NewsStocksSouth Korean Privacy Regulator Fines KT 53.98 Billion Won Over Femtocell Data Breach

South Korean Privacy Regulator Fines KT 53.98 Billion Won Over Femtocell Data Breach

Author: Korea Herald Business·

Key Takeaways

  • The PIPC imposed a 53.98 billion won ($37.4 million) fine on KT Corp. after hackers exploited vulnerabilities in the telecom operator's femtocell system to access subscriber data belonging to 16,647 customers.
  • The breach resulted in unauthorized mobile payments for 368 users, causing financial losses of approximately 240 million won, which the PIPC cited as evidence of concrete harm beyond passive data exposure.
  • KT was aware of a malware infection on 38 of its servers as early as March last year but failed to report it to authorities and deleted logs from 10 compromised servers in what regulators described as an organized concealment effort.
  • The PIPC is referring the case for criminal investigation based on KT's failure to disclose the breach, its destruction of evidence, and its submission of inaccurate information to regulators.
  • The finalized penalty is significantly lower than the potential maximum of approximately 190 billion won, as the PIPC weighed factors including the breach's scale, KT's corrective actions, and customer compensation measures such as waived cancellation fees.
South Korean Privacy Regulator Fines KT 53.98 Billion Won Over Femtocell Data Breach

South Korea's Personal Information Protection Commission (PIPC) on Thursday imposed a fine of 53.98 billion won ($37.4 million) on KT Corp., the country's largest fixed-line operator and second-largest mobile carrier, over a data breach stemming from the telecom operator's failure to adequately secure its femtocell system.

The PIPC determined that KT's insufficient management of its small-cell base station network enabled hackers equipped with illegally manufactured femtocells—compact, low-power cellular base stations typically used to extend indoor coverage—to gain unauthorized access to the company's mobile network. The breach, which took place in August of last year, compromised the personal data of 16,647 KT subscribers, including customers of mobile virtual network operators. The exposed information comprised subscriber identification numbers, device identification numbers, and mobile phone numbers.

The incident also led to unauthorized mobile payments affecting 368 users, resulting in financial losses of approximately 240 million won, according to the regulator. The PIPC emphasized that the case was especially grave because the stolen data was subsequently used to inflict concrete financial harm, rather than merely constituting a passive exposure of personal information.

In addition, the regulator discovered that 38 servers linked to KT's personal information processing systems had been compromised by multiple strains of malware, including BPFDoor, a stealthy Linux backdoor known for using Berkeley Packet Filter techniques to evade detection, in March 2025.

"KT was aware of the malware infection on its servers in March last year but failed to report the security breach to the government," a PIPC official stated. "During a full-scale inspection of KT's servers, we found signs suggesting an organized attempt to conceal the incident, including the deletion of logs from 10 compromised servers."

The PIPC announced it would refer the matter for criminal investigation, citing KT's failure to report the security incident, its deletion of server logs, and the submission of inaccurate information.

The finalized penalty is markedly lower than the maximum KT could have faced under South Korea's Personal Information Protection Act, which was amended in 2023 to permit fines of up to 3 percent of a company's relevant annual revenue. Earlier estimates had indicated the fine could reach as high as 190 billion won.

The commission explained that in setting the final amount it weighed several factors, including the scale of the breach relative to recent incidents involving SK Telecom and Coupang, the duration of the violations, corrective actions taken by KT, and the company's efforts to compensate affected customers, such as waiving cancellation fees. The penalty arrives amid heightened regulatory scrutiny of South Korea's telecom sector, where a succession of major data breaches has intensified pressure on carriers to demonstrate robust cybersecurity governance.

KT said it accepted the regulator's ruling and issued a renewed apology for the distress caused to customers and the broader public.

"We are rebuilding our personal information protection system from the ground up and expanding security investment to prevent similar incidents and restore customer trust," a KT official said.

KT added that it would review the regulator's written decision before determining whether to pursue legal action.

Separately, the PIPC stated it intends to request an investigation into LG Uplus over allegations that the company disposed of servers before the regulator initiated a probe into a suspected data breach, raising concerns about potential evidence destruction.