< Back to all clusters
[BUSINESS] · South Korea · 11 sources

started · updated

KT Corp fined 540 billion won for data breach via illegal femtocells

South Korea’s Personal Information Protection Commission imposed a fine of roughly 539.8 billion won (about $37‑38 million) on telecom operator KT Corp for a large‑scale personal data breach. Hackers exploited unsecured femtocell base stations to access the network from October 2024 to September 2025, leaking phone numbers, IMSI and IMEI data of 16,647 subscribers. The stolen information was used in unauthorized mobile‑payment transactions that harmed 368 users, causing losses of about 240 million won.

The regulator also cited KT’s failure to report a March 2025 malware infection, obstruction of the investigation, and the deletion of server logs. It ordered KT to strengthen security of its wireless‑network equipment, expand its personal‑information‑protection management system, and comply with corrective measures. The commission referred KT for criminal investigation and similarly referred LG U+ for alleged evidence tampering.

The fine is lower than the 1.348 trillion won penalty previously levied on SK Telecom for a similar breach, reflecting the regulator’s new policy that allows fines up to 10 % of a company’s annual revenue for serious privacy violations.

Entities

Coupang · KT Corp · KT Corp. · LG Uplus Corp · Personal Information Protection Commission · SK Telecom · South Korea · femtocell base stations

Claims

What the coverage asserts, and how many sources carry each claim.