South Korea’s privacy watchdog has ordered telecommunications provider KT Corporation to pay KRW 53.979 billion (about $39 million) after concluding that inadequate security measures allowed cybercriminals to compromise customer data and remain connected to the company’s network for nearly a year. The regulator also accused KT of failing to properly disclose a separate malware incident that affected dozens of internal servers.
The enforcement action follows an investigation by the Personal Information Protection Commission (PIPC), which began after customers reported unauthorized mobile micropayments in September 2025. KT initially notified authorities that approximately 5,500 customers were affected, but investigators later determined the breach impacted 16,647 subscribers. The Commission said at least 368 customers suffered fraudulent mobile payment transactions totaling approximately KRW 240 million (around $167,400).
According to the investigation, the attackers gained an advantage by exploiting a legitimate authentication certificate recovered from a lost KT-owned femtocell, a small cellular base station used to extend mobile coverage. Using that certificate, they configured their own device to appear as trusted network equipment, enabling it to intercept communications from nearby mobile devices connected to the rogue station.
The Commission said the intercepted information included mobile phone numbers together with IMSI and IMEI identifiers. Investigators believe the attackers later combined that information with additional personal data and intercepted SMS and automated authentication codes used to approve mobile micropayments, ultimately enabling fraudulent transactions.
Rather than attributing the prolonged compromise to a single vulnerability, the regulator concluded that multiple security shortcomings made the intrusion possible. Among the issues identified were authentication certificates that remained valid for ten years, insufficient restrictions on network connections, and infrastructure that allowed attackers to communicate with KT’s systems without passing through normal management controls. Those weaknesses, according to the Commission, allowed the unauthorised access to continue undetected for approximately 11 months.
During the same investigation, regulators uncovered an unrelated compromise involving 38 servers in KT’s IT services environment. Those systems had been infected with BPFDoor, a stealthy backdoor previously linked by cybersecurity researchers to espionage campaigns targeting telecommunications operators and other critical infrastructure organisations. The PIPC alleges KT discovered the malware in March 2024 but chose not to report the incident to authorities.
Investigators also criticised KT’s handling of forensic evidence, stating that historical logs from some compromised servers were deleted during the company’s internal response. As a result, the Commission said it could not determine whether additional customer information had been accessed or stolen during the malware intrusion.
In addition to the financial penalty, the PIPC ordered KT to strengthen security controls protecting its telecommunications infrastructure, improve oversight of personal data protection, expand the scope of its Information Security Management System certification and give its Chief Privacy Officer a more substantive governance role. The Commission also said it intends to pursue legislative amendments that would impose tougher penalties on organisations that conceal incidents or destroy evidence during regulatory investigations.