South Korean Telco Giant KT Fined $39M Over Data Breach and Cover-Up
South Korea's largest telecommunications provider, **KT Corporation**, has been hit with a hefty KRW 53.979 billion ($39 million) fine by the **Personal Information Protection Commission (PIPC)**. The penalty stems from severe data protection violations, including an 11-month internal network compromise and the alleged concealment and deletion of evidence related to a **BPFDoor** malware infection.
The **PIPC** launched its investigation on September 10, 2025, following user reports of fraudulent micropayments. A day later, **KT Corporation** submitted an initial data breach notification, claiming only 5,500 customers were affected.
However, the government agency's findings painted a much graver picture, determining that the incident exposed the personal information of 16,647 **KT** subscribers. This breach directly led to KRW 240 million ($167,400) in fraudulent mobile payments for at least 368 individuals.
**KT Corporation** is a dominant force in South Korea's telecommunications landscape, serving over 13.5 million mobile subscribers and a significant portion of the country's fixed-line and high-speed internet users.
### Rogue Mobile Station Exploited
The initial point of compromise was identified as a lost **KT** cellular base station, known as a femtocell, which contained a valid authentication certificate. Attackers successfully retrieved this certificate and installed it on a self-made device, allowing it to masquerade as a legitimate part of **KT**'s network.
This rogue femtocell captured cellular traffic from nearby devices, enabling the interception of critical communications between users' devices and **KT**'s core network. Information such as mobile phone numbers, **IMSI** (International Mobile Subscriber Identity), and **IMEI** (International Mobile Equipment Identity) numbers were compromised.
Further exploitation involved combining this intercepted data with additional personal information, along with captured SMS and **ARS** (Audio Response System) authentication codes, to facilitate fraudulent mobile micro-payments.
**PIPC** highlighted several critical security inadequacies on **KT**'s part. Femtocell certificates remained valid for an excessive 10 years, connections lacked source IP address restrictions, and a route existed that bypassed the femtocell management server. These vulnerabilities allowed the attackers to maintain an undetected connection to **KT**'s network and collect sensitive client data for nearly a year.
### **BPFDoor** Malware Infection and Cover-Up Allegations
Compounding the issues, the **PIPC** investigation uncovered that 38 **KT** IT service network servers had been compromised by malware, including **BPFDoor**, in March 2024.
**BPFDoor** is a notoriously stealthy Linux and Solaris backdoor, publicly documented in 2022, which has historically evaded detection for over five years. **PwC** later linked its use to the China-nexus **Red Menshen** espionage group, known for targeting telecommunications providers and other critical sectors.
The malware leverages **Berkeley Packet Filter (BPF)** technology to passively monitor network traffic. This allows attackers to activate the malware using specially crafted "magic" packets, bypassing firewall protections by not opening traditional listening ports and enabling covert remote shell access.
**PIPC** alleges that **KT** was aware of this malware infection since March 2024 but failed to report it to authorities. Instead, the company reportedly handled the incident internally with a lack of transparency towards its customers.
Furthermore, during a malware inspection prompted by a breach at another telecom firm, **LG U+**, **KT** allegedly deleted logs from some compromised servers. **LG U+** reportedly adopted a similar evidence-wiping approach, reinstalling operating systems and disposing of servers before investigators could fully assess the breach's impact. The deletion of these historical network logs by **KT** prevented the Commission from determining whether additional customer data had been stolen.
As part of its enforcement action, **PIPC** has ordered **KT** to significantly strengthen security controls for femtocells and other telecommunications equipment, reinforce governance over personal information protection, and ensure its Chief Privacy Officer plays a substantial oversight role. The company must also expand its **ISMS-P** certification to cover its mobile network systems.
Looking ahead, the Commission has announced plans to pursue legislative changes that would introduce stronger penalties for companies that conceal or destroy evidence before or during investigations, signaling a stricter regulatory environment for data protection in South Korea.