South Korea's Personal Information Protection Commission (PIPC) has fined KT Corporation, the country's largest telecommunications operator, KRW 53.979 billion (approximately $39 million) for significant data protection violations. The penalty stems from an internal network compromise that allowed attackers to access subscriber data for nearly 11 months, with further coverage provided by Bleeping Computer.The breach, which lasted from October 8, 2024, to September 5, 2025, exposed the personal information of 16,647 KT subscribers. Attackers exploited a lost KT femtocell, a small cellular base station, by retrieving its authentication certificate. They then used this certificate on a rogue device to intercept cellular traffic, including phone numbers and authentication codes, leading to fraudulent mobile payments totaling KRW 240 million for at least 368 customers.The PIPC cited inadequate security controls, including long-lived femtocell certificates and a lack of IP address restrictions, as contributing factors. Additionally, the investigation revealed that 38 KT servers were compromised by BPFDoor malware in March 2024. The PIPC alleges KT failed to report this malware infection promptly and deleted logs from compromised servers, hindering the investigation into potential further data exposure. The commission has ordered KT to strengthen security measures and is considering legislative changes for concealing evidence.Source: Bleeping Computer
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
Related Terms
Attack VectorYou can skip this ad in 5 seconds




