Media Partner For

Alliance Partner For

Home » Technology » Wireless & Networking » South Korea Fines KT $37.4 Million Over Data Breach

South Korea Fines KT $37.4 Million Over Data Breach

KT corp logo

South Korea’s privacy regulator has imposed a 53.9 billion won ($37.4 million) fine on KT Corp. (KRX: 030200) over a data breach involving unauthorized mobile base stations that exposed the personal information of more than 16,000 mobile subscribers.

The Personal Information Protection Commission (PIPC) announced the penalty on Thursday, alongside corrective orders requiring the country’s largest telecommunications operator to strengthen security across its wireless network infrastructure and improve its personal data protection practices.

According to the regulator, the breach affected the phone numbers and mobile device identification numbers of 16,647 users. The compromised information was later used to conduct unauthorized financial transactions, resulting in total losses of 240 million won for 368 victims.

The watchdog said attackers infiltrated KT’s wireless network by constructing illegal mobile base stations using authentication certificates extracted from legitimate base stations that had previously been lost by the company.

Investigators determined the unauthorized access continued from October 8, 2024, to September 5, 2025, without being detected. The regulator said KT became aware of the intrusion only after receiving a complaint from a customer.

The commission concluded that the company failed to identify the prolonged compromise of its wireless network and ordered KT to strengthen the security of its network equipment while implementing enhanced safeguards for personal information.

In addition to the financial penalty, the regulator said it would file a complaint with police against KT over allegations that the company obstructed an investigation into a separate cybersecurity incident in March 2024.

According to the commission, KT initially claimed it did not possess records related to that earlier incident, in which company servers had been infected with malicious software. The records were later produced after investigators identified indications of evidence tampering during the inquiry.

The regulator alleged that KT’s actions hindered its investigation into the incident, prompting the decision to seek a criminal investigation.

Separately, the privacy watchdog referred LG Uplus Corp. (KRX: 032640) to police on suspicion of obstructing official duties in connection with another data leak investigation.

The commission said its investigation into LG Uplus was launched after an online cybersecurity publication reported a potential data breach in August. Investigators later concluded that the company had destroyed servers, making it difficult to determine how the incident occurred and assess the full scope of the leak.

ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT

Share this post with your friends

RELATED POSTS