The Personal Information Protection Commission (PIPC) has imposed a fine of approximately 54 billion won (about $40 million) on KT for a data breach and unauthorized small payments resulting from illegal femtocells. The PIPC evaluated the actual financial damage heavily, while also considering the scale of the breach, the types of information involved, compensation for victims, and corrective measures in determining the fine.
On July 29, the PIPC announced in a meeting that it had decided to impose a fine of 53,979 million won on KT for violating safety obligations, along with issuing corrective orders and recommendations.
According to the investigation, KT neglected access control to femtocells and its core mobile network, leading to the exposure of personal information for 16,647 users, including mobile phone numbers, International Mobile Subscriber Identities (IMSI), and International Mobile Equipment Identities (IMEI). Among these, 368 users suffered unauthorized payment losses totaling approximately 240 million won.
Yang Cheong-sam, the PIPC's secretary general, stated during a briefing, “This incident is serious not only because it involves a data breach but also because the leaked personal information resulted in actual financial harm.”
The PIPC reported that hackers extracted certificates from lost KT femtocells and embedded them into illegally manufactured femtocells. They accessed KT's internal network without additional authentication from October 8, 2024, to September 5, 2025, for about 11 months, leaking user personal information.
The hackers directed user devices through the illegal femtocells to intercept network transmission information, combining it with separately obtained personal data to attempt unauthorized payments, even stealing payment authentication codes. KT only identified the abnormal access after receiving complaints about unauthorized payments.
The PIPC concluded that the incident stemmed from KT's basic negligence in access control and management of its internal mobile network. KT failed to manage the cell IDs that could verify whether femtocells were authorized, resulting in undetected access by unauthorized devices. It was also noted that KT did not restrict the IP addresses of femtocells accessing its internal network.
The revenue used to calculate the fine included KT's LTE and 5G wireless communication earnings, as femtocells are LTE-based equipment, but 5G services also utilize LTE networks in some areas.
This fine is about 40% of the 134.8 billion won imposed on SK Telecom for a previous data breach incident. While both cases used mobile communication-related revenue as a basis for the fine, the PIPC assessed the severity of the violations and the scale and type of information leaked differently.
In the SK Telecom case, the PIPC classified the violation as 'very serious,' while the KT case was categorized as a 'serious violation.' Although the actual unauthorized payment losses in the KT case were heavily weighted, the relatively smaller number of affected individuals and the limited types of leaked information—mobile phone numbers, IMSI, and IMEI—were also considered. No leaks of subscriber authentication information were confirmed in the KT case.
Yang emphasized, “The occurrence of secondary damage is a very serious factor. We considered the relatively small scale of the breach, the types of information involved, compensation for victims, and corrective measures comprehensively.”
Meanwhile, this fine is limited to the data breach and unauthorized payment incident involving femtocells, and the conclusion regarding KT's malware infection case is still pending.
The PIPC found that KT recognized the malware infection on its servers in March 2024 but failed to report the breach to the government and did not conduct a detailed analysis of the personal data processing servers. The PIPC plans to file a complaint against KT for deleting logs from some servers and submitting false materials, as well as for obstructing the investigation by changing statements.
The PIPC intends to impose separate penalties regarding the malware infection case if new facts are confirmed through the investigation.
* This article has been translated by AI.
Copyright ⓒ Aju Press All rights reserved.