Seoul: A nationwide rush for sensitive universal subscriber identity modules (USIMs) began Monday for 25 million people on cell phone plans from SK Telecom and carriers using its network. After a delay following a large-scale cyberattack on its subscriber server on April 18 that leaked the USIM information of its subscribers, SK Telecom began offering free USIM replacements about ten days later.
According to Yonhap News Agency, subscribers scrambled as they rushed to contact retail outlets to check for available USIM cards, in a scene reminiscent of how people used to line up to receive masks and tests during the COVID-19 pandemic. But most were unsuccessful and may have to wait for months for the promised replacements. The company said Wednesday that three months are needed to replace USIM cards for all 25 million subscribers. Meanwhile, it asked its subscribers to register with its USIM protection service program. Many subscribers are now moving to rival carriers such as KT and LG Uplus, while those that remain feel wary and distrustful.
Despite all this new information, it isn't easy to find relief in the initial government's findings released Tuesday. After examining SK Telecom's five servers, the Ministry of Science and ICT said that while the data leak did involve four types of information that could possibly be used for USIM cloning, the breach did not involve codes used for identifying mobile devices. As a result, USIM cloning or swapping can be prevented through SK Telecom's protection program. Even so, the government still urged subscribers to get new USIMs and register for the protection service. The full investigations will take a few to several months to be completed.
In a country renowned for its digital infrastructure, the breach feels akin to a simultaneous breach of one's phone company and bank, with potential compromises to personal and financial data. This incident could serve as a catalyst to enhance digital systems across the nation. Mobile phones now function as digital IDs and platforms for numerous transactions, including financial ones, making their security paramount.
The exact causes of what happened at SK Telecom's servers on April 18 and how the massive malware attack unfolded must be thoroughly investigated and made public in an effort to update the nation's digital security. For now, subscribers will have little choice but to take steps to better protect their digital data.
Amid the chaos caused by the cyberattack and breach of customer data, much remains to be said about the actions of the nation's biggest mobile carrier following the incident. The company exceeded the required timeline to report the attack to the authorities, a course of action likely to face "due punishment," according to Minister of Science and ICT Yoo Sang-im. Regulatory authorities have already warned that under the revised Personal Information Protection Act, the company would face higher fines than when a similar incident occurred in 2023. Experts have also pointed out the company's relatively lower investment in data protection compared to its competitors.
The company's delay in notifying the authorities and the public about the cyberattack, coupled with the lack of sufficient replacement USIMs, should serve as a clear example of what not to do in a crisis for other mobile carriers. Even those subscribers who stay with SK Telecom are likely to continue to feel a nagging sense of distrust. Appearing at the National Assembly, SK Telecom CEO Ryu Young-sang called the incident potentially the "worst in the history of the telecommunication industry," vowing the company will do all it can. It should keep its promise. The mobile carrier must reinvigorate its crisis management efforts, but more importantly, strengthen its data protection and rebuild confidence in its cybersecurity.