Skip to main content
Emerging ThreatsData Breaches

South Korea Slaps KT with $39 Million Fine for 11-Month Data Breach

Formal government setting with documents and blurred telecom logo behind somber-toned individual.

KRW 53.979 billion ($39 million) — that is the penalty South Korea's Personal Information Protection Commission (PIPC) has levied against telecommunications giant KT Corporation for failures that let an internal compromise persist for nearly 11 months.

The fine, the timeline, and the scale of exposure

The PIPC’s enforcement action centers on an internal network compromise that the agency says ran from October 8, 2024, to September 5, 2025. The Commission opened a formal investigation on September 10, 2025, after users reported fraudulent micropayments. A day later, KT filed an initial breach notification reporting data on roughly 5,500 customers had been exposed; the PIPC’s probe ultimately concluded the incident exposed personal information for 16,647 KT subscribers.

The Commission also tied at least KRW 240 million ($167,400) in fraudulent mobile payments to the incident, affecting at least 368 customers. KT is South Korea’s largest telecommunications operator: it employs 23,300 people and serves over 13.5 million mobile subscribers, about 90% of the country’s fixed-line subscribers, and 45% of high-speed internet users — a footprint that framed the PIPC’s concern about the breach’s reach.

How a lost femtocell became a network foothold

PIPC identified the point of breach as a lost KT cellular base station — a femtocell — that contained a valid authentication certificate. According to the Commission’s findings, attackers retrieved the certificate, loaded it onto a self-made device that then presented itself as a legitimate part of KT’s network, and captured cellular traffic from nearby devices that connected to the rogue femtocell.

That interception, the Commission says, included mobile phone numbers, IMSI and IMEI identifiers, and ultimately SMS and ARS authentication codes used for mobile micro-payments. The PIPC notes that KT installs femtocells itself, fully owns the devices, and controls their network authentication and authorization.

The Commission alleges multiple security shortfalls that enabled prolonged access: femtocell certificates were valid for 10 years; connections were not restricted by source IP addresses; and a route existed that bypassed the femtocell management server. Those weaknesses, the PIPC concluded, allowed the attackers to remain connected to KT’s network and collect sensitive client data for 11 months without detection.

BPFDoor infection, alleged non-reporting, and erased logs

Separately, the PIPC’s investigation found that 38 KT IT service network servers had been compromised by malware, including BPFDoor, in March 2024. The Commission describes BPFDoor as a stealthy Linux and Solaris backdoor publicly documented in 2022 that evaded detection for more than five years. PwC later linked its use to the China-nexus Red Menshen espionage group that targeted telecommunications providers and organizations in other critical sectors.

BPFDoor uses Berkeley Packet Filter (BPF) technology to passively monitor network traffic and can be activated with specially crafted “magic” packets without opening listening ports, enabling covert remote shell access while bypassing firewall protections, according to the PIPC account. The Commission alleges KT knew about the malware infection since March 2024 but failed to report it to authorities and instead handled the incident internally without transparency toward its customers.

The PIPC further alleges KT deleted logs from some compromised servers while conducting malware inspections. The report notes that LG U+, another telecom firm, followed a similar approach by reinstalling operating systems and disposing of servers before investigators could determine the full impact of its breach. Because KT had wiped historical network logs, the Commission says it could not determine whether additional customer data had been stolen.

PIPC orders and planned legislative changes

As part of the enforcement action, the Commission ordered KT to strengthen security controls for femtocells and other telecommunications equipment, reinforce governance over personal information protection, ensure the Chief Privacy Officer plays a substantive oversight role, and expand ISMS-P certification to cover its mobile network systems. The PIPC also announced plans to pursue legislative changes that would introduce stronger penalties for companies that conceal or destroy evidence before or during investigations.

What this means for telecommunications security teams, regulators, and customers

  • Telecommunications security teams: The PIPC’s findings underscore concrete technical fixes — shorten femtocell certificate lifetimes, restrict connections by source IP, close routes that bypass management servers, and verify log retention practices after malware discovery. The role of covert tools such as BPFDoor highlights the need to detect BPF-based passive monitoring techniques that do not open traditional listening ports.
  • Regulators and legislators: The Commission has not only imposed a large fine but also directed remedial measures and signaled a push for stronger statutory penalties when firms delete evidence or conceal incidents — a regulatory trajectory that may change incident reporting and retention rules in practice.
  • KT customers and the public: The PIPC’s figures — 16,647 subscribers exposed and at least KRW 240 million in fraudulent micropayments across 368 people — will be the baseline for individual recovery claims, disclosures, and any remedial compensation KT may be required to provide as part of compliance with the Commission’s orders.

The PIPC’s action stitches together two separate failure modes — a physical-device compromise exploited via a long-lived certificate and a stealthy, BPF-capable backdoor whose discovery was allegedly handled without external reporting — and treats them as cumulative failures of security governance. With orders to remediate technical controls and a stated intent to seek legislative penalties for evidence destruction, the Commission has signaled both immediate requirements for KT and a broader regulatory shift that will be watched closely by carriers, customers, and lawmakers.

Original story