South Korea has issued a $39 million KT data breach fine after an investigation found serious security and privacy failures at the country’s largest telecoms provider.

The Personal Information Protection Commission, or PIPC, imposed a KRW 53.979 billion penalty on KT Corporation. Attackers remained inside the company’s network for almost 11 months, exposing the data of 16,647 subscribers and enabling fraudulent mobile payments.

Why South Korea issued the KT data breach fine

PIPC began investigating KT in September 2025 after customers reported fraudulent micropayments.

The company initially reported that about 5,500 customers may have been affected. However, the regulator later found that attackers had exposed personal information belonging to 16,647 subscribers.

At least 368 customers suffered fraudulent mobile payments totalling KRW 240 million, or roughly $167,400.

The KT data breach fine covers these failures as well as the company’s inadequate security controls and handling of a separate malware infection.

Rogue femtocell intercepted customer data

The intrusion involved a lost KT femtocell, a small cellular base station that contained a valid authentication certificate.

Attackers extracted the certificate and placed it on a device they built themselves. That rogue device could then appear as a legitimate part of KT’s network.

Mobile devices nearby connected to the fake base station. This allowed attackers to intercept traffic between subscribers and KT’s core network.

The stolen information included phone numbers, IMSI numbers and IMEI numbers. The attackers later combined this data with additional personal information and captured SMS and ARS authentication codes used for mobile micropayments.

PIPC said the attackers remained connected to KT’s network from 8 October 2024 to 5 September 2025.

Weak network controls left KT exposed

KT installed and owned the affected femtocells. It also controlled the devices’ authentication and access to the wider network.

However, PIPC found that femtocell certificates remained valid for 10 years. KT also failed to restrict connections by source IP address.

Investigators identified a network route that bypassed the femtocell management server. Together, these weaknesses allowed attackers to collect sensitive customer data for nearly a year without detection.

KT allegedly failed to disclose BPFDoor infection

The regulator also found that malware had compromised 38 KT IT service network servers in March 2024.

The affected systems included BPFDoor, a stealthy Linux and Solaris backdoor that can listen passively for specially crafted network packets. The malware can provide remote shell access without opening visible listening ports.

PIPC alleged that KT knew about the infection but did not report it to authorities. It said the company handled the incident internally and did not provide sufficient transparency to customers.

The Commission also said KT deleted logs from some compromised systems during its malware investigation. This prevented investigators from determining whether attackers had stolen additional customer data.

KT ordered to improve privacy and security oversight

Alongside the KT data breach fine, PIPC ordered the company to improve security controls for femtocells and other telecoms equipment.

KT must strengthen its personal information governance and give its Chief Privacy Officer a more meaningful oversight role. It must also expand ISMS-P certification to include its mobile network systems.

PIPC said it also plans to push for tougher penalties against companies that conceal incidents or destroy evidence before or during an investigation.


0 responses to “South Korea Fines Telco Giant KT $39 Million for Customer Data Breach”