South Korea Fines KT $37.4 Million After Rogue Cell Equipment Exposed Customer Data
Key Takeaways
- KT Fined $37.4 Million: South Korea’s Personal Information Protection Commission imposed a $37.4 million (KRW 53.979 billion) administrative fine on KT after finding that inadequate safeguards allowed unauthorized access to its telecommunications network.
- More Than 16,000 Subscribers Affected: Personal information belonging to 16,647 subscribers was exposed, while 368 customers suffered fraudulent mobile payment transactions totaling roughly $166,000 (KRW 240 million).
- Access-Control Weaknesses Proved Critical: The PIPC found that KT had configured femtocell credentials to remain valid for 10 years, failed to adequately restrict access by IP address and had network routes capable of bypassing femtocell management servers.
- Investigation Expanded Beyond the Initial Breach: Regulators separately found malware on 38 KT servers and said missing or deleted logs prevented investigators from fully determining what occurred on the affected personal-data processing systems.
- Evidence Handling Could Prompt Broader Reform: The PIPC accused KT of obstructing its investigation and is pursuing stronger legal powers to punish evidence tampering and order evidence preservation.
Deep Dive
South Korea’s Personal Information Protection Commission has imposed a $37.4 million (KRW 53.979 billion) administrative fine on KT after concluding that failures in the telecom company’s security controls allowed attackers to reach its internal network and expose the personal information of 16,647 subscribers. The regulator also ordered KT to correct the deficiencies and publish the results of the sanctions, while recommending broader improvements to its privacy program.
The breach was unusual in both its mechanics and its consequences. Attackers obtained authentication credentials from KT femtocells — small cellular base stations used to improve coverage — and copied those credentials into rogue devices. They then used the counterfeit equipment to connect to KT’s network and induce customers’ phones to connect through it.
That put the attackers in the path between the phones and KT’s internal network. They intercepted information moving in both directions and combined it with personal details, including names, gender and birthdates. The attackers could then capture payment authentication codes delivered through calls or text messages and use them to make fraudulent mobile payments.
The compromised information included phone numbers, international mobile subscriber identity numbers and international mobile equipment identity numbers. Among the 16,647 affected subscribers, 368 suffered fraudulent mobile payment transactions worth approximately $166,000 (KRW 240 million).
The distinction between a conventional data theft and what happened at KT is worth dwelling on. The information did not merely leave the company’s systems and acquire some uncertain life elsewhere. According to the PIPC, it was put to work against the people it described. A weakness in telecommunications infrastructure became a way to intercept authentication codes, and a privacy failure became a financial one.
The Equipment KT Controlled
The regulator’s case turns in part on a mundane question with important consequences: Who was responsible for the femtocells? KT had introduced the equipment to improve network coverage for its internet subscribers. The company owned the devices, installed them and controlled their access to its wireless and internal networks. It also managed their authentication systems, security controls and operation. Subscribers supplied the place to put them.
That arrangement left little ambiguity for the PIPC. It concluded that KT operated the femtocells from both a technical and operational standpoint, making the company responsible for the authentication process by which they connected to its telecommunications network and for the personal information transmitted through them.
The controls around that process were where the trouble lay. KT had configured femtocell credentials to remain valid for 10 years and had not restricted access according to IP address. Rogue devices could therefore connect from other mobile carriers and from overseas IP addresses. Investigators also found network routes that bypassed femtocell management servers, while KT had failed to properly manage the Cell IDs assigned when femtocells connected to the core network. The weaknesses left the company’s anomaly detection and response system unattended, the PIPC found.
Using duplicated credentials from lost KT-owned femtocells, unauthorized equipment accessed the company’s internal network from Oct. 8, 2024, until Sept. 5, 2025. KT became aware of the anomalies after complaints arrived from customers about fraudulent payments and other harm.
The PIPC concluded that KT had failed to put safeguards in place to prevent illegal or unauthorized access and data breaches, as required under South Korea’s Personal Information Protection Act. Its $37.4 million (KRW 53.979 billion) fine was accompanied by correction orders requiring KT to address the vulnerabilities and strengthen access controls across its communications network.
The regulator went further than the network itself. It ordered KT to overhaul its privacy governance framework, including clarifying the role and responsibilities of its chief privacy officer in overseeing personal-data processing across the company. It also recommended that KT expand its Information Security Management System-Personal Information Protection certification, which currently covers some IT services, to include telecommunications network systems.
There is a recognizable governance problem beneath the technical detail. KT had authentication rules, management servers and anomaly detection. What the PIPC found was not an absence of security machinery but weaknesses in the way that machinery had been configured and managed. A credential valid for a decade is still a credential. An anomaly detection system left unattended is still, on paper, an anomaly detection system. The breach exposes the distance that can open between possessing a control and controlling something.
What Happened to the Logs
The PIPC’s investigation eventually carried investigators into a separate part of KT’s network, and there the case took a more serious turn. The regulator found that 38 servers in KT’s IT service network had been infected with several forms of malware, including BPF Door, a Linux backdoor capable of bypassing firewalls and security systems. The discovery prompted the PIPC to expand its investigation in November 2025.
Investigators determined that attackers had exploited vulnerabilities in KT’s roaming and rental service website to enter the network and install malware on multiple servers. SQL injection attacks were also used to access and exfiltrate personal information, including names, phone numbers and accounts belonging to some KT employees and personnel at partner companies.
There was a limit, however, to what investigators could reconstruct. The network logs needed to determine what had happened within personal-data processing systems on the 38 infected servers were no longer available. KT had learned of the infections in March 2024 but did not report the incident to the relevant authority, according to the PIPC. Instead, the company took measures to address the infections without conducting an analysis to determine whether data had been breached between March and July 2024. Then, during a broader review in April 2025, KT deleted logs from 10 servers.
The regulator said KT initially told investigators that it had no data concerning the infected servers. Digital forensic work later established that associated logs had been deleted before the investigation. KT subsequently reversed its position and submitted separately retained logs after the deadline, according to the PIPC.
The commission decided to accuse KT of obstructing its investigation, citing the company’s failure to report the malware infections, deletion of server logs and provision of false information. KT was not the only telecom company caught in the regulator’s widening inquiry. The PIPC also referred LG Uplus Corp. to an investigative authority over a separate potential breach after finding that the company had reinstalled operating systems and decommissioned affected servers before investigators could examine them. Those actions impeded the regulator’s ability to determine whether additional information had been leaked.
For the PIPC, the missing evidence has exposed a weakness not simply in corporate controls but in the law it uses to police them. South Korea’s current framework allows the regulator to pursue criminal punishment or fines for evidence tampering during an investigation. The commission says it lacks equivalent provisions governing concealment or destruction before an investigation has formally begun.
It now wants to close that gap. The PIPC is pursuing provisions that would allow criminal punishment and administrative fines for evidence tampering before an investigation begins, along with a whistleblower reward program. It is also seeking amendments to the PIPA that would permit enforcement fines for inaction or failure to comply with correction orders and allow evidence-preservation orders after an incident occurs.
That may prove the more lasting consequence of the case. The breach began with credentials copied from lost pieces of telecommunications equipment, but the investigation ended up confronting what a regulator can establish when the record of an incident has disappeared. Security failures invite scrutiny of the controls that broke. Missing evidence changes the question. It asks whether anyone can still know how badly they broke.
The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

