
The Personal Information Protection Commission announced on the 30th that it imposed a fine of 53.979 billion won on KT for its data breach incident.
According to the commission, hackers extracted certificates from lost KT femtocells and installed them in self-made femtocells before connecting to KT’s mobile network. They then user devices to route through the hackers’ femtocells, intercepting transmission and reception information between the devices and the internal network. By combining this newly acquired data with additional personal information obtained, they requested small-amount mobile payments and successfully completed unauthorized transactions by stealing ARS and SMS messages containing payment authentication codes.
Investigations revealed that personal information of 16,647 KT users was leaked, resulting in approximately 240 million won in unauthorized small-payment damages targeting 368 individuals. The commission explained that the incident is particularly serious because the leaked personal information directly led to actual financial losses.
The investigation found that KT neglected basic access control management for its internal network while managing and operating femtocells. It failed to restrict access IP addresses for femtocells connecting to the internal network, allowing connections from third-party or foreign IPs. Additionally, there was no detection and response system in place for abnormal connection attempts using unauthorized cell IDs, and KT also neglected access control management over its personal information processing systems via femtocells.
The commission stated that fines were calculated based on relevant revenue, not exceeding 3% of total sales. The fine was determined using the 5G and LTE communication revenue from KT’s mobile services where unauthorized small payments occurred, excluding independent revenues such as IPTV and internet communications.
The difference in monetary terms compared to last year’s SK Telecom data breach fine (134.791 billion won) stems from differences in the type of leaked information and the scale of damage. In the SKT incident, subscriber identification numbers—critical information—were leaked, affecting over 20 million people, leading the commission to judge it more severe than the KT case. The commission classified the SKT incident as a very serious violation, while the KT incident was deemed a serious violation. However, the fact that victim compensation and corrective measures were implemented quickly served as mitigating factors.
It was also revealed that KT first became aware of malware infection on its servers in March 2024 but failed to report the security breach and conducted no detailed analysis regarding potential data leaks before taking self-directed actions. KT systematically concealed the incident, including deleting logs from some infected servers. During the investigation, KT falsely claimed there were no preserved records for the infected servers and later submitted logs belatedly, substantially obstructing the accident investigation. The commission decided to file criminal charges against KT on these grounds.
Meanwhile, the Personal Information Protection Commission decided to refer LG Uplus for investigation today. This is because LG Uplus reinstalled or discarded operating systems of relevant servers, including APPM servers, before the commission’s investigation began, making it difficult to verify the exact circumstances of the data leak and whether additional leaks occurred.