
South Korea’s Personal Information Protection Commission (PIPC) has fined KT Corporation — the country’s largest telecom — KRW 53.979 billion ($39 million) for a data breach that ran undetected for nearly 11 months, from October 2024 through September 2025. The breach exposed the personal data of 16,647 subscribers and led to fraudulent micropayments totalling KRW 240 million for at least 368 victims.
The attackers’ entry point was a lost femtocell — a small cellular base station — that still carried a valid KT authentication certificate. The attackers retrieved that certificate, installed it on a homemade device, and connected it to KT’s network as though it were a legitimate tower. From there, they intercepted mobile phone numbers, IMSI and IMEI identifiers, and the SMS authentication codes used to authorise mobile payments. Investigators found that KT’s security controls were dangerously weak: femtocell certificates remained valid for ten years, connections weren’t restricted by source IP, and a path existed that bypassed the femtocell management server entirely. Separately, PIPC found that 38 KT IT servers had been compromised by BPFDoor — a stealthy Linux backdoor linked to a China-nexus espionage group — since March 2024, more than 18 months before the breach was publicly disclosed. KT allegedly knew about the BPFDoor infection and handled it internally, then deleted server logs during cleanup rather than preserving them for investigators.
