AI Automated Translation.

Font Size

Share

One certificate allowed roaming through the communications network for 11 months… KT breached by 'fake base stations'

One certificate allowed roaming through the communications network for 11 months… KT breached by 'fake base stations'

No restrictions on access IP; unauthorized equipment detection failedPersonal information compromised; text and phone authentication stolen…"Basic access control failure"

[Seoul=NEWSIS] Reporter Lee Young-hwan = On the 29th, a KT agency store is visible in Seoul. The Personal Information Protection Commission held a plenary session today and is scheduled to deliberate on whether KT violated the Personal Information Protection Act, along with penalty measures such as fines and corrective orders. 2026.07.29. 20hwan@newsis.com /Photo=Lee Young-hwan
[Seoul=NEWSIS] Reporter Lee Young-hwan = On the 29th, a KT agency store is visible in Seoul. The Personal Information Protection Commission held a plenary session today and is scheduled to deliberate on whether KT violated the Personal Information Protection Act, along with penalty measures such as fines and corrective orders. 2026.07.29. [email protected] /Photo=Lee Young-hwan

The KT personal information leak incident differs from previous hacking cases because hackers replicated a telecommunications company's small base station to infiltrate the core communications network. Instead of attacking servers storing personal data, they inserted themselves between users' devices and the communications network, intercepting both calls and text message authentication information.

According to an investigation report released by the Personal Information Protection Commission on the 30th, the starting point of the KT attack was a 'femtocell.' A femtocell is a small base station installed in areas with weak mobile signals, such as homes, offices, or underground spaces. Owned by KT, it is directly installed by technicians, and KT manages all aspects including network access approval, certificate issuance, and internal network access rights.

Hackers copied the certificate stored on a lost KT femtocell and inserted it into self-made equipment. This was equivalent to stealing the identity card of legitimate equipment and attaching it to a fake base station. Subsequently, they induced nearby users' devices to recognize the illegal device as a normal base station and connect to it.

Once devices connected to the illegal femtocell, hackers intercepted mobile phone numbers, subscriber identification numbers (IMSI), and device identification numbers (IMEI) traveling between the terminals and KT's internal network. They combined this with separately obtained names, genders, and birthdates to apply for small-amount payments on behalf of users.

Authentication required for payment approval was also breached along the same route. Text messages (SMS) containing authentication codes and automated response calls (ARS) were routed through the illegal femtocell, which hackers intercepted to finalize payment approvals. 368 victims suffered damages totaling approximately 240 million won. The breach did not end with personal information leaking externally; the entire identity verification process via mobile communications networks was neutralized.

The security loopholes identified by the Personal Information Protection Commission were not limited to one or two issues. The validity period of femtocell certificates extended up to 10 years, meaning that even if equipment was lost or certificates were duplicated, they could be exploited for an extended period. However, controls to revoke or renew these certificates failed to function.

Access IP addresses were not restricted either. Hackers could connect using stolen certificates from any source—not only KT's designated lines but also from other telecommunications companies or overseas IPs. There was also a bypass route that reached the core communications network without passing through the femtocell management server. The cell ID, an identifier assigned when equipment connects to the network, was not managed at all, meaning unauthorized devices could attach without detection or blocking.

These overlapping vulnerabilities allowed hackers to remain in KT's internal network for approximately 11 months from October 2024 to September 2025 without undergoing additional authentication procedures. KT failed to detect any anomalies during this period and only identified abnormal access after accumulating cases of fraudulent payments and user complaints.

During the deliberation process, KT argued that the attack was unprecedented because hackers directly manufactured femtocells, making it difficult to predict. The Personal Information Protection Commission reached a different conclusion: femtocells are essential equipment that users in underserved areas must use for communication, and hacking via femtocells has been repeatedly flagged as a security vulnerability in overseas cases and academic research. The core issue was not the novelty of the method but whether the communications network operator fulfilled its fundamental obligation to implement basic access control.

The Personal Information Protection Commission issued a corrective order requiring KT to inspect vulnerabilities across all wireless communication network equipment, including femtocells, and strengthen access controls over personal information within the network. It also recommended expanding KT's Information Security Management System for Personal Information Protection (ISMS-P) certification—which had previously been limited to certain IT services—to cover the mobile communications networks and systems where the breach occurred. This ruling confirmed that the defense line protecting personal information lies not in servers but in the communications network itself.

"Please note that this article has been automatically translated by AI, and minor discrepancies from the original text may occur due to machine translation limits."