Back to feed

South Korea fines telco giant KT $39 million for customer data breach

2 min
South Korea fines telco giant KT $39 million for customer data breach

This digest was compiled by AI from multiple sources — links to the originals are below.

South Korea’s Personal Information Protection Commission fined KT Corporation 53.979 billion won ($39 million) for data protection violations that persisted for nearly 11 months. The breach, which lasted from October 2024 to September 2025, exposed the personal data of 16,647 subscribers and led to fraudulent mobile payments of 240 million won. The penalty comes as investigators also found 38 company servers had been compromised by the BPFDoor malware, previously linked to a Chinese espionage group.

Femtocell Compromise

The attack originated from a lost KT femtocell that contained a valid authentication certificate. Hackers retrieved the certificate and installed it on a self-made device, which then appeared as a legitimate part of KT’s network. This rogue base station captured cellular traffic from nearby devices, including mobile phone numbers, IMSI, and IMEI numbers. The intercepted data was combined with additional personal information to capture SMS and ARS authentication codes used for mobile micro-payments. In total, 16,647 subscribers’ data was exposed, and fraudulent payments of 240 million won ($167,400) were made for at least 368 victims.

Security Gaps

PIPC found that KT’s security controls were insufficient: femtocell certificates remained valid for 10 years, connections were not restricted by source IP addresses, and a route existed that bypassed the femtocell management server. These weaknesses allowed the attackers to remain connected to KT’s network undetected for 11 months, from October 8, 2024 to September 5, 2025. The breach was only discovered after customer complaints about fraudulent micro-payments prompted an investigation on September 10, 2025.

BPFDoor Malware Discovery

During the breach investigation, PIPC discovered that 38 of KT’s IT service network servers had been infected with malware, including BPFDoor, since March 2024. BPFDoor is a stealthy backdoor that evaded detection for over five years, and cybersecurity firm PwC linked its use to Red Menshen, a China-nexus espionage group targeting telecommunications providers. The presence of the malware raises concerns of a separate espionage campaign, though it is not directly linked to the femtocell breach.

1 source

Time · lag behind first