25,000 Shinhan Bank Customers' Data Exposed... Includes Annual Income and Loan Information
Resident Registration Numbers and CI Also Leaked for Some; 119 KB Kookmin Bank Customers Affected
Peripheral Work and Inquiry Services, Not Core Banking Systems, Come Under Attack
Financial Authorities Urgently Summon Banks; Comprehensive Review of External Access Routes

Following the incident at Shinhan Bank, a data breach resulting in the leak of customer information has also occurred at KB Kookmin Bank. With two out of the five major banks consecutively confirming information leaks, the financial industry is on heightened alert. Notably, rather than core financial systems such as internet or mobile banking, it was systems like staff work support platforms or simple inquiry services—services with increased exposure to external contact—that have been targeted. This has prompted calls for a comprehensive reevaluation of security frameworks across the banking sector.

After Shinhan's Massive Data Breach Including Income and Loan Details, KB Kookmin Bank Also Leaks Customer Information (Comprehensive) View original image

According to the financial industry on October 2, KB Kookmin Bank announced that the personal and credit information of 119 customers had been leaked due to an external breach. The leaked information includes customer names, phone numbers, addresses, and encrypted resident registration numbers, varying by customer.


The target of this attack was a mobile work support system used by employees. After detecting the possibility of data exposure via abnormal external access on the night of September 30, KB Kookmin Bank immediately blocked the affected server and access routes. The bank notified impacted customers about the breach and provided guidance on how to prevent secondary damage.


KB Kookmin Bank explained that this incident does not affect the bank's customer financial transaction systems, such as internet banking or mobile banking. Since the Financial Supervisory Service had been conducting a regular inspection of KB Kookmin Bank, the on-site IT inspection team began investigating the circumstances and the extent of the breach starting the previous night.


KB Kookmin Bank has stated that it will fully compensate customers should any damage arise from this incident. A bank representative said, "We are taking this situation extremely seriously," adding, "We are operating an emergency response system across the entire organization and thoroughly reviewing all processes from the ground up to prevent additional damage and recurrence in the future."


Previously, Shinhan Bank experienced a large-scale incident where the information of approximately 25,000 customers was exposed externally. Not only was the scale of the leak far larger than that of KB Kookmin Bank, but the leaked data also included, beyond names and phone numbers, annual income, loan-related information, and even portions of resident registration numbers and linkage information (CI).


The Shinhan Bank incident began with a simple inquiry service on the mobile website used by loan solicitors. An unauthorized external party bypassed authentication steps to gain unauthorized access to the service, entering values such as receipt numbers at random to extract details about loan applications, requested amounts, and approved amounts.


The attacker then used customer numbers obtained in this way to access other simple inquiry services, which could reveal internet banking registration status and currency exchange activity. The information identified as leaked to date includes customer names, phone numbers, annual income, and calculated limits—i.e., loan-related data—including 66 cases of resident registration numbers and 97 cases of linkage information (CI) for some customers.


In particular, the fact that information acquired from one simple inquiry service served as the basis for accessing others highlights the need to review whether Shinhan Bank's authentication and access control systems for each service were adequate.


In both incidents, the banks assert that their core banking systems were not directly compromised. However, because customer data was continuously leaked through externally accessible work and inquiry systems, the adequacy of authentication and access control measures for services operating outside the main banking networks is expected to become a key focus in the regulatory investigation.


Financial authorities are also escalating their response. With consecutive customer data leaks confirmed at Shinhan Bank and KB Kookmin Bank—two of the five major banks—authorities plan to urgently gather commercial bank officials later this afternoon to review internal inspection statuses, external access routes, and overall information security systems. As there is even speculation that AI technology may have been leveraged in the attack, authorities are also expected to examine whether similar breaches have occurred at other financial institutions.


An official said, "Following the confirmation of the Shinhan Bank breach yesterday, each bank has initiated its own inspection," adding, "At today's meeting, we will check the relevant inspection status and discuss the overall information security posture and countermeasures, including external access routes utilized by banks."


Concerns are mounting due to a series of data breaches centered on the financial and platform sectors. At Woori Bank, a July incident caused by an external development vendor’s mistake led to the breach of 17,551 pieces of customer information such as nicknames and IDs. Since then, the banking industry has strengthened vulnerability assessments using AI and measures to protect linkage information.


The timing of the breach adds to the challenge for Shinhan Bank. Shinhan Financial Group has already begun CEO succession procedures for subsidiaries whose terms end at year-end, with Shinhan Bank President Jung Sanghyuk's term also ending on December 31. With the National Assembly's audit scheduled as well, if further security management lapses are identified as the incident is handled and investigated by regulators, pressure on management is expected to grow.



An industry source said, "As technology to protect and store data becomes more sophisticated, methods to steal such data evolve even more swiftly, leaving the entire industry in a perpetual state of alert."


This content was produced with the assistance of AI translation services.

© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.

Today’s Briefing