
Shinhan Bank announced on the 1st that it has confirmed an incident in which unauthorized access to certain services was gained through abnormal methods bypassing external authentication, resulting in the leakage of customers’ personal (credit) information, and deeply apologized to customers and the public.
It is currently assessed that customer information for approximately 25,000 individuals has been leaked. The leaked items include personal (credit) information related to loan applications, such as customer names, phone numbers, annual income, and calculated limits, as well as resident registration numbers (66 cases) and CI (linked information, 97 cases) for some customers.
Shinhan Bank stated that it immediately formed an emergency response team and activated a company-wide emergency response system upon recognizing the data breach. It completed emergency measures to prevent further damage, including blocking external IPs, suspending related services, and applying new security policies, and is currently verifying the exact circumstances of the incident and the scope of the damage.
Additionally, Shinhan Bank has established a separate verification menu on its homepage so that customers can directly check whether their information was leaked and review related details. It plans to open a verification menu on the “Shinhan Super Sol App” within today as well. A dedicated counseling center is also being operated to respond promptly to damage reports and other inquiries.
The bank has stated its policy of fully compensating for any customer damage confirmed to have resulted from this data breach. It plans to concentrate all resources on necessary protective measures and follow-up responses to minimize customer damage.
Along with this, the bank will re-examine the entire personal credit information protection system from scratch and prepare practical measures to prevent similar incidents from recurring. It intends to comprehensively raise the level of customer information protection by improving business processes and security policies, as well as strengthening employee training.
Shinhan Bank President Normal Hyeok said, “As a financial institution responsible for protecting customers’ valuable assets and information, I deeply feel the heavy responsibility for the occurrence of this data breach incident,” adding, “I sincerely apologize to all customers for the worry and inconvenience caused.”
He continued, “We will invest all our resources in damage recovery and prevention of recurrence so that customer anxiety is alleviated and they can use Shinhan Bank with peace of mind,” stating, “All employees will do their utmost to restore customer safety and trust.”