
Shinhan Bank failed to prevent a data leak despite earning perfect scores for six consecutive years in reviews of its personal credit information protection practices. The bank had also conducted security inspections of loan brokerage firms, yet a vulnerability surfaced in an inquiry service used by loan brokers.
Shinhan Bank received an S grade, or a perfect 100 points, for the sixth consecutive year in the Financial Services Commission's review of personal credit information management and protection practices, according to financial industry sources on the 2nd. The bank also holds domestic and international certifications including ISMS and ISMS-P, which certify information security and personal data protection management systems, and ISO 27001, the international standard for information security.
The bank has also run its own security inspection system. In a semiannual report, Shinhan Bank said it "conducts regular inspections and training for outsourcing and partner companies and manages the safety of personal data through systems such as its outsourcing and partnership management system and its personal data management system."
Inspections of loan brokerage firms were carried out regularly as well. Last year, while reviewing security across all companies entrusted with handling personal data, Shinhan Bank designated high-risk sectors such as loan brokerage firms as priority inspection targets. The bank said it tracks whether shortcomings identified in inspections are actually remedied.
Even so, information on about 25,000 customers was leaked through unauthorized access that bypassed authentication on a simplified inquiry service for loan brokers. The leaked data included names, phone numbers, annual incomes and loan limits. It has not been confirmed whether that service was covered by last year's inspection of brokerage firms.
With a breach occurring despite the perfect score and separate security inspections, questions are being raised about how effective the verification process is. Under the continuous information protection assessment, financial companies conduct their own reviews, and the Financial Security Institute checks the results before forwarding them to the FSC. "If the inspection results submitted by financial companies are not closely verified, the structure can allow security weaknesses to go unnoticed," an official in the financial industry said.
In response, the Financial Security Institute is pushing to raise the level of verification in the assessment. Starting this year, it will apply tougher criteria to eight categories including access rights and access logs, monitoring of abnormal activity, and vulnerability checks. It will also focus on whether protective measures are actually implemented and how follow-up actions are managed. From next year, it plans to add a penetration testing category.






