South Korea Fines KT Corporation $39 Million for 11-Month Data Breach
South Korea's Personal Information Protection Commission has fined KT Corporation $39 million for a prolonged data breach that exposed personal information of over 16,000 subscribers and facilitated fraudulent mobile payments.
South Korea's Personal Information Protection Commission (PIPC) has levied a substantial fine of KRW 53.979 billion (approximately $39 million USD) against KT Corporation, the nation's largest telecommunications provider, for significant data protection violations. The penalty stems from an internal network compromise that remained undetected for nearly eleven months, from October 8, 2024, to September 5, 2025.
The investigation, initiated on September 10, 2025, following user reports of fraudulent micropayments, revealed that the breach affected the personal data of 16,647 KT subscribers. This compromise led to fraudulent mobile payments totaling KRW 240 million (about $167,400 USD) for at least 368 affected individuals.
The root cause of the breach was traced to a compromised KT femtocell, a small cellular base station. Attackers obtained a valid authentication certificate from a lost femtocell, which they then used to install on a self-made device. This rogue device masqueraded as a legitimate part of KT's network, enabling the interception of cellular traffic, including mobile phone numbers, IMSI, and IMEI numbers, from nearby devices.
Further exploiting these intercepted communications, the attackers combined the data with additional personal information and captured SMS and ARS authentication codes. These codes were then used to facilitate fraudulent mobile micro-payments, highlighting a sophisticated exploitation of network vulnerabilities.
PIPC identified several critical security lapses within KT's infrastructure. The commission noted that femtocell certificates had an excessively long validity period of 10 years, network connections were not restricted by source IP addresses, and a network route existed that bypassed the femtocell management server. These weaknesses provided attackers with an extended window of 11 months to operate undetected within KT's network.
Adding to the severity of the incident, the investigation also uncovered that 38 KT IT service network servers were infected with malware, including the stealthy BPFDoor backdoor, as early as March 2024. The PIPC alleges that KT was aware of this malware infection but failed to report it to the authorities, instead handling the incident internally with a lack of transparency. Evidence suggests that KT, similar to another telecom firm LG U+, deleted logs from compromised servers during malware inspections, hindering the full determination of the breach's scope.
In response to these findings, PIPC has mandated KT to implement enhanced security measures for its femtocells and other telecommunications equipment. The company is also required to strengthen its governance over personal information protection, ensure its Chief Privacy Officer has a more substantive oversight role, and expand its ISMS-P certification to encompass its mobile network systems.
The commission also announced its intention to pursue legislative changes aimed at introducing stricter penalties for companies that conceal or destroy evidence during investigations, signaling a tougher stance on corporate accountability in data breach incidents.