Shinhan Bank

Oct 2026 · Graded Attested · Financial Services · Beyond the filings

Incident summary

Shinhan BankOct 2026
Not yet quantified
AAttested
Shinhan Bank's "M Shinhan" loan-inquiry site let an outsider bypass authentication and exploit a code flaw on September 29 and 30, 2026, exposing names, phone numbers, incomes, and loan limits for about 25,000 customers, including 66 resident registration numbers and 97 CI records. The bank calls it an AI-driven brute-force attack, its own characterization. A public loan-inquiry page was serving as the authentication boundary for sensitive financial data, scripted guessing isn't brute-force or sophisticated. It's jiggling door handles to see if any of them are unlocked.
Financial Services
South Korean bank hit by data breach affecting thousands of customers
Initial attack type software vulnerability confirmed · Impact data theft confirmed

About this record

This incident is beyond the filings: attributed to a company statement, a regulator or court record, or a news report, and graded Attested or Inferred. Every figure links to the source it was read from; if we have read one wrong, tell us at info@hackerinahoodie.com. This index never sums figures across incidents. See the methodology.

Cite this incident

← The complete Beyond the Filings ledger ← Back to the index