Shinhan Bank hit by data breach affecting 25,000 customers新韩银行遭遇数据泄露,25000名客户受到影响
Shinhan Bank apologized Thursday after personal information belonging to about 25,000 customers was leaked in a data breach, as financial regulator...

Shinhan Bank apologized Thursday after about 25,000 customers had personal information leaked in a data breach, and financial regulators launched an urgent inspection. The leaked data included names, phone numbers, annual income, loan eligibility limits and some resident registration numbers. Shinhan said it blocked external IP addresses, suspended affected services and set up ways for customers to check whether their information was exposed.
The leaked information included 66 cases involving resident registration numbers and 97 cases involving connected information.
The unauthorized access bypassed authentication through an abnormal method.
The Financial Supervisory Service conducted an on-site inspection after receiving Shinhan Bank’s report, and the Financial Services Commission held an emergency meeting on follow-up measures.
Published Oct 1, 2026 2:17 pm KST
Shinhan Bank's headquarters in Jung District, Seoul / Courtesy of Shinhan Bank
Shinhan Bank apologized Thursday after personal information belonging to about 25,000 customers was leaked in a data breach, as financial regulators launched an urgent inspection into the incident.
According to the bank, the leaked information includes customers' names, phone numbers, annual income and loan eligibility limits, as well as other personal and credit information submitted for loan applications.
The data also included 66 cases involving resident registration numbers and 97 cases involving connected information.
The breach occurred as an unauthorized external party gained access to some of its services through an abnormal method that bypassed authentication.
Shinhan Bank CEO Jung Sang-hyuk apologized and said the bank will take full responsibility for any losses.
"We take full responsibility for the fact that an information breach occurred at a financial institution entrusted with protecting our customers' valuable assets and information," Jung said in a statement.
"I sincerely apologize for causing concern and inconvenience to our customers. We will devote all resources to address any damage, preventing a recurrence and regaining customers' trust," he added.
Shinhan said it activated an emergency response team immediately after detecting the breach and took a series of measures, including blocking external IP addresses and suspending affected services.
It said it will conduct a review of its personal information protection system, improve security policies and strengthen employee training to prevent similar incidents.
The bank has also set up a dedicated page on its website where customers can check whether their information was leaked. The feature is also available on the bank's mobile app. A dedicated call center has been established to handle reports related to the data breach.
The bank's announcement came as financial regulators launched an urgent investigation into the incident.
Earlier in the day, the Financial Supervisory Service (FSS) conducted an on-site inspection of Shinhan Bank after receiving a report from the bank that some customer information related to loan applications had been leaked.
The FSS and the Financial Services Commission held an emergency meeting to discuss the circumstances surrounding the breach and follow-up measures.
Some have raised the possibility that the attack involved so-called credential stuffing, a technique in which attackers use account credentials obtained through other means to repeatedly attempt to gain access to another service.
The main target of the attack was a platform used by loan brokers to store customer information as part of the loan application process. The breach could have wider impact, as the platform handles sensitive data such as borrowers' credit profiles and information related to their loans.
新韩银行周四就约2.5万名客户个人信息泄露事件公开道歉,金融监管机构已启动紧急调查。泄露的数据包括姓名、电话号码、年收入、贷款资格限额以及部分居民登记号码。新韩银行表示,已屏蔽外部IP地址,暂停受影响的服务,并设立了客户查询信息是否泄露的途径。
泄露的信息包括 66 起涉及居民登记号码的案件和 97 起涉及关联信息的案件。
未经授权的访问通过异常方法绕过了身份验证。
金融监督院在收到新韩银行的报告后进行了现场检查,金融服务委员会召开紧急会议讨论后续措施。
发布于2026年10月1日下午2:17(韩国标准时间)
新韩银行位于首尔中区的总部 / 图片由新韩银行提供
新韩银行周四就约25000名客户的个人信息泄露事件道歉,金融监管机构已对此事件展开紧急调查。
据该银行称,泄露的信息包括客户的姓名、电话号码、年收入和贷款资格限制,以及在贷款申请中提交的其他个人和信用信息。
数据还包括 66 起涉及居民登记号码的案件和 97 起涉及关联信息的案件。
此次安全漏洞是由于未经授权的外部人员通过绕过身份验证的异常方法访问了其部分服务而造成的。
新韩银行首席执行官郑相赫道歉并表示,该行将承担一切损失的全部责任。
“对于一家受托保护客户宝贵资产和信息的金融机构发生信息泄露事件,我们负全部责任,”郑在一份声明中表示。
“对于给客户带来的担忧和不便,我深表歉意。我们将竭尽全力解决任何损失,防止类似事件再次发生,并重新赢得客户的信任。”他补充道。
新韩表示,在发现安全漏洞后,公司立即启动了应急响应小组,并采取了一系列措施,包括屏蔽外部 IP 地址和暂停受影响的服务。
该公司表示,将对其个人信息保护系统进行审查,改进安全政策,加强员工培训,以防止类似事件再次发生。
该银行还在其网站上设立了专门页面,客户可以在此查询自己的信息是否遭到泄露。该功能也可在银行的手机应用程序上使用。此外,银行还设立了专门的呼叫中心,负责处理与数据泄露相关的报告。
银行发布声明之际,金融监管机构已对该事件展开紧急调查。
当天早些时候,金融监督院(FSS)接到新韩银行的报告,称部分与贷款申请相关的客户信息遭到泄露,随后对该银行进行了现场检查。
金融服务标准局和金融服务委员会召开紧急会议,讨论此次违规事件的相关情况和后续措施。
有人提出,此次攻击可能涉及所谓的凭证填充,这是一种攻击者使用通过其他方式获得的帐户凭证反复尝试访问另一项服务的技术。
此次攻击的主要目标是贷款经纪人用于存储客户信息的平台,这些信息是贷款申请流程的一部分。由于该平台处理借款人的信用记录和贷款相关信息等敏感数据,因此此次数据泄露可能造成更广泛的影响。