Hacker Breach of Loan Solicitor Access System
Resident Registration Numbers, Income, and Loan Amounts Exposed... Violation of the Credit Information Act
FSS to Launch Inspection Following Joint Investigation with Bank, IT, and Security Teams

The Financial Supervisory Service (FSS) has launched an emergency on-site investigation into the customer data breach incident at Shinhan Bank. As of October 1, 2026, it has been confirmed that approximately 25,000 cases of borrower information have been leaked. The leaked data includes personal credit information such as individual income and loan amounts. The financial authorities are considering this a violation of the Credit Information Act.


25,000 Shinhan Bank Customer Records Leaked, Financial Supervisory Service Launches On-Site Investigation View original image

According to financial authorities on October 1, the FSS confirmed indications that some customer information related to loan solicitation at Shinhan Bank had been leaked externally and began an on-site investigation the previous day.


An official from the financial authorities stated, "We are verifying the scale of the leak of customer information related to loans," adding, "Staff from the bank, IT, and security departments are on-site conducting the investigation together."


This incident reportedly occurred not on the main Shinhan Bank website used by customers, but on a separate system accessed by loan solicitors as part of their work. This system contained personal data and credit information collected during the loan review and solicitation process, including the borrowers' resident registration numbers, income, and loan amounts entered by the solicitors.


The FSS is currently confirming the exact scope and type of the leaked information, the circumstances of the incident, and the status of internal controls and security management. Given that this constitutes a violation of the Credit Information Act, there is a high possibility that the investigation will be upgraded to a formal inspection after the on-site probe is concluded.


Some point out that this incident may have involved the use of the "credential stuffing" method. Credential stuffing is an attack technique in which attackers use account information, such as IDs and passwords obtained through other channels, to repeatedly attempt to log into a specific system.


However, it has been confirmed that this incident occurred within a separate system related to loan solicitation, and that the main Shinhan Bank internet and mobile banking systems used by general customers were not themselves hacked.



On the morning of October 1, the Financial Services Commission, the FSS, and other relevant authorities held a meeting to share information on the incident and check response measures.


This content was produced with the assistance of AI translation services.

© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.

Today’s Briefing