Loading...
Share

Customer Information of 25,000 Leaked at Shinhan Bank... CEO Sang-hyuk Jung Promises "Full Compensation for Damages"

신한은행 (사진=연합뉴스)
▲ Shinhan Bank
 
A large-scale hacking incident at Shinhan Bank has resulted in the leakage of personal information for approximately 25,000 customers.

According to the financial sector and financial authorities, Shinhan Bank confirmed the hacking incident, in which loan-related customer information was leaked, yesterday (September 30).

Following the incident, the Financial Supervisory Service launched an emergency on-site inspection of Shinhan Bank today, and the Financial Services Commission and the Financial Supervisory Service held a response meeting this morning to discuss the circumstances of the breach and follow-up measures.

An official from the authorities stated that they are currently conducting a comprehensive assessment of the nature and scale of the leaked information.

Shinhan Bank CEO Sang-hyuk Jung issued a public apology.

Through an apology posted on the website today, CEO Jung stated, "We recently confirmed that an unauthorized external party accessed customer information from some services using abnormal methods."

He explained, "Personal information related to loan applications, such as customer names, phone numbers, connection information (CI), annual income, and calculated limits, was leaked, and it has been confirmed that information for approximately 25,000 customers has been leaked so far."

Specifically, the bank stated that the leaked information included 66 resident registration numbers and 97 pieces of connection information.

CEO Jung said, "As soon as we recognized the personal information leak, we activated an enterprise-wide emergency response system and completed necessary emergency measures, including blocking external IPs, suspending related services, and applying new security policies."

He added, "We offer our deepest apologies for causing concern to our customers, and we promise to take full responsibility and compensate for any damages incurred by our customers."

CEO Jung added, "We take this information leak very seriously and will completely reexamine our overall personal credit information protection system, improve business processes, and strengthen employee training frameworks."

Some raise the possibility that the personal information was leaked through a "credential stuffing" attack method.

Credential stuffing hacking is a method where an attacker acquires account and password information through certain means and indiscriminately attempts logins on other sites until successful.

However, it is reported that login authentication-based banking services were not hacked.

(Photo: Yonhap News)
※ Please note: This article was translated by AI and may contain errors.
Copyright Ⓒ SBS & SBSi. All rights reserved.
Copying, redistribution, and unauthorized use in AI training are strictly prohibited.