KT Corporation and LG U+: South Korea fines telco giant KT $39 million for customer data breach

KT Corporation and LG U+: South Korea fines telco giant KT $39 million for customer data breach

KT Corporation Fined $39 Million for 11-Month Data Breach in South Korea

South Korea’s Personal Information Protection Commission (PIPC) has imposed a KRW 53.979 billion ($39 million) fine on telecommunications giant KT Corporation for severe data protection failures that led to an 11-month-long network compromise between October 8, 2024, and September 5, 2025.

The breach came to light on September 10, 2025, after customers reported fraudulent micropayments. KT initially disclosed that 5,500 users were affected, but the PIPC’s investigation revealed the exposure of 16,647 subscribers’ personal data, resulting in KRW 240 million ($167,400) in fraudulent mobile payments for at least 368 victims.

How the Breach Occurred

The attack stemmed from a compromised femtocell a small cellular base station used to extend network coverage. Attackers obtained a valid authentication certificate from the lost device and installed it on a rogue femtocell, tricking nearby devices into connecting. This allowed them to intercept mobile traffic, including phone numbers, IMSI, and IMEI identifiers, and later capture SMS and ARS authentication codes used for micropayments.

The PIPC found KT’s security measures severely lacking:

  • Femtocell certificates remained valid for 10 years without renewal.
  • Connections were not restricted by source IP addresses.
  • A bypass route allowed attackers to evade the femtocell management server.

Additional Security Failures

The investigation also uncovered a separate malware infection in March 2024, affecting 38 KT servers. The malware, BPFDoor a stealthy Linux/Solaris backdoor linked to the China-nexus Red Menshen group enabled attackers to monitor network traffic covertly using Berkeley Packet Filter (BPF) technology. Despite detecting the infection, KT failed to report it and later deleted logs from compromised servers, hindering the PIPC’s ability to assess the full scope of the breach.

Regulatory Response

In addition to the fine, the PIPC ordered KT to:

  • Strengthen femtocell and network security controls.
  • Improve governance over personal data protection.
  • Ensure its Chief Privacy Officer has meaningful oversight.
  • Expand ISMS-P certification to cover mobile network systems.

The Commission also announced plans to push for legislative changes, including stricter penalties for companies that conceal or destroy evidence during investigations. The case follows a similar incident at LG U+, where logs were wiped before authorities could fully assess the breach.

Source: https://www.bleepingcomputer.com/news/security/south-korea-fines-telco-giant-kt-39-million-for-customer-data-breach/

LG유플러스 (LG Uplus) cybersecurity rating report: https://www.rankiteo.com/company/lg-uplus

KT Corp Worldwide cybersecurity rating report: https://www.rankiteo.com/company/kt-corp-worldwide

"id": "LG-KT-1785457450",
"linkid": "lg-uplus, kt-corp-worldwide",
"type": "Breach",
"date": "10/2024",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '16,647 subscribers',
                        'industry': 'Telecommunications',
                        'location': 'South Korea',
                        'name': 'KT Corporation',
                        'type': 'Telecommunications Company'}],
 'attack_vector': ['Compromised Femtocell',
                   'Malware (BPFDoor)',
                   'Authentication Certificate Exploitation'],
 'customer_advisories': 'Customers reported fraudulent micropayments; KT '
                        'initially disclosed 5,500 affected users but PIPC '
                        'found 16,647.',
 'data_breach': {'data_exfiltration': 'Yes (fraudulent micropayments indicate '
                                      'data was used)',
                 'number_of_records_exposed': '16,647',
                 'personally_identifiable_information': 'Yes (phone numbers, '
                                                        'IMSI, IMEI, '
                                                        'authentication codes)',
                 'sensitivity_of_data': 'High (personally identifiable '
                                        'information, authentication codes)',
                 'type_of_data_compromised': ['Phone numbers',
                                              'IMSI',
                                              'IMEI identifiers',
                                              'SMS/ARS authentication codes']},
 'date_detected': '2025-09-10',
 'date_publicly_disclosed': '2025-09-10',
 'description': 'South Korea’s Personal Information Protection Commission '
                '(PIPC) imposed a KRW 53.979 billion ($39 million) fine on KT '
                'Corporation for severe data protection failures leading to an '
                '11-month-long network compromise. The breach exposed 16,647 '
                'subscribers’ personal data, resulting in KRW 240 million '
                '($167,400) in fraudulent mobile payments for at least 368 '
                'victims. The attack involved a compromised femtocell and a '
                'separate malware infection (BPFDoor) linked to the '
                'China-nexus Red Menshen group.',
 'impact': {'brand_reputation_impact': 'Severe (public disclosure, regulatory '
                                       'fine, customer distrust)',
            'customer_complaints': 'Reported fraudulent micropayments',
            'data_compromised': 'Personal data of 16,647 subscribers, '
                                'including phone numbers, IMSI, IMEI '
                                'identifiers, SMS/ARS authentication codes',
            'financial_loss': 'KRW 53.979 billion ($39 million) fine + KRW 240 '
                              'million ($167,400) in fraudulent payments',
            'identity_theft_risk': 'High (exposure of PII and authentication '
                                   'codes)',
            'legal_liabilities': 'PIPC fine, potential future legal actions',
            'operational_impact': 'Network traffic interception, fraudulent '
                                  'micropayments, regulatory scrutiny',
            'payment_information_risk': 'High (fraudulent micropayments)',
            'systems_affected': ['Femtocell network', '38 KT servers']},
 'initial_access_broker': {'backdoors_established': 'BPFDoor malware on 38 KT '
                                                    'servers',
                           'entry_point': 'Compromised femtocell with valid '
                                          'authentication certificate'},
 'investigation_status': 'Completed (PIPC investigation)',
 'lessons_learned': 'Inadequate femtocell security controls, failure to report '
                    'malware infections, and log deletion hindered '
                    'investigation. Need for stricter certificate management, '
                    'IP restrictions, and regulatory compliance.',
 'motivation': ['Financial Gain', 'Data Exfiltration'],
 'post_incident_analysis': {'corrective_actions': ['Strengthen femtocell '
                                                   'security controls',
                                                   'Improve governance over '
                                                   'personal data protection',
                                                   'Ensure Chief Privacy '
                                                   'Officer oversight',
                                                   'Expand ISMS-P '
                                                   'certification to mobile '
                                                   'networks'],
                            'root_causes': ['Unrestricted femtocell '
                                            'certificates (10-year validity)',
                                            'Lack of IP restrictions on '
                                            'femtocell connections',
                                            'Bypass route in femtocell '
                                            'management server',
                                            'Failure to report BPFDoor malware '
                                            'infection',
                                            'Deletion of logs from compromised '
                                            'servers']},
 'recommendations': ['Renew femtocell certificates more frequently',
                     'Restrict femtocell connections by source IP',
                     'Remove bypass routes in management servers',
                     'Improve log retention and incident reporting',
                     'Expand ISMS-P certification to mobile networks',
                     'Ensure Chief Privacy Officer has meaningful oversight'],
 'references': [{'source': 'Personal Information Protection Commission '
                           '(PIPC)'}],
 'regulatory_compliance': {'fines_imposed': 'KRW 53.979 billion ($39 million)',
                           'legal_actions': ['PIPC ordered security '
                                             'improvements',
                                             'Potential legislative changes '
                                             'for stricter penalties'],
                           'regulations_violated': ['South Korea’s Personal '
                                                    'Information Protection '
                                                    'Act']},
 'response': {'remediation_measures': ['Strengthened femtocell and network '
                                       'security controls',
                                       'Improved governance over personal data '
                                       'protection']},
 'stakeholder_advisories': 'PIPC ordered KT to strengthen security controls '
                           'and improve governance.',
 'threat_actor': 'Red Menshen (China-nexus group)',
 'title': 'KT Corporation Fined $39 Million for 11-Month Data Breach in South '
          'Korea',
 'type': ['Data Breach', 'Network Compromise', 'Malware Infection'],
 'vulnerability_exploited': ['Unrestricted Femtocell Certificates',
                             'Lack of IP Restrictions',
                             'Bypass Route in Femtocell Management Server',
                             'Insufficient Log Retention']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.