[Photo: Shinhan Bank]

An incident at Shinhan Bank has led to the leak of personal and credit information for about 25,000 customers. The Financial Supervisory Service has launched an emergency on-site inspection, and the cause and scale of the damage, as well as whether Shinhan Bank’s information protection and internal control systems worked properly, are expected to become key issues.

The incident comes as the introduction of accountability structure requirements has further clarified the internal control responsibilities of financial company CEOs and responsible executives. Depending on the findings, it could broaden into an issue of management accountability. Another factor is that Shinhan Bank CEO Jeong Sang-hyeok (정상혁) is due to see his term end late this year and the process to select the next bank chief has already begun.

LEAK AFFECTS 25,000, INCLUDES FINANCIAL INFORMATION

On Oct. 1, Shinhan Bank said it had confirmed that customer information was leaked after outsiders accessed some services using an abnormal method to bypass authentication.

The number of affected people identified so far is about 25,000. The leaked data include customer names and phone numbers, as well as personal and credit information collected during the loan application process, such as annual income and calculated loan limits. Also leaked were 66 resident registration numbers and 97 cases of CI (connection information). The Financial Supervisory Service launched an emergency on-site inspection on the day.

A possible "credential stuffing" attack has been raised as the method of the leak. It involves repeatedly trying to log in to other services by applying account information obtained from outside. Shinhan Bank described the cause as "access through an abnormal method that bypassed authentication from outside," meaning further investigation is needed to determine the specific attack method.

Moon Jong-hyun (문종현), head of the security centre at Genians and a director, said, "When personal information is leaked, people often focus on the quantitative aspect of how much was leaked, but in finance the sensitivity is higher because personal information is linked to financial information." He added, "Compared with past large-scale personal information leaks, the number is not large, but it needs to be viewed more seriously because it involves the financial sector."

He said the sensitivity is high because the leak included information that can indicate an individual's financial situation, such as annual income and loan limits. Moon said, "Once annual income is included, it becomes information linked to a person's assets, so it is highly sensitive."

If it is confirmed as a credential stuffing attack, personal information already obtained elsewhere may have been reused in an attack on the financial sector.

Moon said, "Credential stuffing works by taking account information leaked through earlier hacking incidents or malware infections, trading it on the dark web and then applying the IDs and passwords obtained this way to other web services to attempt unauthorised logins." He added, "Recently, as it is combined with AI technology, it has become possible to conduct automated 24-hour attacks targeting large volumes of account information, increasing both the speed and scale of attacks."

Device security is also becoming more important as the starting point from which account information used in attacks is stolen. Account information such as IDs and passwords can be stolen from devices infected with infostealer-type malware and then reused for other attacks.

Moon said, "To respond to credential stuffing, it is important not only to secure accounts but also to protect the device itself, which is the starting point of information leakage." He added, "The importance of EDR (endpoint detection and response) solutions, which can quickly detect and respond to malicious activities occurring on devices, is growing further."

After becoming aware of the leak, Shinhan Bank set up an emergency response team and took urgent steps such as blocking external IP addresses, suspending related services and applying new security policies. It opened a separate menu on its website for customers to check whether their information was leaked and said it would provide full compensation if damage is confirmed. It also said it would re-examine its personal credit information protection system from the ground up and strengthen work processes and employee training systems.

CALLS FOR STRONGER SECURITY, GREATER MANAGERIAL RESPONSIBILITY

The fallout from the incident is expected to expand beyond the scale of the leak to whether Shinhan Bank’s internal control and information protection systems functioned properly.

Financial authorities have recently been urging stronger cybersecurity across the financial sector. After the SGI Seoul Guarantee ransomware incident in July last year, the Financial Services Commission conducted self-inspections of incident preparedness across the entire financial sector and decided to push theme inspections and surprise penetration tests. It also presented, as a task for institutional improvement, a plan to impose punitive fines if major incidents occur due to inadequate security systems.

In July this year, "Information Security Day" events attended by financial company CEOs addressed financial security governance and CEOs’ roles and responsibilities as key agenda items. In a keynote lecture at the time, a proposal was also made to treat security as the top management priority that a financial company CEO must oversee directly and to strengthen security governance and the CEO’s role and responsibility.

Moves to view cybersecurity incidents as a matter of management and supervisory responsibility rather than a working-level issue are also strengthening in the public sector. The government announced a "plan to strengthen accountability for cybersecurity in the public sector" on the day. It said it would amend relevant rules to impose responsibility on supervisors in the event of major information leaks and to raise disciplinary standards. It also aims to strengthen management and supervisory responsibility so the heads of institutions can also be held accountable.

In the financial sector, there is also criticism that security should not be confined to a problem for operational departments alone. Moon said, "In the financial sector as well, bank chiefs need to recognise the importance of security investment." He added, "It is important to invest actively in security personnel and related systems."

Under the revised Act on Corporate Governance of Financial Companies, executives at financial firms must manage internal controls and risk management to operate effectively in relation to their assigned responsibilities. Representative directors are given an "overall management duty" to establish company-wide internal control systems and check whether executives are fulfilling their management obligations. If a violation of management obligations is confirmed, sanctions against responsible executives are also possible.

Still, a data leak alone does not automatically mean a CEO’s management obligation has been violated. Financial authorities will comprehensively examine an executive’s responsibilities and whether internal control management measures were implemented, the circumstances, extent and outcome of unlawful acts, and the level of attention exercised by management, before determining whether there was a breach.

Accordingly, the on-site inspection is expected to focus on issues such as why authentication bypass was possible, whether a security system was properly in place to detect and block abnormal access, and whether internal control systems functioned properly during the process of recognising and responding to the incident.

INCIDENT HITS AHEAD OF YEAR-END BANK CHIEF SELECTION

For management, the timing of the incident is also sensitive. Shinhan Financial began succession procedures on Sept. 21 for the chief executives of 12 subsidiaries whose terms, including Shinhan Bank CEO Jeong, end late this year. Jeong first took office as head of Shinhan Bank in February 2023 and was reappointed once at the end of 2024. His current term runs until Dec. 31. The next CEO will be decided through deliberations by Shinhan Financial’s committee that recommends candidates for subsidiary CEOs and procedures at each subsidiary’s executive candidate recommendation committee.

As a result, the outcome of the financial authorities’ investigation into the leak and Shinhan Bank’s follow-up response could become intertwined with future discussions on management responsibility. As the financial authorities’ probe is at an early stage, it remains to be seen what actual impact the incident will have on the selection of the next bank chief.

The fact that a parliamentary audit is approaching is another factor. As internal controls and information protection could be treated as one of the main issues in this year’s audit, the incident could also emerge as a point of contention in the National Assembly. Jeong could also be additionally adopted as a witness in relation to the incident.

Jeong said in an apology statement to customers, "As a financial company that must make protecting customers’ valuable assets and information its top goal, we are taking this personal and credit information leak very seriously." He added, "We will mobilise all our capabilities to recover damage and prevent a recurrence."

He added, "As bank chief, I once again bow my head in apology on behalf of Shinhan Bank executives and employees."

Keyword

#Shinhan Bank #Financial Supervisory Service #Credential stuffing #EDR #CI
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.