Shinhan Bank
Oct 2026 · Graded Attested · Financial Services · Beyond the filings
Incident summary
Shinhan BankOct 2026
Not yet quantified
AAttestedShinhan Bank's "M Shinhan" loan-inquiry site let an outsider bypass authentication and exploit a code flaw on September 29 and 30, 2026, exposing names, phone numbers, incomes, and loan limits for about 25,000 customers, including 66 resident registration numbers and 97 CI records. The bank calls it an AI-driven brute-force attack, its own characterization. A public loan-inquiry page was serving as the authentication boundary for sensitive financial data, scripted guessing isn't brute-force or sophisticated. It's jiggling door handles to see if any of them are unlocked.
Financial Services
South Korean bank hit by data breach affecting thousands of customers
Initial attack type software vulnerability confirmed · Impact data theft confirmed
About this record
This incident is beyond the filings: attributed to a company statement, a regulator or court record, or a news report, and graded Attested or Inferred. Every figure links to the source it was read from; if we have read one wrong, tell us at info@hackerinahoodie.com. This index never sums figures across incidents. See the methodology.