South Korea's Personal Information Protection Commission (PIPC) has imposed a fine of KRW 53.979 billion ($39 million) on KT Corporation, the country's largest telecommunications operator, for violating data protection laws. The penalty stems from an internal network compromise that persisted for nearly 11 months, between October 8, 2024, and September 5, 2025.
Investigation and Breach Details
The PIPC launched an investigation into a potential data breach on September 10, 2025, following user reports of fraudulent micropayments. A day later, KT Corporation filed its initial data breach notification, reporting that data of roughly 5,500 customers had been exposed. However, the government agency's investigation determined that the incident exposed the personal information of 16,647 KT subscribers and caused fraudulent mobile payments of KRW 240 million ($167,400) for at least 368 of them.
Rogue Mobile Station and Attack Vector
The point of breach was a lost KT cellular base station called a femtocell, which contained a valid authentication certificate. The attackers retrieved this certificate and installed it on a self-made device, which then appeared as a legitimate part of KT's network, capturing cellular traffic from nearby devices connecting to the rogue femtocell. This allowed the hacker to intercept communications between users' devices and KT's core network, including mobile phone numbers, IMSI, and IMEI numbers.
Eventually, the attackers combined the intercepted data with additional personal information and captured SMS and ARS authentication codes used for mobile micro-payments. The PIPC notes that KT installed femtocells itself, fully owned the devices, and controlled network authentication and authorization.
Security Controls and Malware Infection
The Commission alleges that KT's security controls were inadequate because femtocell certificates remained valid for 10 years, connections weren't restricted by source IP addresses, and a route existed that bypassed the femtocell management server. These weaknesses allowed the hackers to remain connected to KT's network and collect sensitive client data for 11 months, without being detected.
During the investigation, the PIPC also discovered that 38 KT IT service network servers had been compromised by malware, including BPFDoor, in March 2024. BPFDoor is a stealthy Linux and Solaris backdoor that evaded detection for more than five years. The malware uses Berkeley Packet Filter (BPF) technology to passively monitor network traffic, allowing attackers to activate the malware with specially crafted 'magic' packets without opening listening ports, effectively bypassing firewall protections and enabling covert remote shell access.
Consequences and Enforcement Action
The Commission alleges that KT knew about the malware infection since March 2024 but failed to report it to the authorities and handled the incident internally with no transparency towards its customers. Later, the firm even deleted logs from some compromised servers while conducting malware inspection, following a malware breach on another telecom firm, LG U+.
As part of the enforcement action, the PIPC ordered KT to strengthen security controls for femtocells and other telecommunications equipment, reinforce governance over personal information protection, ensure its Chief Privacy Officer plays a substantive role in oversight, and expand ISMS-P certification to cover its mobile network systems. The Commission also announced plans to pursue legislative changes that would introduce stronger penalties for companies that conceal or destroy evidence before or during investigations.
Test every layer before attackers do. Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Source: BleepingComputer