2025 Shinhan Card — internal leak of ~192k merchant owners’ data
Data compromised
Merchant owner mobile numbers; some names, DOB, gender; store business contact fields
Technical writeup
Shinhan Card disclosed on 23 December 2025 that personal information tied to about 190,000–192,088 merchant network store owners was leaked in an internal incident—not an external cyberattack. Korea Herald reported most records involved mobile phone numbers, with some also containing names, birth dates, and gender; resident registration and credit-card numbers were not exposed. Ordinary cardholders were not affected. An employee improperly accessed and used merchant data for solicitation. The leak was identified after a tip prompted PIPC review (first flagged around 12 November). Company-confirmed insider misuse.
Root cause
Internal misuse / improper employee access to merchant data