Shinhan Bank, customer personal information leaked in new hacking using AI agent
Hacking of the communication structure of a service exclusively for loan originators... Approximately 25,000 people were damaged
Quick Look
- Shinhan Bank had customer personal information stolen through a new hacking attack using an advanced AI agent.
- As the information of about 25,000 people was leaked through a mobile website dedicated to loan originators, it is pointed out that there is an urgent need to reexamine the security system of the entire financial sector.
AI-generated summary
Why It Matters
Customer information was leaked through unauthorized external access through the Shinhan Bank mobile homepage exclusively for loan originators.
It was reported that Shinhan Bank used an advanced artificial intelligence (AI) agent in the process of having customer personal information stolen.
As it has been revealed that the company has been hit by a new AI-based attack that exploits platform vulnerabilities, there are calls for a reexamination of the information security system across the financial sector.
Shinhan Bank President Jeong Sang-hyuk said in an apology posted on the website on the 1st, "We have confirmed that an external unauthorized person leaked customer information from some services through abnormal methods."
The leaked information includes 66 resident registration numbers and 97 linked information (CI) of some customers, as well as customer names, phone numbers, annual income, and loan limits.
The number of customers affected by the leak is approximately 25,000.
Unlike other banks, loan seekers at Shinhan Bank can easily check the status of the loans they have received through the mobile website 'M Shinhan', but the bank explains that an unauthorized external party accessed the loan through this route without going through the normal identity verification process.
After hacking and intruding into the 'communication professional structure' (code) of this recruiter-only service, they randomly substituted search input values to call up information, and stole contact information and other information using the customer number secured in that way.
Regarding this, it is pointed out that Shinhan Bank's security vulnerabilities were exposed due to a hacking incident that bypassed a route that did not exist in other banks.
An official from the financial sector said, “The system that allows recruiters to check the status of loan processing on the website is not a common method,” and added, “It does not appear that there is a device in place to block abnormal access at the source.”
Security experts believe that this hacking did not specifically target Shinhan Bank, and that Shinhan Bank was exposed to random AI-based attacks targeting platform vulnerabilities.
As Shinhan Bank has accelerated its AI transition internally, the impact inside and outside the bank is expected to be even greater.
In addition, there is an analysis that if other financial companies also fail to filter out abnormal access on platforms with weak security, there is a high risk that personal information leakage incidents may continue.
In particular, as AI agents develop, hacking methods that randomly substitute information values are spreading, unlike in the past.
The security industry believes that this incident is similar to hacking incidents at beauty and medical information platform Gangnam Unni and online fashion platform 29CM, which recently suffered large-scale leaks.
An official from the financial sector said, “The entire financial sector is vulnerable to attacks by AI agents,” and “self-inspection to respond to this is urgently needed.”
The Financial Services Commission and the Financial Supervisory Service convened an emergency response meeting this morning, and the Financial Security Service was reported to have been on site since the previous day to investigate the cause of the accident.
It is expected that it will take several months to announce the final investigation results. As of now, it is believed that it is not the work of domestic hackers.
Shinhan Bank has formed an emergency response team and is operating a company-wide emergency response system. The bank said it has also completed emergency measures such as blocking external IPs, suspending related services, and applying new security policies.
However, Shinhan Bank emphasized that this accident has nothing to do with applications directly used by customers, such as 'Shinhan Super SOL'.
Bank officials repeatedly drew the line, saying, "This incident was a website information leak and is not related to the customer banking app that requires formal authentication."
Experts emphasize that banks need a 'paradigm change' to protect sensitive customer information and assets.
Kim Hwan-guk, a professor of information security and cryptography at Kookmin University, pointed out, "As information and communication technology (ICT) technology is converted to artificial intelligence (AI) technology, attack technology is advancing, but there are aspects in which the security systems and technologies of companies as well as banks are unable to keep up with the pace."
He continued, "Quantitative information security infrastructure has been built, but qualitative change is also needed," and added, "There is a need for a paradigm shift to build AI-based defense technology or prepare a more in-depth response system than in the past."
This is already the second incident this year where customer personal information has been leaked from a major commercial bank.
Previously, at Woori Bank, in early July, an incident occurred in which 17,551 pieces of personal information (nicknames and IDs) arbitrarily stored by an external development company were leaked due to the negligence of the company's employees.
What to Watch
AI outlook — possibilities, not facts
Announcement of final investigation results on the cause of the accident by authorities such as the Financial Security Institute
Very likely · Within months
Open Questions
- Attack path of specific AI agent used in hacking
- When will the final survey results be announced?
- Whether additional damage will spread







