Breaking
BRQuaest survey shows Daniel Vilela ahead for the government of Goiás with 57% of valid votesINCBI files chargesheet against Reliance Communications and executives in Rs 3,750 crore LIC fraud caseBRDatafolha research shows technical tie between Lula and Flávio Bolsonaro in Minas GeraisARThe coalition rejects the Houthis’ claims of targeting Riyadh and confirms that they have suffered significant human and material lossesBRSão Paulo wins unprecedented Brasileirão Feminino A1 title after draw with Corinthians at MorumbisINTLCar crashes into crowd in Newcastle, injuring ten including critically injured five-year-oldRULatvian Prime Minister's Party Leads in Seimas Elections After Processing 3% of BallotsRUAn explosion occurred in Kharkov amid an air raid raidBRMPT-DF recommends that Iges guarantee sufficient time for workers to vote in the electionsARTrump declares the possibility of resolving the conflict with Iran peacefully or forcefully and indicates that Tehran wants an agreementBRQuaest survey shows Daniel Vilela ahead for the government of Goiás with 57% of valid votesINCBI files chargesheet against Reliance Communications and executives in Rs 3,750 crore LIC fraud caseBRDatafolha research shows technical tie between Lula and Flávio Bolsonaro in Minas GeraisARThe coalition rejects the Houthis’ claims of targeting Riyadh and confirms that they have suffered significant human and material lossesBRSão Paulo wins unprecedented Brasileirão Feminino A1 title after draw with Corinthians at MorumbisINTLCar crashes into crowd in Newcastle, injuring ten including critically injured five-year-oldRULatvian Prime Minister's Party Leads in Seimas Elections After Processing 3% of BallotsRUAn explosion occurred in Kharkov amid an air raid raidBRMPT-DF recommends that Iges guarantee sufficient time for workers to vote in the electionsARTrump declares the possibility of resolving the conflict with Iran peacefully or forcefully and indicates that Tehran wants an agreement
BackCustomer information leaked from Shinhan and Kookmin Bank... Exposure of income and loan information
Customer information leaked from Shinhan and Kookmin Bank... Exposure of income and loan information
Developing
연합뉴스1 hour agoTech3 min readSouth KoreaView original

Customer information leaked from Shinhan and Kookmin Bank... Exposure of income and loan information

Quick Look

Customer personal information was leaked from Shinhan Bank and KB Kookmin Bank, exposing financial information such as income, loan limit, and resident registration number, and as the threshold for hacking technology using AI has been lowered, concerns are growing about customized phishing attacks combining leaked information.

AI-generated summary

Why It Matters

This year, following communication, distribution, and online platforms, there have been a series of personal information leaks from OTT, payment, beauty platforms, and major commercial banks. In particular, in the financial sector, customer information was leaked from Shinhan Bank and KB Kookmin Bank, exposing sensitive financial information such as income, loan limits, and resident registration numbers.

Font size

Ordinary daily life, such as obtaining a loan from a bank, using an online video service (OTT), or consulting on beauty procedures, is emerging as a risk area for personal information leakage.

Following communication, distribution, and online platforms, this year, OTT, payment, beauty platforms, and major commercial banks have been breached one after another, exposing not only names and contact information, but also sensitive life information such as income and loan limits, and consultation and treatment information.

In particular, in recent banking incidents, the possibility of attacks using artificial intelligence (AI) was even raised.

As the technical threshold for hacking is lowered through AI, concerns are growing that if personal information leaked from different sources is combined, it could lead to secondary damage, such as customized phishing that approaches people as if they know the details of an actual transaction or consultation.

◇ Following Shinhan, Kookmin Bank also… Hacking targeting financial information

According to financial authorities and the financial sector on the 4th, following the leakage of customer information of approximately 25,000 customers from Shinhan Bank, the personal credit information of 119 customers was also leaked from KB Kookmin Bank due to an external infringement.

It was reported that at Shinhan Bank, the inquiry service used by loan originators was attacked, and not only customer names and contact information, but also financial information such as annual income and loan limit were leaked.

Some customers' resident registration numbers were also included in the leak.

At KB Kookmin Bank, customer names, phone numbers, addresses, and encrypted resident registration numbers were leaked through the mobile work support system for employees. Leakage items vary by customer.

The two banks explained that the incident had nothing to do with financial transaction services such as internet and mobile banking that customers directly use.

However, as it has been revealed that customer information can be leaked from loan-related services and employee work systems, there is a growing demand to expand the scope of security checks.

The financial authorities decided to check the status of information security and countermeasures by convening banking officials and listening to their opinions.

◇ OTT, beauty, and content… Information leakage regardless of industry

The banking incident is attracting attention because it occurred as an extension of the personal information leak incident that is spreading throughout daily life this year.

Following large-scale accidents that occurred at telecommunication companies, credit card companies, and e-commerce companies last year, breaches continued in OTT, electronic payment, beauty, medical, and content platforms this year.

A government investigation confirmed that the personal information of approximately 39.54 million accounts was leaked at TVING in a breach that occurred last May.

In addition to personal information such as name, date of birth, mobile phone number, email address, and linked information (CI), 361 technical assets containing source code were also leaked.

Healing Paper, which operates the aesthetic medicine information platform Gangnam Unnie, had the personal information of approximately 220,000 domestic and foreign users leaked. Some users even had information related to consultations and procedures leaked.

At Tos Payments, an electronic payment agency (PG) company, the payment linkage authentication information of a specific affiliated store was exposed and a third party searched 4,131 pieces of payment information.

Toss Payments said that it was not an incident where its internal system was directly hacked, but rather the authentication information managed by the affiliated store's external payment linkage platform was exposed.

In the music and video source platform Mupot, some users' names, email addresses, and mobile phone numbers were viewed or exported due to abnormal external access.

Although the information stored and accident paths are different for each service, users complain that it is now difficult to determine which company the information they have entrusted is safe.

◇ AI lowers the attack threshold… Concerns about secondary damage due to combination of leaked information

Experts point out that the digital transformation of companies has increased the number of attack points and that AI is lowering the technical entry barrier for attackers.

The scope of security management has expanded as it connects not only servers and applications, but also external payment platforms, partner systems, and employee work tools.

In recent banking incidents, the possibility of attacks using AI agents has been discussed.

However, the role AI played in individual accidents and the specific attack method are expected to be confirmed through the results of the investigation.

Experts believe that online hacking attacks have become easier through AI than in the past.

As the scope of leaked information expands, secondary damage is also a concern.

This is because if your name and contact information are combined with income/loan information or counseling history, it can be exploited for sophisticated phishing that approaches you as if you know the actual transaction or counseling.

Experts suggest that companies should not only introduce security solutions, but also continuously inspect access rights, authentication information management, external connection paths, and business systems.

In addition, experts advised that users should not immediately trust the contact they received just because they know their name, services used, or consultation history, but should check the truth through the official app or representative number.

What to Watch

AI outlook — possibilities, not facts

  • Financial authorities will expand the scope of security checks for banking sectors to include employee systems and external linkage platforms.

    Likely · Within weeks

  • Customized phishing attempts using leaked personal information will increase.

    Possible · Within months

Open Questions

  • It has not been confirmed how the leaked personal information is actually being misused.
  • It is not yet clear how the hacking attack using AI was carried out specifically.
  • It is not clear in what direction fundamental security measures for leak incidents will be prepared.

Related Topics

This article was originally published by 연합뉴스.

Related Stories

Successive infringements by Shinhan, Kookmin, Hana, and Busan banks... We and Nonghyup were also attacked
Developing·

Successive infringements by Shinhan, Kookmin, Hana, and Busan banks... We and Nonghyup were also attacked

Hacking incidents occurred one after another at Shinhan Bank, KB Kookmin Bank, Hana Bank, and BNK Busan Bank, and Woori Bank and NH Nonghyup Bank were also attacked, but no information leaks were confirmed. Experts warned that a security paradigm shift is needed as AI agents evolve into attack tools, emphasizing zero trust and AI-based defense systems.

연합뉴스
3 min read
AI hacking attacks spread to Saemaeul Geumgo following savings banks and capital... Representatives of financial authorities convened
BREAKING·

AI hacking attacks spread to Saemaeul Geumgo following savings banks and capital... Representatives of financial authorities convened

Hackers using AI attacked the financial sector in all directions, including commercial banks, savings banks, capital companies, and Saemaeul Geumgo, and customer information leaks were confirmed in some institutions. Financial authorities acknowledge the limitations of existing security capabilities and are pushing for a complete overhaul of the financial sector's security system, and plan to convene representatives of financial companies today to discuss response plans.

연합뉴스
3 min read
More on this topicShinhan Bank