AI Automated Translation.

Font Size

Share

Personal Information Breach Fines to Increase… What Are the Two Key Factors in KT’s Sanction Decision?

Personal Information Breach Fines to Increase… What Are the Two Key Factors in KT’s Sanction Decision?

Personal Information Protection Commission holds plenary session on the 29th; will announce the level of sanctions against KT on the 30th. KT: Financial losses incurred serve as an aggravating factor for fines… However, since the 'SIM authentication key' used for subscriber verification was not exposed, the risk of secondary damage is reduced.

Song Kyung-hee, a commissioner of the Personal Information Protection Commission, delivers opening remarks at the 13th plenary session held on the 8th at the Seoul Jongno-gu government office in Seoul./Photo=Kim Sun-woong
Song Kyung-hee, a commissioner of the Personal Information Protection Commission, delivers opening remarks at the 13th plenary session held on the 8th at the Seoul Jongno-gu government office in Seoul./Photo=Kim Sun-woong

The level of sanctions by the Personal Information Protection Commission (Personal Information Protection Commission) regarding KT’s personal information breach is expected to be decided soon. Under the Personal Information Protection Act, fines of up to 3% of the relevant business segment's sales can be imposed; however, whether actual financial losses occurred and the sensitivity of the leaked information are likely to determine the final fine amount.

The Personal Information Protection Commission will hold a plenary session on the 29th to deliberate on the sanction proposal for KT’s personal information breach.

In September last year, KT suffered a hacking attack that exploited illegal small base stations (femtocells), resulting in the leakage of subscriber identification numbers (IMSI), terminal identification numbers (IMEI), phone numbers, and other data belonging to 22,227 subscribers in the southwestern region of the Seoul metropolitan area. Among them, 368 individuals suffered unauthorized micro-payment damages totaling 777 cases, amounting to approximately 243 million won. The cause of the incident was attributed to negligence in femtocell management.

The Personal Information Protection Act allows for fines of up to 3% of the average sales of the relevant business segment over the three preceding fiscal years. KT’s wireless business sales for the three years prior to the incident totaled approximately 6.5 trillion won, making the maximum possible fine under the law around 190 billion won.

However, the actual fine will be determined by comprehensively reflecting factors such as the severity of the violation, the level of failure to fulfill safety obligations, the scale of damage, and post-incident response. Previously, Coupang was fined approximately 624.6 billion won (about 2%) based on its service sales of around 30 trillion won, while SK Telecom was fined approximately 127.8 billion won (about 1%) based on its wireless business sales of around 13 trillion won.

KT CEO Kim Young-seop apologizes regarding micro-payment damages and the security incident at the West Building of KT Gwanghwamun in Seoul Jongno-gu, late last year./Photo=Hong Hyo-sik
KT CEO Kim Young-seop apologizes regarding micro-payment damages and the security incident at the West Building of KT Gwanghwamun in Seoul Jongno-gu, late last year./Photo=Hong Hyo-sik

The most significant aggravating factor in the KT case is that the personal information breach led to actual financial losses. Another variable is that KT failed to report its server infection with malicious code to the government in 2024 and instead handled it internally. At the time, 43 servers were infected, which were only confirmed late during the government investigation. This incident prompted the Personal Information Protection Commission to introduce a criminal penalty provision (imprisonment of up to two years or a fine of up to 0.2 billion won) for actions such as discarding servers or deleting access logs. However, this provision will not be applied retroactively to the current KT incident.

Conversely, the fact that the SIM authentication key—a core piece of information used for USIM authentication—was not leaked is a representative mitigating factor, as it reduces the likelihood of secondary damage. In contrast, SK Telecom previously had to implement large-scale SIM replacements after both IMSI and SIM authentication keys were leaked together.

Additionally, the scale of damage involving approximately 20,000 individuals is smaller than that of SK Telecom (23 million) and Coupang (over 37 million). Other mitigating factors include the implementation of follow-up measures such as operating a customer compensation program worth around 450 billion won and replacing femtocells.

Industry observers believe it will be difficult for KT’s fine to exceed those imposed on SK Telecom or Coupang. An industry representative stated, “While the occurrence of financial losses is unfavorable, factors such as the non-leakage of the SIM authentication key, the scale of damage, and post-incident response will all be taken into consideration.”

"Please note that this article has been automatically translated by AI, and minor discrepancies from the original text may occur due to machine translation limits."