← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

South Korea fines KT Corporation $39 million for 11-month data breach

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • KT Corporation fined $39 million by South Korea's PIPC.
  • Data breach lasted nearly 11 months, affecting 16,647 subscribers.
  • Breach originated from a lost femtocell with an active authentication certificate.
  • Inadequate security controls cited, including long-valid certificates and network bypasses.

Regulatory Fine Imposed on KT Corporation

South Korea's Personal Information Protection Commission (PIPC) has issued a fine of KRW 53.979 billion ($39 million) to KT Corporation, a major telecommunications provider. This penalty follows an investigation into data protection violations related to an internal network compromise that persisted for nearly 11 months.

Details of the Data Breach

The breach occurred between October 8, 2024, and September 5, 2025. PIPC initiated an investigation on September 10, 2025, after receiving user reports of fraudulent micropayments. KT Corporation initially reported exposure of approximately 5,500 customer data records, but the PIPC's investigation determined that 16,647 subscribers had their personal information exposed. This led to KRW 240 million ($167,400) in fraudulent mobile payments for at least 368 affected individuals.

Origin of the Compromise

The point of breach was identified as a lost KT cellular base station, known as a femtocell, which contained a valid authentication certificate. Attackers retrieved this certificate and used it to create a rogue device that mimicked a legitimate part of KT's network. This allowed them to intercept cellular traffic, including mobile phone numbers, IMSI, and IMEI numbers, from nearby devices connecting to the rogue femtocell. The intercepted data was then combined with other personal information and used to capture SMS and ARS authentication codes for mobile micro-payments.

Security Lapses Identified

PIPC found KT's security controls to be inadequate. The femtocell certificates remained valid for 10 years, connections were not restricted by source IP addresses, and a route existed that bypassed the femtocell management server. These vulnerabilities allowed the attackers to maintain access to KT's network and collect sensitive client data for nearly a year without detection. KT Corporation is South Korea's largest telecommunications operator, serving over 13.5 million mobile subscribers and a significant portion of the country's fixed-line and internet users.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

South Korea's Personal Information Protection Commission (PIPC) has fined telecommunications giant KT Corporation $39 million for data protection violations stemming from an 11-month internal network compromise. The breach exposed personal information of 16,647 subscribers and led to fraudulent mobile payments, highlighting significant security inadequacies in KT's network management.