the website by selecting "Security Services → Privacy Policy → Customer Information Leak Lookup." The bank also plans to add a lookup menu to its Shinhan Super SOL app later in the day. It is operating a dedicated call center to handle damage reports and other inquiries.
Shinhan Bank said it will fully compensate customers for any confirmed losses from the leak and will concentrate its resources on protective measures and follow-up steps to minimize harm. The bank first became aware of the leak after detecting unusual signs through its own internal monitoring. Immediately after identifying the breach, it formed an emergency task force and activated a company-wide emergency response system, and it has completed urgent measures including blocking external internet protocol (IP) addresses, suspending related services and applying new security policies.

So far, banking services that require login authentication were not hacked, and some information was leaked through a simplified lookup service on the web, according to the bank. Some observers have raised the possibility of a "credential stuffing" attack, in which account names and passwords obtained elsewhere are entered repeatedly across multiple sites, but the specific method of attack has not yet been confirmed.
Shinhan Bank President Chung Sang-hyuk said in a public apology on the same day, "We feel the heavy weight of our responsibility that an information leak occurred at a financial company that must protect customers' valuable assets and information." He added, "We promise to take full responsibility and provide full compensation if customers suffer losses."
Shinhan Bank plans to prepare measures to prevent similar incidents from recurring and to improve its security policies to raise the overall level of customer information protection. The president said, "We will re-examine our entire personal credit information protection framework from the ground up and strengthen our work processes and employee training systems." He stressed, "We will mobilize all of our capabilities on damage recovery and prevention so that customers can use the bank with confidence."
The Financial Supervisory Service received a report from Shinhan Bank the previous day that information related to loan solicitation had been leaked and launched an emergency on-site investigation. The Banking Examination Department II and the IT Examination Department are investigating at the site how the incident occurred and the types and scale of the leaked information. On the morning of the 1st, the FSS held a review meeting with the Financial Services Commission to discuss follow-up steps such as customer notification. The specific extent of the damage is still under investigation.
An official at the financial authorities said, "Investigators handling banking and IT matters have been deployed to the site and are working to grasp the overall picture, including which personal information items were leaked and the scale."






