South Korean Telecom Giant KT Fined $39 Million for 11-Month Customer Data Breach
A massive data breach at South Korea’s largest telecommunications operator, KT Corporation, has resulted in a hefty fine of KRW 53.979 billion (approximately $39 million) from the country’s Personal Information Protection Commission (PIPC). The breach, which persisted for nearly 11 months, compromised the sensitive information of over 16,000 customers and led to hundreds of thousands of dollars’ worth of fraudulent mobile payments.
The breach was made possible through a rogue cellular base station, called a femtocell, that was lost by KT. Attackers managed to retrieve a valid authentication certificate from the device, which they then installed on a self-made device masquerading as a legitimate part of KT’s network. This allowed them to intercept sensitive information, including mobile phone numbers, IMSI and IMEI numbers, and even SMS and ARS authentication codes used for mobile micro-payments.
KT’s security controls were criticized by the PIPC for being inadequate, with certificates remaining valid for 10 years, connections not restricted by source IP addresses, and a route existing that bypassed the femtocell management server. These weaknesses allowed hackers to remain connected to KT’s network and collect sensitive client data for months on end without being detected.
In addition to the breach through the lost femtocell, investigators also discovered that 38 of KT’s IT service network servers had been compromised by malware, including BPFDoor, a stealthy backdoor publicly documented in 2022. The malware uses Berkeley Packet Filter (BPF) technology to passively monitor network traffic, allowing attackers to activate it with specially crafted “magic” packets without opening listening ports.
The PIPC alleges that KT was aware of the malware infection since March 2024 but failed to report it to authorities and instead handled the incident internally with no transparency towards customers. Furthermore, when investigators asked for historical network logs from compromised servers, KT deleted them, making it impossible to determine whether additional customer data had been stolen.
As part of its enforcement action, the PIPC has ordered KT to strengthen security controls for femtocells and other telecommunications equipment, reinforce governance over personal information protection, ensure its Chief Privacy Officer plays a substantive role in oversight, and expand ISMS-P certification to cover its mobile network systems. The Commission also plans to push for legislative changes that would introduce stronger penalties for companies that conceal or destroy evidence before or during investigations.
The breach highlights the importance of robust security measures in protecting sensitive customer data. KT’s failure to implement adequate controls has led to a significant fine and damage to its reputation. As the telecommunications industry continues to evolve, it is crucial for operators like KT to prioritize cybersecurity and ensure that their customers’ trust is not compromised.
Source: Bleeping Computer — 2026-07-30