Search
Close this search box.
Government Criticizes KT Over Femtocell Security Lapse Leading to Payment Breach

Seoul: The science ministry announced on Monday that a significant security breach at KT Corp. resulted from inadequate management of femtocells, leading to unauthorized mobile payments throughout the year. The breach involved improper handling of small base stations intended for residential and business use.

According to Yonhap News Agency, the Ministry of Science and ICT disclosed the findings following KT Corp.'s report of unauthorized micropayments amounting to 243 million won (US$169,000), impacting 368 users. Additionally, it was revealed that the mobile numbers, International Mobile Subscriber Identities (IMSI), and International Mobile Equipment Identities (IMEI) of 22,227 users were compromised.

The ministry's investigation concluded that KT's management of femtocells was deficient, allowing illegal access to the company's internal network. A critical issue identified was that all femtocells provided to KT shared identical certificates, which facilitated unauthorized network access. The investigation also uncovered that 94 KT servers were infected with 103 types of malware.

The ministry highlighted that the 10-year expiration period of KT certificates enabled continuous access for femtocells that had previously connected to the network. To prevent future incidents, the ministry recommended that KT regularly update the authentication server's IP address and implement systems to detect and block unauthorized femtocell access attempts.

Following the investigation, the ministry plans to mandate KT to present detailed preventive measures within the next month and will assess the implementation of these measures in June. The ministry also suggested that due to KT's failure to meet contractual obligations, users wishing to unsubscribe might be eligible for waived cancellation fees.

In a separate incident, the ministry addressed a data breach at LG Uplus Corp., initially reported in July. The No. 3 mobile carrier allegedly filed false documents and discarded affected servers, hindering the investigation. The ministry has requested a police investigation into LG Uplus on suspicions of obstructing official duties, noting that server reinstallation or disposal occurred after notification of the breach by the Korea Internet and Security Agency.

Science Minister Bae Kyung-hoon emphasized the importance of secure service environments for business survival and urged companies to prioritize information security. He affirmed the government's commitment to bolstering national information security capabilities in pursuit of becoming a leading artificial intelligence powerhouse.

ADVERTISEMENT