AI Automated Translation.

Font Size

Share

Personal Information Protection Commission imposes 54 billion won fine on KT for data breach involving 16,647 individuals

Personal Information Protection Commission imposes 54 billion won fine on KT for data breach involving 16,647 individuals

539.79 billion won in fines for violating safety measures; third-largest penalty in historyKT reported for obstructing investigation; LG Uplus referred for inquiry after destroying servers prior to probe

[Seoul=NEWSIS] Reporter Lee Young-hwan = On the 29th, KT's Gwanghwamun office building is visible in Seoul Jongno-gu. The Personal Information Protection Commission is scheduled to hold a plenary meeting today to deliberate on whether KT violated the Personal Information Protection Act, along with penalties and corrective orders. July 29, 2026. 20hwan@newsis.com /Photo=Lee Young-hwan
[Seoul=NEWSIS] Reporter Lee Young-hwan = On the 29th, KT's Gwanghwamun office building is visible in Seoul Jongno-gu. The Personal Information Protection Commission is scheduled to hold a plenary meeting today to deliberate on whether KT violated the Personal Information Protection Act, along with penalties and corrective orders. July 29, 2026. [email protected] /Photo=Lee Young-hwan

A fine of 54 billion won has been imposed following the "KT fake base station" incident, in which small cell base stations installed by telecom providers in homes with poor signal coverage were hacked, allowing unauthorized access to make small payments via victims' mobile phones. The act of concealing the incident and obstructing the investigation will be handled separately through criminal proceedings beyond the administrative fine.

On the 30th, the Personal Information Protection Commission announced that it held its 15th plenary meeting on the 29th and decided to impose a fine of 539.79 billion won on KT for violating safety obligation requirements under the Personal Information Protection Act, along with issuing corrective orders, improvement recommendations, and public disclosure orders. This marks the third-largest penalty imposed by the Commission, following Coupang (624.6 billion won) and SK Telecom (134.791 billion won). KT was reported for submitting false documents and deleting logs during the investigation, while LG Uplus was referred for inquiry on charges of obstructing official duties after destroying servers before the investigation began.

According to the Personal Information Protection Commission, this penalty targets the "fake base station" hacking incident that shook the telecommunications industry last year. From October 2024 to September 2025, approximately 11 months, hackers used illegal equipment created by duplicating authentication certificates from lost KT small cells (femtocells) to access KT's internal network, stealing the resident registration numbers and subscriber/device identification numbers of 16,647 users, including those on MVNOs. They also intercepted payment confirmation texts and calls, causing unauthorized small payment damages totaling approximately 240 million won to 368 individuals. The Commission stated, "The severity is extremely high as this case went beyond mere data leakage and resulted in actual financial harm."

Investigation results by the Personal Information Protection Commission revealed that KT had set the validity period of femtocell certificates to 10 years and failed to restrict access IPs, among other deficiencies in internal network access controls. As a result, no abnormal access was detected over the 11th-month period. Although KT claimed it was an unpredictable new-type attack, the Commission rejected this argument. The fine was calculated based on the 5G and LTE sales revenue of the mobile communication service where the incident occurred.

The grounds for reporting were concealment. In March 2024, there were indications that 38 servers had been infected with malware, leading to the leakage of information belonging to employees and partner company staff, yet KT failed to report this to the government and covered it up through internal measures alone. During a comprehensive inspection in April 2025, logs from 10 infected servers were deleted. When questioned by the Personal Information Protection Commission, they initially testified that "no preserved data exists," but after being exposed during digital forensics, they later submitted logs that had been stored.

LG Uplus learned of the breach in August 2025 following an announcement by the American hacking magazine Phrack. Before the Personal Information Protection Commission began its investigation, LG Uplus reinstalled the operating systems of relevant servers, including the Application Password Management System (APPM), and destroyed the servers, thereby preventing any verification of how the data was leaked.

The divergence in handling these two companies—reporting for KT and referral for inquiry for LG Uplus—stems from a legal gap. Under current law, only obstruction during an investigation is punishable; thus, LG Uplus, which destroyed evidence before the investigation began, could only be referred to law enforcement authorities on charges of obstructing official duties under the Criminal Act. This creates a regulatory blind spot where destroying evidence in advance may appear advantageous when an incident occurs. The Personal Information Protection Commission plans to push for legislative amendments this year, including introducing criminal penalties for concealing or destroying evidence before investigation begins, imposing fines up to 3% of total sales revenue for such acts, establishing coercive daily fines of 0.3% of daily sales for non-cooperation during investigations, and introducing orders for data preservation.

KT must submit a report within three months outlining measures to prevent recurrence, including inspections for vulnerabilities in communication facilities and the substantive role performance of the Chief Privacy Officer (CPO), and must publicly disclose the fact of the penalty on its own website.

Song Kyung-hee, Chairperson of the Personal Information Protection Commission, stated, "This penalty should serve as an opportunity to further strengthen security capabilities across the entire telecommunications industry," and added, "We will improve the system so that acts of concealing or downplaying data result in serious disadvantages for companies, fostering industry-wide recognition that transparent disclosure is the most rational choice."

"Please note that this article has been automatically translated by AI, and minor discrepancies from the original text may occur due to machine translation limits."