Search
Close this search box.
KT Corp. Fined 54 Billion Won for Data Breach via Illegal Base Stations

Seoul: South Korea's privacy watchdog announced on Thursday that it has imposed a fine of 53.9 billion won (approximately US$37.4 million) on KT Corp., a major wireless carrier, due to a significant data breach impacting over 16,000 users. The Personal Information Protection Commission (PIPC) also mandated KT to implement corrective measures following the breach, which involved unauthorized access to the company's wireless network through illegal mobile base stations.

According to Yonhap News Agency, the breach, initially reported by KT in September, compromised the phone numbers and mobile device identification numbers of 16,647 users. Malicious actors exploited this information to conduct unauthorized transactions, resulting in a total loss of 240 million won for 368 victims. The PIPC revealed that the hackers operated undetected within KT's wireless network from October 8, 2024, to September 5, 2025, and the breach was only discovered following a user complaint.

The hackers infiltrated the network by constructing illegal base stations using authentication certificates obtained from lost KT base stations. As a consequence, the commission has instructed KT to enhance the security measures for its wireless network equipment and to bolster its personal information protection protocols.

In addition to the fine, the privacy watchdog has decided to file a police complaint against KT for obstructing its investigation into a separate hacking incident in March 2024, which the company failed to report. Initially, KT denied having records of the event, where its servers were compromised with malicious code, but eventually surrendered the records after the regulator uncovered evidence of tampering.

The PIPC has also elected to refer another telecom operator, LG Uplus Corp., to the police for investigation on grounds of obstruction of official duties. This decision follows findings that LG Uplus had concealed or destroyed records of a data leak, initially reported by an online cybersecurity publication in August. The regulator discovered that the company had dismantled servers, complicating efforts to ascertain the exact circumstances of the leak.

ADVERTISEMENT