South Korea fines telecom giant KT $39 million for data breach
South Korea's Personal Information Protection Commission (PIPC) has slammed telecommunications giant KT Corporation with a record $39 million fine for severe security failures that led to an 11-month data breach exposing thousands of customers.
What Happened
KT Corporation, the largest telecommunications player in South Korea, is facing a severe penalty from the government for its failure to protect customer data. The country's data protection authority, the Personal Information Protection Commission (PIPC), announced it has imposed a fine of exactly KRW 53.979 billion, equivalent to approximately $39 million. This penalty comes as a direct result of a security vulnerability within the company's internal network that went undetected for nearly a year.
The investigation conducted by PIPC revealed that cyber attackers had infiltrated KT's network between October 8, 2024, and September 5, 2025, a period spanning almost 11 months. This extended duration allowed the attackers to collect sensitive customer data and conduct financial fraud activities without being detected. The government's intervention was triggered by complaints from users who noticed suspicious and fraudulent micropayments on their phone bills. On September 10, 2025, PIPC launched an official investigation based on these reports. Just one day after the investigation began, KT issued its initial data breach notification, admitting that the data of roughly 5,500 customers had been compromised. However, PIPC's in-depth review revealed that the scale of the breach was far greater, surpassing the company's initial estimates.
What Data Was Stolen
The investigation concluded that a total of 16,647 KT subscribers were affected by the attack. The attackers gained access to highly critical personal and technical information belonging to these subscribers. The stolen data included basic contact information like mobile phone numbers, as well as unique identifiers for each mobile device and SIM card, namely IMSI (International Mobile Subscriber Identity) and IMEI (International Mobile Equipment Identity) numbers. These identifiers are considered highly sensitive as they allow for the tracking and identification of a device and subscriber on a network.
The attackers took their efforts a step further, using the stolen data for financial gain. Specifically, they managed to intercept SMS and ARS (Automated Response System) authentication codes used for mobile micropayments. Using these codes, they made fraudulent payments from the accounts of at least 368 subscribers, totaling KRW 240 million (approximately $167,400). This demonstrates that the cyberattack was not just a data leak but also evolved into direct financial fraud.
How Did the Attack Happen
According to PIPC's report, the epicenter of the attack was a lost KT-owned cellular base station, known as a 'femtocell.' A femtocell is a small, low-power base station used to improve signal strength indoors. The attackers managed to retrieve a valid authentication certificate from this lost device, which it used to connect to KT's network.
By installing this certificate on a custom-built device, the attackers made their rogue device appear as a legitimate base station to KT's network. Through this 'rogue mobile station,' they began capturing cellular traffic from nearby KT subscribers' mobile devices. This method allowed them to eavesdrop on communications between users' devices and KT's core network, collecting valuable data such as phone numbers, IMSI, and IMEI.
The Commission also uncovered a series of critical vulnerabilities in KT's security measures. First, the certificates on femtocell devices had an extraordinarily long validity period of 10 years, allowing a stolen certificate to be used for decades. Second, network connections were not restricted by source IP addresses, enabling attackers to connect to KT's network from anywhere in the world. Finally, the existence of a network route that bypassed the femtocell management server made the rogue device nearly impossible to detect. The combination of these weaknesses allowed the attackers to collect data for 11 months without being noticed.
During the investigation, it was also discovered that 38 of KT's IT service servers had been infected with malware called BPFDoor in March 2024. BPFDoor is an extremely stealthy Linux and Solaris backdoor, publicly documented in 2022, that managed to evade detection for over five years. Security researchers had previously linked this malware to the China-nexus espionage group Red Menshen, known for targeting telecommunications providers. BPFDoor uses Berkeley Packet Filter (BPF) technology to passively monitor network traffic, allowing attackers to activate the backdoor by sending specially crafted 'magic' packets. This method does not open listening ports, making it exceptionally difficult to detect with traditional security systems.
Who Is Affected
Those directly affected by this data breach are the 16,647 KT subscribers whose personal information was compromised. As South Korea's largest telecom operator, KT serves over 13.5 million mobile subscribers, 90% of the country's fixed-line subscribers, and 45% of high-speed internet users. This vast customer base significantly amplifies the potential impact of the attack. In particular, the 368 subscribers who had money illicitly withdrawn from their accounts are the tangible financial victims of the breach.
What You Can Do
If you are a KT subscriber or are concerned about a similar situation, there are several preventive measures you can take:
- Check Your Bills: Regularly review your phone and credit card statements. For any unrecognized or suspicious micropayments or charges, immediately contact your operator and bank.
- Change Your Passwords: Update the passwords for your KT online account and any other accounts associated with your mobile payment systems. Make sure to use strong and unique passwords.
- Be Wary of SMS-Based Authentication: This attack demonstrated that verification codes sent via SMS can be intercepted. Wherever possible, opt for app-based two-factor authentication (2FA) methods, such as Google Authenticator or Authy.
- Be Alert for Fraud Attempts: Attackers may use the stolen phone numbers for phishing attacks. Avoid clicking on suspicious links and messages from unknown numbers.
What the Company Says
The source article does not include an official comment or statement from KT Corporation regarding the findings announced by the Personal Information Protection Commission and the record fine imposed. The steps the company will take and its public communication on the matter are awaited.
Source
This content was generated with AI assistance through our Argus Flow application. We are continuously working to improve Argus Flow; if you encounter any issues such as translation errors, incorrect sources, or unverified information, you can report them using the button below. We appreciate your feedback.