● Based on · 2026-10-01 Shinhan Bank incident · 25,000 customers' data leaked
Identity Bypass Simulator
A live demo reproducing the pattern that actually broke through at Shinhan Bank (bypass identity verification → bulk-lookup other customers) and showing how session-bound verification stops it — then escalates to 2 follow-up moves: switching identity after being blocked, and flooding one's own account. No real customer data is used.
Unverified Lookup Trusts whatever the client sends
Allowed attempts 0
Session-Bound Lookup + Extensions Handles ID mismatch, identity switching, and anomalies