Industry - Data Breach
Executive Summary
South Korea's Personal Information Protection Commission fined telecommunications giant KT Corporation $39 million after hackers accessed its network for nearly 11 months, exposing personal data of over 16,000 customers and enabling fraudulent mobile payments. The breach occurred when attackers retrieved a valid authentication certificate from a lost cellular base station device and used it to intercept customer communications, including phone numbers and SMS authentication codes. The governm...
What Happened
Between October 2024 and September 2025, hackers compromised South Korea's KT Corporation telecommunications network for nearly 11 months. The attackers obtained a valid authentication certificate from a lost cellular base station device (femtocell) and used it to create a rogue station that intercepted customer communications, including phone numbers, device identifiers, and SMS authentication codes. This enabled fraudulent mobile payments totaling approximately $167,400 affecting at least 368 customers, with personal data of over 16,000 KT subscribers exposed overall.
Who Is Affected
At least 16,647 KT Corporation subscribers in South Korea had their personal information exposed, including mobile phone numbers and device identifiers. Among those affected, 368 customers experienced fraudulent mobile micropayments. KT serves over 13.5 million mobile subscribers, 90% of South Korea's fixed-line subscribers, and 45% of the country's high-speed internet users.
Why It Matters
This breach demonstrates critical vulnerabilities in telecommunications infrastructure security, where authentication certificates valid for 10 years, lack of IP address restrictions, and inadequate network monitoring allowed undetected network access for nearly a year. The incident also revealed that 38 of KT's IT servers had separately been infected with BPFDoor malware since March 2024, indicating systemic security failures at a telecommunications provider serving the majority of South Korea's population. The $39 million fine represents one of South Korea's significant enforcement actions for data protection violations.
What You Should Do
If you are a KT Corporation customer in South Korea, immediately monitor your mobile account for any unauthorized micropayments or unusual activity and report suspicious charges to KT. Enable additional authentication methods beyond SMS codes where possible, as SMS-based authentication was compromised in this breach. Contact KT directly to confirm whether your account was among those affected and request details about what specific data was exposed. Consider reviewing and updating passwords for any accounts that used SMS authentication through KT's network during the breach period.
Summary generated from verified sources and reviewed before publication. How we summarize.
Sources