Invest1 publisherNot yet confirmed elsewhere3 min readPublished
Hackers took data on 25,000 Shinhan customers through a site built for loan recruiters
South Korea's financial regulator gave lenders until Thursday to check every internet-facing system after hackers breached at least seven banks. Attackers entered through tools built for loan recruiters and staff, so the repair falls on how much credit data banks let outsiders see.
The Investor · Invest desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Over about 30 hours from Sept. 28, attackers fed random customer numbers into a lookup site Shinhan built for loan recruiters and got past a phone verification step.
- Other ways in included a mobile work-support system for KB Kookmin employees and a sales-support system at a third bank, according to the banks and Korean press.
- The attackers did not obtain passwords or one-time authentication codes, and regulators have confirmed no case of a customer losing money.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- decision Every lender that relies on outside recruiters now has to decide which credit fields an agent needs to see, under an order that calls those agents' systems the cause of the breaches.
- cost The checks cover every internet-facing system "regardless of whether they are customer-facing," so the work due by Thursday lands on staff and agent tools outside the customer apps.
- exposure Shinhan's customers carry the risk forward, since their incomes and borrowing limits are what a fraudster needs to make a fake loan offer look legitimate, as regulators warned.
About 25,000 Shinhan records taken over about 30 hours is an average of roughly 830 an hour, or 14 a minute [16]. Feeding random customer numbers into a lookup [9] is what Dong-A Ilbo described as enumeration: cycling through guessed account numbers until some of them return data [19]. Yonhap called the technique credential stuffing, which usually means trying usernames and passwords stolen from somewhere else [19]. The two point to different repairs. Under enumeration, the site handed over data for numbers no recruiter had legitimately looked up. Under credential stuffing, real recruiter logins were in the wrong hands.
KB Kookmin and Hana together reported 188 affected customers [7]. Shinhan's 25,000 is about 133 times that, and more than 99% of the customer records the three banks have counted [17]. Shinhan's door opened onto credit data. The bank had given recruiters, outside agents who refer borrowers and are not its employees, access to sensitive customer credit data including applicants' incomes and borrowing limits, and American Banker reported that the access was criticised as excessive [10]. Its Oct. 1 notice listed names, phone numbers, annual incomes and calculated borrowing limits among the exposed data [8].
The commission's order goes after that data. Firms must make sure personal credit data is not "unnecessarily stored or viewable" in systems used by employees and by "outside personnel such as loan recruiters and outsourcing contractors," which the commission called "the cause of the recent intrusions" [13]. As reported, the order does not tell banks to stop using recruiters. I'd expect the cost to show up in that channel anyway, because a lookup that stops returning incomes and borrowing limits is less use to an agent screening a borrower.
"In some hacking incidents, signs have emerged of AI being used, causing considerable public concern and anxiety," President Lee Jae Myung said at a Tuesday cabinet meeting [1]. BNK Busan Bank told Yonhap the attempt on its web servers used an AI agent [2]. The same bank said some of its pages had "insufficient session validation," meaning the pages never confirmed that whoever sent a request was actually logged in [11]. Data on 11 outsourced developers was exposed through that hole [11]. Shinhan has said only that an "unauthorized outsider" reached some services "through abnormal means" [21]. How the attackers beat its phone check is unclear: the step may have been skippable, the site may have mishandled sessions, or it may have been something else [20].
I don't think 14 records a minute needs AI to explain it. A verification step that could be passed and pages that skipped session checks are enough. The case against that view is that agents found and chained these gaps faster than banks could close them. If so, patching the known holes by the Oct. 8 deadline buys less than the commission assumes [4]. That case gains weight if lenders report fresh intrusions after the inspections close.
What to watch
- Customer counts and entry points from the breached lenders beyond the four named so far, once the Oct. 8 inspections close.
- Whether the police investigation settles the method, credential stuffing as Yonhap reported or enumeration as Dong-A Ilbo described.