Lim Jeong-gyu (임정규), director general for information security network policy at the Ministry of Science and ICT, announces the findings of the joint public-private investigation team into Tving’s breach on Sept. 3 at the Government Complex Seoul. [Photo: Yonhap News Agency]

Behind the cyber breaches that have rocked South Korea’s telecommunications and broadcasting industry over the past 500 days was the work of a joint public-private investigation team. The team identified security gaps across incidents ranging from SK Telecom’s USIM hacking case to KT and LG Uplus, and a recent Tving account leak.

The joint public-private investigation team is a temporary body formed under the Information and Communications Network Act when a serious breach occurs. The team was formed six times from 2014 to 2023. Since April last year, it has rapidly expanded its work as major breaches occurred in succession. Targets included key infrastructure across telecommunications and broadcasting platforms, such as mobile core networks and USIM information, illegal base stations, corporate servers, and OTT databases and development environments.

SKT server sweep, KT illegal femtocell trace... broad probe of telecom industry

The trigger for heightened attention to the team’s work was SKT’s USIM hacking incident in April last year. The team checked 42,605 servers operated by SKT for malware infections. It found 33 types of malware, including BPFDoor, on 28 servers. A total of 25 types of USIM information, including phone numbers and International Mobile Subscriber Identity (IMSI), totalling 9.82 gigabytes, leaked externally. Based on IMSI, the leak amounted to about 26.96 million cases.

The probe went beyond identifying the hacking methods and the scale of damage. It also found weaknesses in SKT’s internal information security system, including the management of server account information and critical data. The investigation also revealed that SKT had already found malware on some servers in 2022 but did not report it to the government as a breach incident and took its own measures. As multiple grounds for responsibility emerged, SKT also waived cancellation fees for users who terminated service out of concern over follow-on damage after the hack.

Just a few months later, the team’s focus returned to another telecom company. In September last year, an unauthorised small-payment incident involving KT subscribers became known. The incident began when an illegal small base station, known as a femtocell, that was not registered with the company accessed its internal network.

The Ministry of Science and ICT ordered KT to preserve relevant materials and formed an investigation team. The team analysed an illegal femtocell secured by police and inspected about 33,000 servers held by KT in six rounds. It found that the IMSI, International Mobile Equipment Identity (IMEI) and phone numbers of 22,227 users who connected to the illegal femtocell were leaked. It also confirmed that 368 people suffered unauthorised small-payment losses totalling about 243 million won.

The investigation found poor femtocell authentication and internal network access management, as well as weaknesses in company-wide asset management, supply chain security and log management. The probe also revealed that KT had found web shells and BPFDoor during its own checks but did not report them to the government. Like SKT, KT also waived cancellation fees for customers who left for other carriers.

LG Uplus, however, remained a case in which the team failed to determine the full circumstances. In August last year, a U.S. security magazine, Phrack, raised indications of an internal information leak at LG Uplus. But LG Uplus reinstalled or discarded the operating system of an integrated server access control solution (APPM) server related to the incident in August and September, before the investigation began, making it impossible to determine the exact intrusion route and the scope of damage. The matter is currently under police investigation.

Outside telecommunications, the team was also deployed to a Coupang breach incident. The most recent target was OTT platform Tving. Tving said a hack led to the leak of information for a total of 39.54 million accounts: 22.06 million active accounts, 17.37 million inactive accounts including dormant and withdrawn accounts, and 110,000 test accounts. The team found the cause and scope of the incident, including that the attacker stole a developer access key to penetrate Tving’s internal systems and exfiltrated development projects externally.

The probe found a lax security system. Tving did not manage access keys systematically and had no monitoring system to detect abnormal activity. Its information security staff numbered only around 4, and log management was inadequate. Vulnerabilities identified in a 2024 penetration test were also found to have gone unaddressed.

Repeated 'basic security' gaps... beyond investigations to institutional improvements

Over the past 500 days, the attack methods the team encountered differed each time. At SKT, malware penetrated as far as core communications servers. At KT, an illegal femtocell became the starting point of the incident. At Tving, a single developer access key became the starting point for a chain hack that led to internal system intrusion and account theft.

But the findings also had many common elements. Problems repeatedly surfaced in so-called basic security, including the management of accounts and authentication information, log retention, detection of anomalous signs, and server and network asset management. At SKT and KT, the probe found that they identified signs of past malware infections but did not report them. Tving reported the breach after the legally required deadline despite recognising it. At LG Uplus, concerns emerged over evidence preservation after servers needed for the investigation were reinstalled or discarded.

A security industry official said, "Even if the types of incidents differ, problems are recurring in basic areas such as account management, log retention and detection of abnormal signs." The official added, "There is a need to examine not only technical attack paths but also internal security operations systems together."

The team’s work has become a seed for legal and institutional improvements. The government is pushing to strengthen sanctions for serious and repeated violations, expand investment in information security and conduct pre-emptive incident investigations. It is also working to improve the Information Security Management System (ISMS and ISMS-P) certification system and strengthen the reporting and remediation system for security vulnerabilities.

Keyword

#SK Telecom #KT #LG Uplus #Tving #Ministry of Science and ICT
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.