KT Corporation: KT Corporation fined $39 million for 11-month data breach

KT Corporation: KT Corporation fined $39 million for 11-month data breach

KT Corporation Fined $39 Million for Prolonged Data Breach in South Korea

South Korea’s Personal Information Protection Commission (PIPC) has imposed a KRW 53.979 billion ($39 million) fine on KT Corporation, the country’s largest telecommunications provider, for severe data protection failures. The penalty follows a near-year-long breach from October 8, 2024, to September 5, 2025, during which attackers accessed the personal data of 16,647 subscribers.

The attackers exploited a lost KT femtocell a small cellular base station by extracting its authentication certificate and deploying it on a rogue device. This allowed them to intercept cellular traffic, including phone numbers and authentication codes, leading to fraudulent mobile payments totaling KRW 240 million ($175,000) for at least 368 customers.

The PIPC identified critical security lapses, including long-lived femtocell certificates and the absence of IP address restrictions, which facilitated the breach. Further investigation revealed that 38 KT servers were compromised by BPFDoor malware in March 2024, though the company allegedly failed to report the infection promptly and deleted logs from affected systems, obstructing the probe into potential additional data exposure.

In response, the PIPC has ordered KT to enhance security measures and is exploring legislative changes to penalize evidence concealment. The incident underscores systemic vulnerabilities in telecom infrastructure and regulatory enforcement.

Source: https://www.scworld.com/brief/kt-corporation-fined-39-million-for-11-month-data-breach

KT SAT cybersecurity rating report: https://www.rankiteo.com/company/ktsat

"id": "KTS1785522946",
"linkid": "ktsat",
"type": "Breach",
"date": "10/2024",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '16,647 subscribers',
                        'industry': 'Telecommunications',
                        'location': 'South Korea',
                        'name': 'KT Corporation',
                        'size': 'Largest telecommunications provider in South '
                                'Korea',
                        'type': 'Telecommunications Provider'}],
 'attack_vector': 'Exploited lost femtocell authentication certificate, rogue '
                  'device deployment',
 'data_breach': {'data_exfiltration': 'Yes (intercepted cellular traffic)',
                 'number_of_records_exposed': '16,647',
                 'personally_identifiable_information': 'Yes (phone numbers, '
                                                        'authentication codes)',
                 'sensitivity_of_data': 'High (personally identifiable '
                                        'information, authentication '
                                        'credentials)',
                 'type_of_data_compromised': ['Personal data',
                                              'Phone numbers',
                                              'Authentication codes']},
 'date_detected': '2025-09-05',
 'description': 'South Korea’s Personal Information Protection Commission '
                '(PIPC) imposed a KRW 53.979 billion ($39 million) fine on KT '
                'Corporation for severe data protection failures. The breach '
                'lasted from October 8, 2024, to September 5, 2025, during '
                'which attackers accessed the personal data of 16,647 '
                'subscribers. Attackers exploited a lost KT femtocell to '
                'intercept cellular traffic, leading to fraudulent mobile '
                'payments totaling KRW 240 million ($175,000) for at least 368 '
                'customers. The PIPC identified critical security lapses, '
                'including long-lived femtocell certificates and the absence '
                'of IP address restrictions. Additionally, 38 KT servers were '
                'compromised by BPFDoor malware in March 2024, but the company '
                'allegedly failed to report the infection promptly and deleted '
                'logs, obstructing the investigation.',
 'impact': {'brand_reputation_impact': 'Severe (regulatory fine, public '
                                       'disclosure of security lapses)',
            'data_compromised': 'Personal data of 16,647 subscribers, phone '
                                'numbers, authentication codes',
            'financial_loss': 'KRW 53.979 billion ($39 million) fine, KRW 240 '
                              'million ($175,000) in fraudulent payments',
            'identity_theft_risk': 'High (phone numbers and authentication '
                                   'codes exposed)',
            'legal_liabilities': 'KRW 53.979 billion ($39 million) fine, '
                                 'potential legislative changes for evidence '
                                 'concealment penalties',
            'operational_impact': 'Compromised cellular traffic interception, '
                                  'fraudulent transactions',
            'payment_information_risk': 'High (fraudulent mobile payments '
                                        'executed)',
            'systems_affected': '38 KT servers, femtocell infrastructure'},
 'initial_access_broker': {'entry_point': 'Lost femtocell authentication '
                                          'certificate'},
 'investigation_status': 'Completed (with obstruction due to log deletion)',
 'lessons_learned': 'Critical need for secure femtocell certificate '
                    'management, IP address restrictions, prompt malware '
                    'reporting, and log preservation to prevent obstruction of '
                    'investigations.',
 'motivation': 'Financial gain (fraudulent mobile payments)',
 'post_incident_analysis': {'corrective_actions': ['Enhance femtocell security',
                                                   'Implement IP address '
                                                   'restrictions',
                                                   'Improve malware detection '
                                                   'and reporting',
                                                   'Preserve logs for '
                                                   'compliance',
                                                   'Conduct security audits'],
                            'root_causes': ['Lost femtocell with long-lived '
                                            'certificate',
                                            'Absence of IP address '
                                            'restrictions',
                                            'BPFDoor malware infection on 38 '
                                            'servers',
                                            'Failure to report malware '
                                            'promptly',
                                            'Log deletion obstructing '
                                            'investigation']},
 'recommendations': 'Implement short-lived femtocell certificates, enforce IP '
                    'address restrictions, enhance malware detection and '
                    'reporting protocols, preserve logs for regulatory '
                    'compliance, and conduct regular security audits of '
                    'telecom infrastructure.',
 'references': [{'source': 'Personal Information Protection Commission '
                           '(PIPC)'}],
 'regulatory_compliance': {'fines_imposed': 'KRW 53.979 billion ($39 million)',
                           'legal_actions': 'Exploring legislative changes to '
                                            'penalize evidence concealment',
                           'regulations_violated': 'South Korea’s Personal '
                                                   'Information Protection '
                                                   'Act'},
 'response': {'remediation_measures': 'Enhancement of security measures '
                                      '(ordered by PIPC)'},
 'stakeholder_advisories': 'PIPC ordered KT to enhance security measures and '
                           'is considering legislative changes for evidence '
                           'concealment penalties.',
 'title': 'KT Corporation Fined $39 Million for Prolonged Data Breach in South '
          'Korea',
 'type': 'Data Breach',
 'vulnerability_exploited': 'Long-lived femtocell certificates, absence of IP '
                            'address restrictions, BPFDoor malware'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.