KT Corp.: South Korea to Review KT Data Breach Sanctions on July 29 < Finance < 기사본문

KT Corp.: South Korea to Review KT Data Breach Sanctions on July 29 < Finance < 기사본문

KT Corp. Faces Sanctions Over 2023 Data Breach Linked to Illegal Femtocell Attack

South Korea’s Personal Information Protection Commission (PIPC) will decide on July 29 whether to impose sanctions on KT Corp. following a 2023 data breach caused by an illegal small-cell base station attack. The plenary meeting will determine if KT violated the Personal Information Protection Act (PIPA) and whether administrative fines will be levied.

The breach, detected in September 2023, exposed personal data tied to 22,227 KT subscriber lines, including IMSI numbers, IMEI numbers, and phone numbers. Among the affected users, 368 victims experienced 777 unauthorized micropayment transactions totaling approximately 243 million won ($180,000 USD). The PIPC has also investigated KT’s response to a separate BPFDoor malware infection on its servers.

During deliberations, the commission will assess whether KT implemented adequate technical and administrative safeguards, as well as its compliance with breach reporting and notification requirements. Under PIPA, companies failing to protect personal data may face fines of up to 3% of relevant revenue. Based on KT’s average wireless service revenue of 6.4955 trillion won over the past three years, the maximum potential fine could reach 194.8 billion won ($143 million USD). However, the final amount will depend on factors such as the severity of the breach, the scale of damages, and KT’s incident response.

A decision is expected on July 29, though delays are possible if further review is needed. Previous cases involving SK Telecom and Coupang saw corrective measures approved on the same day as the plenary review.

Source: https://www.thelec.net/news/articleView.html?idxno=12560

KT cybersecurity rating report: https://www.rankiteo.com/company/kt

"id": "KT1785198533",
"linkid": "kt",
"type": "Breach",
"date": "9/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '22,227 subscriber lines',
                        'industry': 'Telecommunications',
                        'location': 'South Korea',
                        'name': 'KT Corp.',
                        'type': 'Telecommunications company'}],
 'attack_vector': 'Illegal small-cell base station (femtocell) attack',
 'data_breach': {'number_of_records_exposed': '22,227',
                 'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'High (personally identifiable '
                                        'information)',
                 'type_of_data_compromised': ['IMSI numbers',
                                              'IMEI numbers',
                                              'Phone numbers']},
 'date_detected': '2023-09',
 'description': 'South Korea’s Personal Information Protection Commission '
                '(PIPC) investigated a 2023 data breach at KT Corp. caused by '
                'an illegal small-cell base station attack. The breach exposed '
                'personal data of 22,227 subscribers, leading to unauthorized '
                'micropayment transactions totaling approximately 243 million '
                'won ($180,000 USD). The PIPC will decide on sanctions for '
                'potential violations of the Personal Information Protection '
                'Act (PIPA).',
 'impact': {'brand_reputation_impact': 'Potential reputational damage due to '
                                       'regulatory scrutiny',
            'data_compromised': 'Personal data of 22,227 subscribers',
            'financial_loss': '243000000 KRW (~180000 USD)',
            'identity_theft_risk': 'High (exposure of IMSI, IMEI, and phone '
                                   'numbers)',
            'legal_liabilities': 'Potential fines up to 3% of relevant revenue '
                                 '(max 194.8 billion KRW / ~143 million USD)',
            'payment_information_risk': 'High (unauthorized micropayment '
                                        'transactions)'},
 'investigation_status': 'Ongoing (PIPC plenary meeting on July 29)',
 'motivation': 'Financial gain (unauthorized micropayments)',
 'post_incident_analysis': {'root_causes': 'Inadequate technical and '
                                           'administrative safeguards against '
                                           'illegal femtocell attacks'},
 'references': [{'source': 'Personal Information Protection Commission '
                           '(PIPC)'}],
 'regulatory_compliance': {'fines_imposed': 'Pending (up to 194.8 billion KRW '
                                            '/ ~143 million USD)',
                           'regulations_violated': ['Personal Information '
                                                    'Protection Act (PIPA)'],
                           'regulatory_notifications': 'PIPC investigation and '
                                                       'plenary meeting '
                                                       'scheduled for July 29'},
 'title': 'KT Corp. Data Breach via Illegal Femtocell Attack',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.