Skip to main content
Emerging ThreatsData Breaches

KT's Lax Security Exposes 16,647 Users to $175,000 in Unauthorized Micropayments

Close-up of partially disassembled small cellular base station on a surface.

"The hacker extracted a certificate from a lost KT femtocell, embedded it into a self-made femtocell, and then accessed the KT mobile network," the Personal Information Protection Commission (PIPC) explained — a concise chain of events that the regulator says led to stolen identities, fraudulent micropayments and a multimillion-dollar penalty for South Korea's largest telecommunications company.

PIPC's reconstruction of the intrusion

The PIPC opened its investigation into KT in September 2025 after reports that customers had been hit by fraudulent micropayments and after KT itself notified the regulator of a breach of personally identifiable information (PII). The regulator traced the fraud to a stolen femtocell — a small, low-powered cellular base station — and described how an attacker combined network interception with additional personal data to perform unauthorized payments.

The PIPC found the attacker extracted a certificate from a lost KT femtocell, used it in a self-made device to join KT's internal mobile network, and then induced user terminals to route through the attacker's femtocell so that transmission and reception information could be intercepted and correlated with name, gender and date of birth to bypass payment authentication.

How the femtocell campaign worked

The regulator described a straightforward but effective abuse of trust in networked access devices: with a valid femtocell certificate and a rogue base station, the actor intercepted traffic between user devices and KT’s internal systems, then captured ARS and SMS messages that contained payment authentication codes. According to the PIPC, the attacker combined intercepted signaling and message data with additionally obtained personal information to request micropayments and siphon funds.

Scale of data exposure and financial loss

The PIPC concluded that mobile phone numbers, subscriber identification numbers (IMSI) and device identification numbers (IMEI) for 16,647 users were compromised. Financially, 368 customers were defrauded via unauthorized micropayments totaling 240 million won (reported as $175,000).

BPFDoor, the Roaming Rental Service vulnerability and missing logs

Further investigation uncovered a separate but related set of failures. The regulator reported that 38 internal KT servers had been infected with various strains of malware, including the BPFDoor backdoor. The PIPC said that in March 2024 a hacker exploited a vulnerability on the KT Roaming Rental Service website, uploaded a malicious code file and infected multiple servers.

Investigators also found indications that an SQL injection attack on the Roaming Rental Service administrator page allowed the hacker to view and leak personal information — name, phone number and account details — belonging to KT employees and some employees of partner companies. The PIPC said it could not determine whether the breach extended beyond the observed cases because relevant network logs were absent.

Failures in access control, detection, and reporting

  • The PIPC placed responsibility squarely on weak internal controls: KT's femtocell management system "was generally inadequate," allowing unauthorized femtocells to access the internal network.
  • The regulator pointed to specific configuration failures: femtocell certificates were given a long validity period of 10 years and KT did not restrict the IP addresses allowed to connect to its internal network, permitting access from other companies or overseas IP addresses.
  • Individuals were able to bypass the femtocell management server, and insufficient detection and response capabilities meant the intrusion went unnoticed for 11 months.
  • KT did not report the March 2024 breach to the government at the time. Instead the company handled the matter internally and did not conduct a detailed analysis to determine whether PII had been leaked — a decision the PIPC has challenged in a formal complaint alongside allegations of deleted server logs, submission of false data and the retraction of statements during the investigation.

What this means for technologists, regulators, and consumers

  • Technologists and security teams: The case underscores how device-level trust (long-lived certificates on deployed femtocells) and permissive network access controls can be combined into a high-impact attack. The PIPC has mandated vulnerability checks for wireless communication equipment and improved governance as remedial steps.
  • Regulators and compliance officers: The PIPC’s actions show a regulator willing to trace a complex chain of network misuse, demand technical mitigations and pursue administrative complaints where evidence suggests failures in reporting, log retention and candor during inquiries.
  • Consumers and affected users: The breach resulted in compromised identifiers for 16,647 people and monetary loss for 368 customers; the regulator's findings and penalties are intended to force operational changes that reduce the likelihood of similar frauds.

The PIPC has ordered KT to strengthen its security posture and imposed a multimillion-dollar fine — reported in coverage of the case at $38 million — while also filing complaints over KT’s handling of the incident. The immediate questions left by the regulator’s account are operational and specific: will the mandated vulnerability checks and governance changes close the gaps the PIPC identified, and will improved logging and reporting prevent future intrusions from remaining hidden for nearly a year?

https://www.infosecurity-magazine.com/news/koreas-largest-telco-kt-fine-39m/