South Korea’s Personal Information Protection Commission (PIPC) has imposed a fine of 53.979 billion won (around $39 million) on telecommunications giant KT Corporation after finding serious violations of the country’s personal data protection laws. The investigation found that attackers remained inside KT’s internal network for nearly 11 months, from October 8, 2024, to September 5, 2025. During that period, they were able to access customer information and misuse it for financial fraud. The penalty is one of the largest data protection fines issued by the regulator.

south-korea-telecom-cybersecurity-data-breach-kt-corporation

The case first came to light in September 2025 after several customers reported suspicious mobile micropayment transactions that they had never approved. Following those complaints, the privacy regulator opened an investigation on September 10, and KT submitted its first breach notification the next day. At that time, the company believed the incident had affected around 5,500 customers, but investigators later discovered the actual impact was much larger than initially reported.

According to the final investigation, the breach exposed the personal information of 16,647 KT mobile subscribers. Authorities also confirmed that at least 368 customers became victims of fraudulent mobile payments, resulting in losses of approximately 240 million won (about $167,400). The regulator said the attackers collected enough personal information to bypass security checks and carry out unauthorized payment transactions using stolen customer data.

mobile-payment-fraud-customer-financial-loss-south-korea

Investigators traced the attack to a lost KT femtocell, which is a small cellular base station used to improve mobile signal coverage. The missing device still contained a valid authentication certificate that should have been protected. Cybercriminals reportedly extracted this certificate and installed it on a rogue device, allowing it to appear as a legitimate part of KT’s mobile network. This enabled the attackers to secretly intercept communications from nearby mobile users.

The fake network equipment allowed attackers to capture important subscriber information, including mobile phone numbers, IMSI identifiers, and IMEI device numbers. Investigators found that the stolen information was later combined with other personal details and intercepted SMS and automated authentication codes used for mobile micropayments. This combination gave criminals enough information to complete fraudulent payment transactions without the victims’ knowledge.

sms-authentication-code-mobile-identity-verification-security

The Personal Information Protection Commission concluded that KT was responsible for protecting the compromised equipment because the company owned the devices and managed the authentication and authorization systems connected to them. The regulator also found multiple security weaknesses during its investigation, including malware discovered on KT’s servers. Officials said these failures showed that the company had not implemented adequate security measures to protect customer information from cyber threats.

The investigation also found that KT failed to properly report the full extent of the incident as required under South Korean law. According to the regulator, the company did not immediately disclose all of the affected customers and the scale of the attack during the early stages of the investigation. Authorities said timely reporting is essential because it allows customers to take protective action and helps regulators respond more effectively to major cybersecurity incidents.

kt-femtocell-network-security-cellular-base-station

KT Corporation is South Korea’s largest telecommunications provider, serving more than 13.5 million mobile subscribers along with broadband, cloud, IPTV, and enterprise IT services. The case has become another reminder that telecom companies remain attractive targets for cybercriminals because they manage huge amounts of sensitive customer information. Regulators hope the record penalty will encourage organizations to strengthen cybersecurity defenses, improve incident reporting, and better protect customer data from future attacks.

Stay alert, and keep your security measures updated!

Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news