South Korea fines telco giant KT $39 million for customer data breach

South Korea’s largest telecommunications operator, KT Corporation, has been hit with a massive fine of $39 million by the country’s Personal Information Protection Commission (PIPC) for a data breach that exposed sensitive customer information. The incident, which lasted nearly 11 months, highlights the vulnerabilities in modern telecom infrastructure and the need for stricter security measures.

The breach occurred when hackers compromised a KT cellular base station, known as a femtocell, which contained a valid authentication certificate. The attackers then installed this certificate on a self-made device, allowing them to intercept communications between users’ devices and KT’s core network. This included sensitive information such as mobile phone numbers, IMSI (International Mobile Subscriber Identity) numbers, and IMEI (International Mobile Equipment Identity) numbers.

The hackers used this data to make fraudulent micropayments, with at least 368 customers being affected. The PIPC investigation found that the breach was made possible due to inadequate security controls by KT. The company’s femtocell certificates remained valid for 10 years, connections were not restricted by source IP addresses, and a route existed that bypassed the femtocell management server. These weaknesses allowed the hackers to remain connected to KT’s network undetected.

The investigation also uncovered a malware infection on 38 KT IT service network servers, including BPFDoor, a stealthy Linux and Solaris backdoor publicly documented in 2022. The malware was linked to the China-nexus Red Menshen espionage group that targeted telecommunications providers and organizations in other critical sectors. KT had known about the malware infection since March 2024 but failed to report it to the authorities, instead handling the incident internally with no transparency towards its customers.

The company even went so far as to delete logs from some compromised servers while conducting malware inspection, following a similar approach taken by another telecom firm, LG U+. This deletion of evidence made it impossible for the PIPC to determine whether additional customer data had been stolen. The Commission has ordered KT to strengthen security controls and improve its governance over personal information protection.

The fine imposed on KT is one of the largest ever in South Korea, and serves as a warning to other companies about the importance of prioritizing cybersecurity and transparency. As part of its enforcement action, the PIPC also plans to pursue legislative changes that would introduce stronger penalties for companies that conceal or destroy evidence before or during investigations.

For individual users, this incident highlights the need to be vigilant about their online security. While KT’s breach was a result of a sophisticated attack on its infrastructure, it’s essential to remember that data breaches can happen at any level. Users should always be cautious when sharing sensitive information and regularly review their account activity for any suspicious transactions. By staying informed and taking proactive steps to protect themselves, individuals can minimize the risk of falling victim to similar attacks in the future.


Source: Bleeping Computer — 2026-07-30