| Title | The PIPC Sanctions KT Corporation for Data Breaches | ||
|---|---|---|---|
| Department | Date | 2026.08.07 | |
| Attachment | press release The PIPC Sanctions KT for Data Breaches.pdf | ||
| Page URL | https://www.pipc.go.kr/eng/user/ltn/new/noticeDetail.do?bbsId=BBSMSTR_000000000001&nttId=3133 | ||
| Contents |
Press Release The PIPC Sanctions KT Corporation for Data Breaches
July 30, 2026 (This is an unofficial translation of a press release, originally prepared in Korean.)
The Personal Information Protection Commission (PIPC) held its 15th plenary meeting of 2026 and resolved to impose administrative sanctions on KT Corporation (KT) for violations of the Personal Information Protection Act (PIPA) on June 29, 2026. The sanctions imposed on KT are as follows:
● Administrative fine: KRW 53.979 billion ● Correction order ● Recommendation for improvement ● Publication order
Meanwhile, the PIPC also resolved to accuse KT of obstructing its investigations and refer LG Uplus Corp. (LG U+) to an investigative authority for tampering with evidence, including decommissioning affected servers before the investigation.
The following explains the details of KT’s data breach.
KT’s Data Leaks Caused by Rogue Femtocells
The PIPC preemptively launched investigations due to potential data breaches following reports of fraudulent mobile payment transactions and subsequent media coverage on September 10, 2025. In September 2025, KT reported a data breach of 5,560 users. During the course of the investigation, the company identified additional data leaks and reported them on September 18 and October 17, 2025.
The investigation results showed that hackers extracted authentication credentials from KT’s femtocells and inserted them into their rogue femtocells. They used this scheme to access KT’s telecommunications network. Then, they caused users’ mobile phones to connect to rogue femtocells, enabling them to intercept incoming and outgoing information between users’ devices and KT’s internal network. They combined the intercepted information with users’ personal information, including names, gender, and birthdates, and used it to initiate fraudulent mobile payment transactions by intercepting payment authentication codes transmitted through voice calls or text messages. *A femtocell is a small cellular base station designed for use in homes, businesses, or places where the signal to the main network cells is weak. It is a signal booster for improved coverage and signal strength.
As a result of the hacks, personal information of 16,647 subscribers (including budget carrier users, deduplicated) was leaked. The leaked data includes:
● Mobile phone numbers ● International mobile subscriber identity (IMSI) ● International mobile equipment identity (IMEI)
Among the affected users, 368 subscribers suffered fraudulent mobile payment transactions totaling approximately KRW 240 million.
Unlike many previous data breaches, this incident resulted in unauthorized mobile payment transactions using the leaked personal information through rogue femtocells.
Femtocell Ownership and Control
KT started introducing and operating femtocells to improve network coverage and strengthen signal, targeting its Internet subscribers. The femtocells are the company’s assets and are installed directly by the company’s personnel.
Femtocells’ wireless network access approval, authentication system management, internal network access approval, security controls, and operations are done by KT. Subscribers merely provide the physical places to install and operate them.
Accordingly, the PIPC concluded that KT owns and operates the femtocells from a technical and operational standpoint. The authentication process through which femtocells connect to KT’s telecommunications network, and the management of personal information transmitted during the process, therefore fall under KT’s responsibility.
KT’s Violations of the PIPA
The PIPC’s investigations into KT’s data processing practices and operational management found that the data breach resulted from the company’s failure to implement baseline access controls on its internal networks while managing and operating femtocells.
To provide telecommunications services, KT’s home subscriber server (HSS), a personal data processing system in the company’s internal network, transfers user terminal and personal information to authenticate subscribers and devices and connect voice and text message services. During this process, areas with weak network coverage should go through femtocells. Accordingly, KT is required to strictly control and manage femtocells to ensure authorized access only.
However, KT’s femtocell management system was not robust enough to prevent rogue femtocells from accessing the internal network at the time of the incident. KT configured the femtocell validity period to 10 years and failed to restrict access based on IP addresses, allowing unauthorized connections from other mobile carriers and overseas IP addresses.
Furthermore, the PIPC found that there are network routes that bypassed the femtocell management servers, and KT failed to properly manage Cell IDs, identifiers assigned when femtocells connect to the core network. As a result, the company’s anomaly detection and response system was left unattended.
KT’s security failures resulted in unauthorized access to KT’s internal network for nearly a year (From October 8, 2024, to September 5, 2025) by duplicating the authentication credentials of lost KT-owned femtocells. KT became aware of access anomalies after receiving several complaints about fraudulent mobile payments and other resulting harm.
Based on these findings, the PIPC concluded that KT failed to implement safeguards to prevent illegal or unauthorized access and data breaches as required by the PIPA.
Administrative Sanctions
The PIPC imposed an administrative fine of KRW 53.979 billion on KT for failing to implement appropriate safeguards required for mobile carriers and issued an order to publish the sanction results on the company’s website.
In addition, the PIPC issued correction orders requiring KT to:
● Strengthen security safeguards by addressing identified security vulnerabilities and reinforcing access controls to prevent unauthorized access to personal information in its communications network ● Overhaul its privacy governance framework, including clarifying the roles and responsibilities of its Chief Privacy Officer (CPO) in overseeing company-wide personal data processing practices
Moreover, the PIPC issued recommendations on KT to further strengthen its personal information protection framework by expanding the scope of its Information Security Management System-Personal Information Protection (ISMS-P) certification, which currently covers some of its IT services, to include telecommunication network systems.
KT’s Malware-Infected Servers and LG U+’s Data Breach
KT’s Malware-Infected Servers
The PIPC found that 38 servers within KT’s IT service network were infected with multiple types of malware, including Berkeley Packet Filter (BPF) Door malware—a Linux backdoor that bypasses firewalls and security systems. As the malware infections could have been associated with potential data breaches, the PIPC expanded the scope of its investigation on November 6, 2025.
Meanwhile, the Ministry of Science and ICT’s Joint Public-Private Investigation Group announced that 41 servers were infected, but 3 of them were located on a different network and were not classified as personal data processing systems.
The investigation found that hackers exploited security vulnerabilities of KT’s roaming and rental service website to gain access to its network. They installed malware on the network, infecting multiple servers. They also carried out Structured Query Language (SQL) injection attacks to access and exfiltrate personal information, including names, phone numbers, and accounts, of some KT employees and partner companies.
However, the PIPC was unable to identify what happened in the personal data processing systems on 38 infected servers because relevant network logs were unavailable at the time of the investigation.
KT became aware of its server infections in March 2024, but failed to report the incident to the competent authority. Instead, the company took measures without conducting analysis to identify whether data breaches took place between March 2024 and July 2024.
During a thorough review of whether KT’s servers were infected with malware during another mobile carrier’s data breach investigation in April 2025, KT deleted logs from 10 servers, thereby concealing the incident.
The company also misled the PIPC during a breach investigation that it had no data about infected servers. However, through digital forensics, the PIPC found that the company deleted logs associated with infected servers before the investigation. The company impeded the investigation by going back on its statement and submitting separately retained logs after the due date.
LG U+’s Data Breach
The PIPC began investigating LG U+’s data breach after Phrack, a U.S.-based hacking magazine, reported on September 10, 2025, that hackers stole personal information.
During its investigation, the PIPC examined whether text files containing the names and account information of LG U+ employees and partner company personnel were leaked. The investigation found that the leaked data was retained and managed by LG U+’s automated process policy management (APPM) system.
LG U+ reinstalled operating systems of associated servers and decommissioned affected servers, including APPM servers, before the PIPC’s investigation. These actions impeded the PIPC’s efforts to identify the data breach and assess whether additional leaks occurred.
The PIPC’s Measures Against KT and LG U+
The PIPC decided to accuse KT of impeding official investigations, including:
● KT’s failure to report the malware infections and complacency in analyzing the incident in March 2024 ● Deleting some of the logs of affected servers ● Providing false data and going back on its initial statement
The PIPC also decided to refer LG U+ to an investigative authority for disrupting the PIPC’s investigation into potential data breaches.
The PIPC’s Plans to Improve its Enforcement Framework
The PIPC is pushing to improve its enforcement framework to respond effectively to attempts to conceal data breaches or obstruct investigations through evidence tampering, as demonstrated by KT and LG U+.
Under the current legal framework, the PIPC may seek criminal punishment or impose fines for evidence tampering during an investigation. However, the legal framework lacks provisions to regulate such malpractices before an investigation launches, creating a loophole that may allow organizations to conceal or destroy evidence.
To minimize further harm by ensuring breach notifications without undue delay, the PIPC pushes for taking enhanced measures, including:
● Enacting provisions for criminal punishment for evidence tampering before an investigation begins ● Imposing administrative fines for evidence tampering (concealment or destruction) ● Introducing a whistleblower reward program for reporting evidence tampering
At the same time, the PIPC will make amendments to the PIPA to prevent delays caused by inaction and non-cooperation during investigations by introducing:
● Imposing enforcement fines for inaction or failure to comply with correction orders ● Issuing orders to preserve evidence when an incident takes place
Key Takeaways
Through administrative sanctions imposed on KT, the PIPC reaffirmed that:
● Organizations should be held accountable for data breaches through sanctions proportionate to their violations; and ● Layered privacy protections are essential to safeguarding the personal information of the Korean people.
At the same time, data controllers should remain vigilant in preventing data breaches, noting that such incidents can affect people’s daily lives, including financial loss and other harm.
PIPC Chairperson Kyung Hee Song said, “The PIPC’s administrative sanctions on KT should serve as an opportunity for all mobile carriers providing services essential to everyday life to further strengthen their security capabilities.” She also highlighted that “The PIPC will continue improving its enforcement framework to encourage organizations to recognize that transparency is the best course of action following a data breach, while imposing stricter sanctions against tampering with evidence.”
* A PDF file, formatted for better readability, is attached.
|
||