Breach

KT Corporation fined $39 million for 11-month data breach

(Adobe Stock)

South Korea's Personal Information Protection Commission (PIPC) has fined KT Corporation, the country's largest telecommunications operator, KRW 53.979 billion (approximately $39 million) for significant data protection violations. The penalty stems from an internal network compromise that allowed attackers to access subscriber data for nearly 11 months, with further coverage provided by Bleeping Computer.

The breach, which lasted from October 8, 2024, to September 5, 2025, exposed the personal information of 16,647 KT subscribers. Attackers exploited a lost KT femtocell, a small cellular base station, by retrieving its authentication certificate. They then used this certificate on a rogue device to intercept cellular traffic, including phone numbers and authentication codes, leading to fraudulent mobile payments totaling KRW 240 million for at least 368 customers.

The PIPC cited inadequate security controls, including long-lived femtocell certificates and a lack of IP address restrictions, as contributing factors. Additionally, the investigation revealed that 38 KT servers were compromised by BPFDoor malware in March 2024. The PIPC alleges KT failed to report this malware infection promptly and deleted logs from compromised servers, hindering the investigation into potential further data exposure. The commission has ordered KT to strengthen security measures and is considering legislative changes for concealing evidence.

Source: Bleeping Computer

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

Related Terms

Attack Vector

You can skip this ad in 5 seconds