South Korea's Personal Information Protection Commission (PIPC) has fined telecommunications giant KT Corporation KRW 53.979 billion ($39 million) over data protection violations.
The penalty was imposed for an internal network compromise that persisted for nearly 11 months, between October 8, 2024 and September 5, 2025.
PIPC launched an investigation into a potential data breach on September 10, 2025, following user reports of fraudulent micropayments. A day later, the company filed its initial data breach notification, reporting that data of roughly 5,500 customers had been exposed.
The government agency's investigation determined that the incident exposed the personal information of 16,647 KT subscribers and caused fraudulent mobile payments of KRW 240 million ($167,400) for at least 368 of them.
KT Corporation is South Korea's largest telecommunications operator, providing mobile and fixed-line communications, broadband internet, IPTV, cloud, data center, and enterprise IT services.
The company, which employs 23,300 people, serves over 13.5 million mobile subscribers, 90% of the country’s fixed-line subscribers, and 45% of high-speed internet users.
Rogue mobile station
The point of breach was a lost KT cellular base station called a femtocell, which contained a valid authentication certificate.
The attackers retrieved this certificate and installed it on a self-made device, which then appeared as a legitimate part of KT’s network, capturing cellular traffic from nearby devices connecting to the rogue femtocell.
This allowed the hacker to intercept communications between users’ devices and KT’s core network, including mobile phone numbers, IMSI, and IMEI numbers.
Eventually, the attackers combined the intercepted data with additional personal information and captured SMS and ARS authentication codes used for mobile micro-payments.
PIPC notes that KT installed femtocells itself, fully owned the devices, and controlled network authentication and authorization.
The Commission alleges that KT’s security controls were inadequate because femtocell certificates remained valid for 10 years, connections weren’t restricted by source IP addresses, and a route existed that bypassed the femtocell management server.
These weaknesses allowed the hackers to remain connected to KT’s network and collect sensitive client data for 11 months, without being detected.
BFDoor malware infection
During the investigation, PIPC also discovered that 38 KT IT service network servers had been compromised by malware, including BPFDoor, in March 2024.
BPFDoor is a stealthy Linux and Solaris backdoor publicly documented in 2022 that evaded detection for more than five years.
PwC later linked its use to the China-nexus Red Menshen espionage group that targeted telecommunications providers and organizations in other critical sectors.
The malware uses Berkeley Packet Filter (BPF) technology to passively monitor network traffic, allowing attackers to activate the malware with specially crafted "magic" packets without opening listening ports, effectively bypassing firewall protections and enabling covert remote shell access.
The Commission alleges that KT knew about the malware infection since March 2024, but failed to report it to the authorities, and handled the incident internally with no transparency towards its customers.
Later, the firm even deleted logs from some compromised servers while conducting malware inspection, following a malware breach on another telecom firm, LG U+.
LG U+ followed a similar evidence-wiping approach, reinstalling the operating system OS and disposing of servers before the investigators could determine the full impact of the breach.
Due to KT wiping those historical network logs, the Commission says it could not determine whether additional customer data had been stolen.
As part of the enforcement action, PIPC ordered KT to strengthen security controls for femtocells and other telecommunications equipment, reinforce governance over personal information protection, ensure its Chief Privacy Officer plays a substantive role in oversight, and expand ISMS-P certification to cover its mobile network systems.
The Commission also announced plans to pursue legislative changes that would introduce stronger penalties for companies that conceal or destroy evidence before or during investigations.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Get the whitepaper