← Shinhan Bank

2026 Shinhan Bank — ~25k loan customers; names/phones/income/limits; 66 RRNs + 97 CI

2026 25.0K records affected Share on X

Data compromised

Names, phone numbers, annual income, estimated loan eligibility limits; ~66 resident registration numbers and ~97 connecting-information (CI) identifiers also confirmed leaked (bank disclosures via Aju Press / Yonhap)

Technical writeup

Shinhan Bank (South Korea) confirmed on October 1, 2026 that personal and credit information tied to about 25,000 customers’ loan applications leaked after unauthorized external parties accessed services through abnormal means that bypassed authentication. Yonhap and Aju Press reported the leak occurred Wednesday (September 30, 2026) via hacking; exposed fields include names, phone numbers, annual income, and estimated loan limits. Aju Press further reported ~66 resident registration numbers and ~97 connecting-information (CI) identifiers confirmed leaked, with the breach believed to involve a simple inquiry service used by loan solicitors. CEO Jung Sang-hyuk issued a public apology and pledged full compensation; the Financial Supervisory Service launched an on-site inspection. The bank blocked external IPs, suspended affected services, stood up a customer lookup on its website (and planned Super SOL app features), and opened a damage-reporting center. Credential stuffing has not been confirmed. companyConfirmed true.

Root cause

Unauthorized external access via abnormal methods bypassing authentication on a loan-solicitor inquiry service (bank/FSS-facing reporting; credential stuffing not confirmed)

References