KT Corp fined $37.4 million over data breach via illegal base stations
Synopsis
Key Takeaways
South Korea's privacy regulator has fined wireless carrier KT Corp. 53.9 billion won ($37.4 million) over a significant data breach that compromised the personal information of more than 16,000 subscribers through unauthorised mobile base stations. The Personal Information Protection Commission (PIPC) announced the penalty on Thursday, 30 July, along with a directive ordering the company to implement corrective security measures.
What the Breach Involved
According to the regulator, the breach exposed the phone numbers and mobile device identification numbers of 16,647 users. Malicious actors exploited this data to carry out unauthorised transactions, resulting in financial losses of 240 million won in total across 368 victims.
The PIPC said hackers accessed KT's wireless network undetected between 8 October 2024 and 5 September 2025 — a period of nearly eleven months. Critically, the company only became aware of the intrusion after receiving a complaint from a user, not through its own monitoring systems.
The Role of Femtocells
At the centre of the breach were femtocells — small, low-power cellular base stations typically deployed in homes or small businesses. KT Corp. CEO Kim Young-shub acknowledged during a parliamentary hearing that the company had mismanaged these micro base stations. 'After the incident, we reviewed the management of femtocells and found numerous vulnerabilities and poor management,' Kim said. 'We have since taken measures to prevent illegal femtocells from connecting to the network.'
Kim noted that KT outsources the installation and management of femtocells to third parties. According to the company, unregistered femtocells connected to its network around late August and gained access to private data belonging to 362 users, with damages estimated at 240 million won ($173,000).
Regulatory Action and Security Orders
Beyond the monetary penalty, the PIPC has ordered KT to strengthen security protocols for its wireless network equipment and personal information protection systems. The fine is among the more substantial penalties levied on a South Korean telecom company under the country's data protection framework.
Notably, lawmakers at the parliamentary hearing pointed out that KT's internal investigation had been narrowly focused on breaches involving the automated response system (ARS). In response, CEO Kim said the company is now expanding its analysis to cover all authentication data — a broader probe that may yet surface additional exposure.
What Happens Next
KT has been directed to overhaul its network equipment security and tighten oversight of third-party femtocell operators. The expanded internal audit could determine whether the confirmed breach figures represent the full scope of the incident or merely its visible surface. Regulators and lawmakers are expected to monitor compliance with the corrective orders closely.