Particle.news
Download on the App Store

KT Fined 53.9 Billion Won for Data Breach Through Illegal Femtocells

The regulator says attackers used stolen base‑station certificates to build rogue small cells that exposed thousands of subscribers and has ordered fixes plus criminal probes.

Overview

  • The Personal Information Protection Commission, which fined KT 53.9 billion won Thursday, found the breach exposed phone numbers and device IDs for 16,647 users.
  • Investigators concluded attackers recovered authentication certificates from lost KT femtocells and used them to create illegal small‑cell base stations that impersonated the network and captured subscriber identifiers.
  • Malicious actors used the stolen identifiers and intercepted authentication codes to make unauthorized mobile payments that cost 368 victims about 240 million won in total.
  • The regulator said it discovered a March 2025 server infection with malware including BPFDoor and found signs that KT deleted logs and failed to report the incident, so it referred the company to police and asked authorities to probe LG Uplus for possible evidence disposal.
  • KT accepted the ruling, apologized, pledged to rebuild its personal information protections and expand security investment, and said it will review the decision before deciding on legal action while regulators impose corrective orders that could prompt tighter telecom oversight.