Attacker bypassed identity verification, then repeatedly cycled query values to extract customer data
AI-assisted automated attack suspected; Korea Financial Security Institute investigating
A security gap in a portal reserved exclusively for loan solicitation agents is believed to be the origin of a data breach that exposed the personal information of about 25,000 Shinhan Bank customers. The vulnerability allowed unauthorized access to customer data through a dedicated service designed to let loan agents track the progress of applications they had submitted, without completing the normal identity-verification process.
According to financial industry sources Thursday, an outside attacker analyzed the architecture of the loan agent service on Shinhan Bank's mobile website "M Shinhan" and found a way to bypass standard authentication. The attacker then repeatedly cycled through randomized customer identification numbers and other query values to pull up customer records. Using the data obtained that way, the attacker extracted additional personal details including phone numbers, annual income figures and loan limit calculations.
Banking industry observers say the very structure of the service — allowing loan agents to look up customers' application status through a web portal — became the weak link in this incident. Whether the bank had adequate systems to detect and block anomalies such as repeated queries from the same source or access from unusual IP addresses is also expected to be part of the investigation.
The number of affected customers confirmed so far stands at about 25,000. The leaked data includes customer names, phone numbers, annual income figures and calculated loan limits. The breach also exposed 66 resident registration numbers and 97 connected information (CI) records used for personal identification.
There is growing speculation that an AI agent may have been used in the attack. Security industry experts say attacks that use AI to rapidly cycle through large numbers of input values and automatically probe for vulnerabilities are on the rise. However, the exact tools and methods used in this incident will not be confirmed until the Korea Financial Security Institute and other investigators complete their probe.
Shinhan Bank President Jung Sang-hyuk posted an apology on the bank's website Thursday, confirming that an unauthorized outside party had accessed certain services through abnormal means and leaked customer information. The bank said it blocked external IP connections, suspended the relevant service and applied new security policies after becoming aware of the incident.
The Financial Services Commission and the Financial Supervisory Service have also launched emergency responses. The Korea Financial Security Institute is conducting an on-site investigation to determine the attack vector, the full scope of the leak and whether Shinhan Bank's security systems functioned as intended. Shinhan Bank drew a line between the breach and its general banking applications used by retail customers, saying services such as "Shinhan Super SOL" were not affected.
brunch@heraldcorp.com
