South Korean Regulator Fines KT 53.9 Billion Won for Data Breach, Concealment

Hackers built illegal femtocells using authentication certificates extracted from base stations KT had lost, enabling unauthorized access to KT's wireless network and data leakage.
There is a discrepancy in the number of affected individuals: joint investigation cited 22,227 affected, while PIPC's count is 16,647 after excluding corporate and multi-line duplicates, with MVNOs included in the figure.
LG Uplus is being referred to police for possible obstruction of duties after regulators found it concealed or destroyed records related to a separate data leak.
Criminal complaints accompanying the KT case include obstructing the investigation and submitting false information, according to the PIPC briefing.
The intrusion occurred between Oct. 8, 2024, and Sept. 5, 2025, with KT only realizing the breach after a user complaint.
South Korea's privacy watchdog has hit KT Corp with a 53.9 billion won ($37.4 million) fine after hackers broke into the telecom giant's wireless network and stole personal data from more than 16,600 mobile users, according to Reuters. The breach also enabled 240 million won in unauthorized payments.
The Personal Information Protection Commission (PIPC) said KT failed to detect the intrusion and concealed the incident from regulators. Investigators also found malicious programs on KT's servers, according to Korea JoongAng Daily.
The attackers built illegal femtocells — small, unauthorized mobile base stations — to get inside KT's network. They did it using authentication certificates stolen from base stations KT had previously lost, according to Reuters. Those certificates let the hackers pose as legitimate network equipment.
The intrusion ran from Oct. 8, 2024, to Sept. 5, 2025 — nearly a full year. KT only discovered the breach after a customer filed a complaint, according to The Edge Malaysia. The PIPC said the company should have caught it far sooner.
The final victim count depends on how you count. A joint investigation found 22,227 affected people. But the PIPC put the number at 16,647 after removing corporate accounts and duplicate multi-line subscribers. Users of mobile virtual network operators (MVNOs) — smaller carriers that ride on KT's network — were included in that figure, according to Mezha.
Stolen data included personal information and device identifiers. The hackers used that data to make 240 million won in fraudulent payments, according to Korea JoongAng Daily. The PIPC said KT's failure to monitor its own network made the theft possible.
The PIPC did not stop at a fine. It filed criminal complaints against KT for obstructing the investigation and submitting false information, according to WDSM. Those are serious charges that go beyond a typical regulatory penalty.
In a separate case, the PIPC referred LG Uplus to police for possible obstruction of duties. Regulators said the carrier concealed or destroyed records tied to its own data leak. The two cases together signal a sharp crackdown on how South Korea's major telecoms handle — and hide — data breaches.
Beyond the fine, the PIPC ordered KT to strengthen its wireless network security and tighten personal data safeguards, according to The Edge Malaysia. The commission framed the case as a major test of South Korea's data-protection and incident-notification rules for the telecom sector.
Regulators also warned that additional criminal complaints could follow if new facts emerge from the ongoing investigation. The KT case is now one of the largest data-breach penalties ever handed to a South Korean telecom company, according to Mezha.
Publishers
14
Articles
21
Reach
35