Search TorWire

Find cybersecurity guides and research articles

Home > News > Cybersecurity > South Korea Fines KT $39 Million Over Data Breach and 11-Month Cyberattack

South Korea Fines KT $39 Million Over Data Breach and 11-Month Cyberattack

By: Morgan Cipher Senior Privacy Journalist

Last updated: July 31, 2026

Human Written
South Korea Fines KT $39 Million Over Data Breach and 11-Month Cyberattack
  • The regulator responsible for data protection in South Korea has fined KT for a data breach.

  • The hackers exploited a lost femtocell device, poor certificate management, and insufficient access controls to steal customer information for 11 months.

  • KT concealed a malware infection, deleted server logs, and misled investigators, leading to a criminal referral and orders for sweeping security reforms.

The data protection regulator of South Korea has hit KT Corporation with a massive fine. The Personal Information Protection Commission levied a penalty of 53.979 billion won, which equals roughly $39 million.

The fine followed a serious data breach that exposed customer information and led to financial losses. The intrusion lasted nearly 11 months, from October 8, two years ago, until September 5, last year. Hackers accessed the internal network of KT and remained undetected for almost a year.

KT only found out about the breach after receiving reports of unauthorized transactions from customers. Upon further investigation, authorities revealed that 16,647 customers had their personal data compromised. Also, at least 368 customers experienced fraudulent mobile transactions amounting to 240 million won, equivalent to $167,400.

How Hackers Gained Access

The breach started with a lost device. A cellular base station of KT called a femtocell went missing. This device contained a legal authentication certificate. Hackers retrieved this certificate and installed it on their own equipment.

The self-made device then appeared legitimate on the network of KT. It captured cellular traffic from nearby phones and devices. This allowed the attackers to intercept communications between users and the core systems of KT. They obtained phone numbers, IMSI numbers, and IMEI numbers from unsuspecting subscribers.

The attackers combined this intercepted data with additional personal information. They also captured SMS and ARS authentication codes used for mobile micro-payments. This enabled them to complete unauthorized transactions.

The security controls of KT had serious weaknesses. The investigation found that femtocell certificates remained valid for 10 years. The company did not restrict connections by source IP addresses. There is a route that bypasses the femtocell management server completely, so the hackers remained undetected for almost a year.

The PIPC stated that basic access controls could have prevented this incident. KT argued that the attack was unprecedented. But regulators rejected this defense, saying fundamental security measures were missing.

Malware Infection and Evidence Destruction

The investigation uncovered another serious issue. Two years ago, the hackers infected 38 servers of the KT IT services network with malware. The malware included BPFDoor, which is a stealthy backdoor program.

BPFDoor is a Linux and Solaris backdoor and could remain unnoticed for more than five years. Researchers first disclosed this in 2022, noting that it utilizes the technology of Berkeley Packet Filter to passively monitor network traffic. Attackers can activate it with specially crafted packets without opening listening ports. This allows them to bypass firewall protections.

PwC later linked BPFDoor to the Red Menshen espionage group, which has connections to China. This group targets telecommunications providers and other critical sectors.

KT knew about the malware infection since March, two years ago, however, the company failed to report it to authorities. Instead, KT handled the incident internally with no transparency toward customers. PIPC officials confirmed that KT was aware of the breach but did not notify the government.

KT also deleted logs from some compromised servers. The company did this while conducting malware inspections. This happened after another telecom firm, LG U+, followed a similar approach. LG U+ reinstalled operating systems and disposed of servers before investigators could assess the full impact.

Because KT wiped those historical network logs, regulators could not determine whether additional customer data had been stolen. The company initially told investigators that no preserved data existed. However, digital forensics confirmed that logs had been deleted. KT later retracted its statement and submitted logs it had kept separately.

The PIPC decided to refer KT for criminal investigation. The regulator cited obstruction of justice and submission of false information. LG U+ was also referred for investigation over server destruction.

Enforcement Actions and Next Steps

The fine of 53.979 billion won represents about 0.8 percent of the relevant revenue of KT. This is about one-quarter of the legal maximum under the Personal Information Protection Act of South Korea. The maximum penalty is 3 percent of annual revenue. Earlier estimates suggested the fine could reach 190 billion won.

Regulators considered several factors when setting the amount. These included the scale of the breach, the duration of violations, and corrective measures by KT. The company also compensated affected customers by waiving cancellation fees. The relatively small number of leaked records also played a role.

KT accepted the decision of the regulator and apologized. The company announced plans to invest 4 trillion won in information security over the next three years. Also, it promised to review the written verdict before it decides if it will pursue legal action.

The PIPC ordered several corrective measures. KT must strengthen security controls for femtocells and other equipment. The company must reinforce governance over personal information protection. The Chief Privacy Officer of the firm must play a substantive role in oversight.

The regulatory scrutiny on cybersecurity is not limited to South Korea; an Australian court recently fined FIIG Securities $2.5 million for failures in protecting customer data. The company must also expand ISMS-P certification to cover its mobile network systems.

The regulator also announced plans for legislative changes. These would introduce stronger penalties for companies that destroy or conceal evidence, both before or during investigations. The PIPC also plans to introduce compulsory compliance fines of 0.3 percent of daily sales for businesses that fail to cooperate with investigations.

Share this article

About the Author

Morgan Cipher

Morgan Cipher

Senior Privacy Journalist

Morgan combines a journalist’s curiosity with a security specialist’s precision. His reporting on data breaches, privacy laws, and encryption tech has been featured in several tech publications. At TorWire, he focuses on real-world threats and how to counter them, always with an eye on what’s next in digital privacy.

Comments (0)

No comments.