South Korea's Personal Information Protection Commission (PIPC) has issued a fine of KRW 53.979 billion ($39 million) to KT Corporation, a major telecommunications provider. This penalty follows an investigation into data protection violations related to an internal network compromise that persisted for nearly 11 months.
The breach occurred between October 8, 2024, and September 5, 2025. PIPC initiated an investigation on September 10, 2025, after receiving user reports of fraudulent micropayments. KT Corporation initially reported exposure of approximately 5,500 customer data records, but the PIPC's investigation determined that 16,647 subscribers had their personal information exposed. This led to KRW 240 million ($167,400) in fraudulent mobile payments for at least 368 affected individuals.
The point of breach was identified as a lost KT cellular base station, known as a femtocell, which contained a valid authentication certificate. Attackers retrieved this certificate and used it to create a rogue device that mimicked a legitimate part of KT's network. This allowed them to intercept cellular traffic, including mobile phone numbers, IMSI, and IMEI numbers, from nearby devices connecting to the rogue femtocell. The intercepted data was then combined with other personal information and used to capture SMS and ARS authentication codes for mobile micro-payments.
PIPC found KT's security controls to be inadequate. The femtocell certificates remained valid for 10 years, connections were not restricted by source IP addresses, and a route existed that bypassed the femtocell management server. These vulnerabilities allowed the attackers to maintain access to KT's network and collect sensitive client data for nearly a year without detection. KT Corporation is South Korea's largest telecommunications operator, serving over 13.5 million mobile subscribers and a significant portion of the country's fixed-line and internet users.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
South Korea's Personal Information Protection Commission (PIPC) has fined telecommunications giant KT Corporation $39 million for data protection violations stemming from an 11-month internal network compromise. The breach exposed personal information of 16,647 subscribers and led to fraudulent mobile payments, highlighting significant security inadequacies in KT's network management.