The Personal Information Protection Commission has imposed a fine of 53.979 billion won on KT for violating privacy laws. This action follows a data breach linked to inadequate management of femtocells, which resulted in the exposure of personal information and actual financial losses.
On July 29, the commission held its 15th plenary meeting, where it decided to fine KT and issue corrective orders, recommendations for improvement, and a public announcement of the findings. The commission also plans to file charges against KT for obstructing the investigation by submitting false documents and deleting relevant logs. Additionally, it will refer LG Uplus to law enforcement for destroying related servers before the investigation began.
According to the commission's investigation, hackers replicated the certificates of lost KT femtocells and installed them on their own devices to access KT's mobile network. They intercepted information transmitted between user devices and the internal network, exploiting it for unauthorized mobile payments.
As a result, personal information, including phone numbers and subscriber identification numbers of 16,647 KT users, was leaked. Among them, 368 users suffered unauthorized mobile payment losses totaling approximately 240 million won.
The commission found that KT neglected basic access control management by setting the validity period of femtocell certificates to 10 years and failing to restrict access IPs. The lack of a system to detect and block unauthorized femtocell access allowed hackers to access KT's internal network for about 11 months without detection.
It was also confirmed that KT recognized a separate malware infection incident but failed to report it to the government and did not adequately analyze whether personal information had been leaked. Furthermore, KT deleted some server logs and initially provided false statements during the investigation, later submitting the relevant materials.
The commission has ordered KT to strengthen safety measures, including vulnerability assessments of wireless communication equipment like femtocells and blocking unauthorized access. It also recommended clarifying the roles and responsibilities of the personal information protection officer and expanding the scope of certification for personal information management systems to include mobile network systems.
Moreover, the commission plans to push for amendments to privacy laws to penalize actions that conceal or destroy evidence related to data breaches before investigations begin. Proposed penalties include fines equivalent to 3% of total revenue for evidence concealment and daily fines of 0.3% of daily revenue for non-cooperation with investigations or failure to comply with corrective orders.
Meanwhile, LG Uplus has been found to have reinstalled the operating system of its servers or destroyed them after evidence of personal information leaks involving employees and partners was confirmed. The commission stated that this has made it difficult to ascertain the exact circumstances of the leak and any additional damages, leading to a referral for investigation on charges of obstructing official duties.
Song Kyung-hee, chairperson of the Personal Information Protection Commission, stated, “This decision should serve as an opportunity to enhance the security capabilities of the telecommunications industry, which provides essential services to the public. We will improve the system so that actions to conceal or downplay incidents result in significant disadvantages for companies.”
* This article has been translated by AI.
Copyright ⓒ Aju Press All rights reserved.