KT Corp fined $37.4 million over data breach via illegal base stations

Share:
Audio Loading voice…
KT Corp fined $37.4 million over data breach via illegal base stations

Synopsis

South Korea's privacy regulator slapped KT Corp. with a $37.4 million fine after hackers used illegal femtocells to silently access its wireless network for nearly eleven months — and the company only found out because a customer complained. With 16,647 users exposed and 368 victims suffering financial losses, the breach raises sharp questions about telecom outsourcing and third-party security oversight.

Key Takeaways

KT Corp. fined 53.9 billion won ($37.4 million) by South Korea's Personal Information Protection Commission on 30 July .
The breach exposed phone numbers and device IDs of 16,647 users via unauthorised femtocells connected to KT's network.
Hackers operated undetected from 8 October 2024 to 5 September 2025 ; the company discovered the breach only after a user complaint.
368 victims suffered combined financial losses of 240 million won through unauthorised transactions.
CEO Kim Young-shub admitted 'numerous vulnerabilities and poor management' of femtocells, which KT outsources to third parties.
KT has been ordered to strengthen network equipment security and is expanding its internal audit to all authentication data.

South Korea's privacy regulator has fined wireless carrier KT Corp. 53.9 billion won ($37.4 million) over a significant data breach that compromised the personal information of more than 16,000 subscribers through unauthorised mobile base stations. The Personal Information Protection Commission (PIPC) announced the penalty on Thursday, 30 July, along with a directive ordering the company to implement corrective security measures.

What the Breach Involved

According to the regulator, the breach exposed the phone numbers and mobile device identification numbers of 16,647 users. Malicious actors exploited this data to carry out unauthorised transactions, resulting in financial losses of 240 million won in total across 368 victims.

The PIPC said hackers accessed KT's wireless network undetected between 8 October 2024 and 5 September 2025 — a period of nearly eleven months. Critically, the company only became aware of the intrusion after receiving a complaint from a user, not through its own monitoring systems.

The Role of Femtocells

At the centre of the breach were femtocells — small, low-power cellular base stations typically deployed in homes or small businesses. KT Corp. CEO Kim Young-shub acknowledged during a parliamentary hearing that the company had mismanaged these micro base stations. 'After the incident, we reviewed the management of femtocells and found numerous vulnerabilities and poor management,' Kim said. 'We have since taken measures to prevent illegal femtocells from connecting to the network.'

Kim noted that KT outsources the installation and management of femtocells to third parties. According to the company, unregistered femtocells connected to its network around late August and gained access to private data belonging to 362 users, with damages estimated at 240 million won ($173,000).

Regulatory Action and Security Orders

Beyond the monetary penalty, the PIPC has ordered KT to strengthen security protocols for its wireless network equipment and personal information protection systems. The fine is among the more substantial penalties levied on a South Korean telecom company under the country's data protection framework.

Notably, lawmakers at the parliamentary hearing pointed out that KT's internal investigation had been narrowly focused on breaches involving the automated response system (ARS). In response, CEO Kim said the company is now expanding its analysis to cover all authentication data — a broader probe that may yet surface additional exposure.

What Happens Next

KT has been directed to overhaul its network equipment security and tighten oversight of third-party femtocell operators. The expanded internal audit could determine whether the confirmed breach figures represent the full scope of the incident or merely its visible surface. Regulators and lawmakers are expected to monitor compliance with the corrective orders closely.

Point of View

Yet it was KT's customers — and ultimately KT's balance sheet — that bore the consequences. The eleven-month detection gap is the most damning detail: a carrier of KT's scale going nearly a year without spotting network intrusion points to systemic monitoring failure, not a one-off lapse. South Korea's data protection framework has grown more assertive, but the real test is whether corrective orders translate into structural change or merely a compliance checklist. The expanded audit into all authentication data is the right move — but it should have been the starting point, not a concession extracted by lawmakers.
NationPress
30 Jul 2026

Frequently Asked Questions

Why was KT Corp. fined $37.4 million?
South Korea's Personal Information Protection Commission fined KT Corp. 53.9 billion won ($37.4 million) for a data breach in which hackers accessed its wireless network through unauthorised femtocell base stations, exposing personal data of 16,647 users and enabling financial fraud against 368 victims.
What is a femtocell and how was it exploited?
A femtocell is a small, low-power cellular base station typically used in homes or small businesses. In this case, unregistered femtocells were connected to KT's network, giving hackers access to subscribers' phone numbers and device identification numbers, which were then used for unauthorised transactions.
How long did the breach go undetected?
According to the regulator, hackers accessed KT's network undetected between 8 October 2024 and 5 September 2025 — nearly eleven months. The company became aware of the breach only after a customer filed a complaint, not through its own security monitoring.
What corrective measures has KT been ordered to take?
The Personal Information Protection Commission has ordered KT to strengthen security protocols for its wireless network equipment and personal information protection systems. The company is also expanding its internal audit to cover all authentication data, beyond the automated response system initially investigated.
Who was affected and what were the financial losses?
The breach compromised data belonging to 16,647 users. Of these, 368 victims suffered financial losses totalling 240 million won through unauthorised transactions carried out using their stolen information.
Nation Press
The Trail

Connected Dots

Tracing the thread behind this story — newest first.

8 Dots
  1. Latest 1 month ago
  2. 6 months ago
  3. 7 months ago
  4. 8 months ago
  5. 8 months ago
  6. 10 months ago
  7. 10 months ago
  8. 1 year ago
Google Prefer NP
On Google