VYPR
breachPublished Aug 3, 2026· 1 source

South Korean Telco KT Fined $38 Million Over Femtocell Data Breach

South Korea's largest telco, KT, has been fined $38 million by regulators after a year-long data breach involving compromised femtocells led to customer fraud.

South Korea's largest telecommunications provider, KT, has been slapped with a substantial $38 million fine by the country's Personal Information Protection Commission (PIPC) following a protracted data breach that compromised customer information and facilitated fraudulent activities. The breach, which reportedly went unnoticed for 11 months, stemmed from the exploitation of femtocells, small cellular base stations typically used in homes or small businesses.

The investigation by the PIPC was initiated in September 2025 after reports surfaced of customers being affected by fraudulent micropayments. KT subsequently confirmed a breach of personally identifiable information (PII) to the regulator. The PIPC's investigation revealed that hackers successfully extracted a certificate from a lost KT femtocell. This certificate was then embedded into a self-made femtocell, which the attackers used to access KT's mobile network. By forcing user terminals to connect through their rogue femtocell, the attackers were able to intercept transmission and reception data between devices and the internal network.

This intercepted information, combined with other obtained personal details such as name, gender, and date of birth, allowed the threat actors to initiate unauthorized mobile phone micropayments. Crucially, they were able to intercept ARS and SMS messages containing payment authentication codes, thereby successfully completing the fraudulent transactions. In total, the mobile phone number, IMSI (International Mobile Subscriber Identity), and IMEI (International Mobile Equipment Identity) of 16,647 users were compromised. The financial impact was significant, with 368 customers defrauded of approximately 240 million won (around $175,000) through these unauthorized micropayments.

The PIPC attributed the incident to a severe lack of "basic access control management" for KT's internal network, which provided an easy entry point for the rogue femtocell. The regulator highlighted that KT's femtocell management system was "generally inadequate," allowing unauthorized femtocells to gain access with ease. Specific security lapses included issuing femtocell certificates with an excessively long validity period of 10 years and failing to restrict IP addresses for internal network access, which permitted connections from external or overseas IP addresses.

Further compounding the security failures, individuals were able to bypass the femtocell management server. The regulator also pointed to insufficient detection and response capabilities within KT's infrastructure, which contributed to the breach remaining undetected for nearly a year. In response to these findings, the PIPC has mandated that KT strengthen its security posture, conduct thorough vulnerability checks on its wireless communication equipment, and improve its overall governance practices.

Adding to KT's woes, investigators uncovered evidence of malware infection on 38 internal servers, including the BPFDOOR backdoor. The PIPC confirmed that a hacker infiltrated the network in March 2024 by exploiting a vulnerability on the KT Roaming Rental Service website, subsequently uploading malicious code to multiple servers. Evidence suggested the hacker viewed and potentially leaked personal information of KT employees and some partner company employees through an SQL injection attack on the Roaming Rental Service administrator page. The absence of network logs hindered a full assessment of the breach's scope.

KT's handling of the incident also drew criticism. The company did not report the breach to the government at the time, opting instead for internal handling without a comprehensive analysis of PII leakage. The PIPC has filed a complaint regarding this lack of transparency, as well as the deletion of server logs, submission of false data, and retraction of statements made by KT during the investigation. This multifaceted breach underscores significant vulnerabilities in telco infrastructure and the critical need for robust security management and timely incident reporting.

Synthesized by Vypr AI