South Korea's biggest telecommunications company has been hit with a multimillion-dollar penalty after critical security weaknesses allowed hackers to steal from its subscribers. The country's Personal Information Protection Commission announced the fine against KT, formerly Korea Telecom, following an investigation that began in September 2025 into reports of fraudulent micropayments affecting customers. The company serves more than 13 million mobile subscribers—the majority of South Korea's domestic market—and nearly half of all high-speed internet users nationwide.
The breach stemmed from theft of a femtocell, a small cellular base station typically used in homes or small businesses. Hackers extracted a security certificate from the stolen device, embedded it into their own homemade femtocell, and used it to access KT's mobile network. By forcing customer phones to route through the rogue device, attackers intercepted communications between users and KT's internal systems. They combined this captured data with additional personal details—names, gender, and birth dates—to request mobile phone micropayments, then stole authentication codes sent via text message and automated voice systems. In total, personal data belonging to 16,647 users was compromised, including mobile phone numbers, subscriber identification numbers, and device identification numbers. Some 368 customers lost 240 million won, equivalent to $175,000, through unauthorized micropayments.
The regulator determined that the incident resulted from a failure to implement basic access controls for KT's internal network, which enabled attackers to connect their unauthorized femtocell. According to the commission, KT's femtocell management was "generally inadequate," allowing rogue devices easy access to internal systems. The company had configured femtocell certificates with a validity period of 10 years and failed to restrict which IP addresses could connect to the internal network, permitting access from other companies or foreign IP addresses. The regulator also noted that users could bypass the femtocell management server entirely, and weak detection capabilities meant the breach went undetected for 11 months.
The commission's investigation uncovered a separate security failure involving 38 internal servers infected with multiple malware strains, including the BPFDoor backdoor. Attackers infiltrated the network in March 2024 by exploiting a vulnerability on KT's Roaming Rental Service website and uploaded malicious code files to multiple servers. Evidence suggested hackers viewed and leaked personal information—names, phone numbers, and accounts—of KT employees and some partner company staff through an SQL injection attack on the service's administrator page. The commission couldn't determine the full scope of this breach because network logs were missing. KT didn't report the incident to authorities at the time, instead handling it internally without a thorough analysis of whether personal data had been stolen. The regulator has since filed a complaint over KT's failure to report, as well as the deletion of server logs, submission of false data, and retraction of statements during the investigation.
The commission has mandated improvements to KT's security posture, requiring vulnerability assessments for wireless communication equipment and enhanced governance practices. The case highlights how legacy security practices—like decade-long certificate validity periods and unrestricted network access—can create openings for sophisticated attacks on critical telecommunications infrastructure. For a company serving the majority of South Korea's mobile market, the 11-month detection gap and subsequent cover-up attempts represent failures not just of technology but of accountability to millions of customers whose data and money were at risk.

