In a significant cybersecurity incident, South Korea’s largest telecommunications provider, KT (formerly Korea Telecom), has faced a substantial fine imposed by the country’s Personal Information Protection Commission (PIPC) due to severe security failures that facilitated a breach impacting numerous customers. With over 13 million mobile subscribers, KT dominates the local market, accounting for a significant share of high-speed internet users as well. However, a recent investigation, initiated by the PIPC in September 2025, uncovered troubling reports of customers falling victim to fraudulent micropayments.
The investigation was sparked when KT notified the PIPC about a compromise involving personally identifiable information (PII). This alarm began ringing the moment several KT customers reported unauthorized micropayments on their mobile accounts. The PIPC subsequently traced the fraud to the theft of a femtocell—a compact cellular base station typically utilized in residential or small business settings.
According to the PIPC’s detailed findings, the hacker gained unauthorized access to KT’s network by exploiting a certificate obtained from a misplaced femtocell. The cybercriminal crafted a makeshift femtocell and was able to infiltrate the KT mobile network. This unauthorized access permitted the hacker to reroute user terminals through the counterfeit femtocell to intercept data transmissions between user devices and KT’s internal systems. By collating this intercepted data with additional personal information—such as names, gender, and birth dates—the malicious actor requested micropayments, fraudulently stealing SMS messages and authentication codes in the process.
The scale of the breach was alarming, with the PIPC reporting that sensitive information belonging to 16,647 users had been compromised. Financially, about 368 customers were defrauded, amounting to a loss of approximately 240 million won (around $175,000) through these unauthorized micropayments.
The PIPC’s ruling highlighted fundamental failures in KT’s security protocols, particularly pointing out that the firm lacked essential access control management for its internal network. This oversight allowed the hacker to seamlessly connect their unauthorized femtocell to KT’s infrastructure. The investigation revealed that KT’s femtocell management system was grossly insufficient, allowing unidentified femtocells to easily infiltrate the internal network. The commission noted that KT had set a prolonged validity period of 10 years for femtocell certificates intended for network access, failing to restrict IP addresses effectively. This lack of restriction enabled potential access not just from KT’s legitimate devices but also from foreign entities or other companies.
Moreover, the PIPC identified another grave security inadequacy: individuals were able to bypass the femtocell management server altogether. This lapse in security detection and response capabilities resulted in the breach remaining unnoticed for an extended period of 11 months. In light of these incidents, the PIPC compelled KT to enhance its security measures. Recommendations included conducting vulnerability assessments on wireless communication equipment and bolstering overall governance processes.
Additionally, the situation deteriorated further when investigators discovered evidence of malware infection across 38 internal servers within KT. Among the malicious software identified was the BPFDoor backdoor, which allowed unauthorized access to KT’s systems. According to the PIPC, a hacker capitalized on vulnerabilities present on the KT Roaming Rental Service website in March 2024. This breach resulted in the upload of malicious code onto KT’s servers, potentially allowing access to sensitive personal information belonging to KT employees and affiliates, further exacerbating the situation.
Despite these breaches, KT initially opted not to report the incidents to the relevant government authorities. The firm’s decision to handle the crisis internally raised further concerns, especially since they did not conduct a comprehensive analysis to assess whether personal information had been leaked. Consequently, the PIPC has lodged a complaint against KT regarding this lack of transparency, noting points such as the deletion of server logs, submission of misleading information, and retraction of statements during the inquiry.
As South Korea continues to grapple with the implications of this incident, the case underscores the critical need for robust security measures in the telecommunications sector. It serves as a cautionary tale for organizations worldwide, exemplifying the potential consequences of neglecting data protection protocols and the imperative for vigilance against cyber threats. The ongoing fallout from this situation will likely provoke dialogue on regulatory compliance and prioritizing customer data protection in the ever-evolving digital landscape.

