A KT dealership in Seoul. [Photo: Yonhap]

[Digital Today reporter Jin-ho Lee (이진호)] The government is set to soon disclose the level of sanctions over KT’s hacking incident involving unauthorized small-amount payments. The number of people whose personal information was leaked is smaller than in SK Telecom’s SIM information leak, but the case involved financial damage and problems in the response process such as delayed reporting, raising expectations of disputes over how the fine will be calculated.

The Personal Information Protection Commission will hold a plenary meeting on Tuesday afternoon to deliberate a sanctions proposal that includes whether KT violated the Personal Information Protection Act, along with administrative fines, penalties and corrective orders.

The industry views the key issue as how much the fine will reflect the scale of the leak, actual damage and the extent of KT’s violation of its duty to take safety measures. As the decision could affect KT’s future investment stance, the industry is watching closely.

If the legal cap is applied, it would near 200 billion won... Scope of 'related revenue' is a variable

Under the current Personal Information Protection Act, authorities can impose an administrative fine of up to 3 percent of revenue related to the violation. In actual calculations, revenue unrelated to the violation is excluded from total revenue. KT’s average wireless service revenue over the past three years is about 6.5 trillion won. If 3 percent, the statutory cap, is applied mechanically, the maximum fine would reach about 195 billion won.

The 3 percent is only a legal ceiling. The first issue is how broadly the commission will recognise KT revenue as "related to the violation". If it treats the mobile network that formed the basis of the incident and the entire wireless service business as a related business, the base for the fine grows. If it narrowly judges relatedness around subscribers confirmed to have connected to illegal femtocells, or the services and period in which the incident occurred, the base revenue could shrink.

KT is stressing that, unlike SKT’s case in which the entire subscriber server was attacked, this was a localised incident in which illegal femtocells stole information in some areas. A prior notice the commission sent to KT is reported to have specified the number of people whose personal information was leaked at about 16,000, excluding corporate lines and duplicate lines.

Earlier, in relation to the SKT incident, the commission judged that 25 types of information were leaked, including mobile phone numbers, International Mobile Subscriber Identity (IMSI) numbers and SIM authentication keys of about 23.24 million users, and imposed an administrative fine of 134.791 billion won. It concluded that safety measures for key mobile telecommunications systems were broadly inadequate, including firewall settings, server account management, encryption and malware prevention.

By leaked headcount alone, the scale of KT’s incident is less than 1/1,000 of SKT’s. KT could seek a lower assessment rate and mitigation, citing that the scope of damage and the types of leaked information were relatively limited. It argues that even if related revenue is set as the entire wireless service business, the ratio applied for the seriousness of the violation should not be viewed the same as SKT’s.

A strengthened new standard for calculating administrative fines is not applied retroactively to KT’s case. From May this year, the commission strengthened the system by using the larger of revenue from the previous year and average revenue over the most recent three business years as the basis for calculating fines, and restricting mitigation for "very serious violations". The commission decided to apply the previous standard to KT because the violation ended before the revised rules took effect.

Leak is smaller but financial damage materialised... Poor femtocell management also a negative

A disadvantage for KT is that the leak led to actual financial damage. Government investigation results showed the IMSI, International Mobile Equipment Identity (IMEI) and phone numbers of 22,227 users who connected to illegal femtocells were leaked. Of those, 368 people suffered losses of about 243 million won from 777 cases of unauthorised small-amount payments.

The attacker copied KT certificates and server IP information into illegal femtocells, accessed the internal network and then transmitted strong radio waves to connect users’ devices to the illegal equipment. The attacker then stole phone numbers and intercepted text messages sent to victims during gift certificate purchases, as well as interactive voice response authentication information, to carry out the payments. As it caused financial damage, the commission could rate the result of the violation as serious.

The femtocell management system is also being cited as a factor that could increase fines. Earlier, a public-private joint investigation team judged that because femtocells supplied to KT used the same manufacturer certificate, abnormal devices that copied the certificate could also access KT’s internal network. The certificate validity period was also set at 10 years, leaving devices that had accessed the network able to connect for a long period.

The fact that 103 types of malware, including BPFdoor, rootkits and backdoors, were found on 94 KT servers is also a variable. The joint investigation team judged that company-wide asset management, operation of security equipment and a supply chain security system were also inadequate.

The process of reporting the incident and responding to the government investigation is also a burden for KT. KT detected and blocked abnormal communication patterns related to unauthorised small-amount payments on Sept. 5, 2025, but reported the incident to authorities only on the afternoon of Sept. 8, after identifying the illegal femtocell ID. The government judged that it violated the duty to report within 24 hours of recognising a cybersecurity incident. It also submitted different information to the government on the actual disposal timing of servers infected with malware in the past and later reported the existence of backup logs.

Such reporting delays and problems responding to the investigation could serve as material for judging whether KT’s internal information protection governance functioned properly, separate from the incident itself. If the commission focuses its assessment on management and supervisory responsibility, the effect of mitigation could be limited.

Customer compensation, information security investment could also be mitigation cards

KT has compensated victims after the incident and implemented measures including free SIM replacement for all customers and waiving cancellation fees. It is also running a customer rewards programme from February to August this year. Efforts to prevent damage from spreading and compensate victims could be reviewed as grounds for mitigation in calculating the fine.

Expanded investment in information security is also expected to be used as supporting material. KT said it would create a chief information security officer (CISO) position, regularise security reporting to the board and expand dedicated staff, and invest 1 trillion won in information security over the next five years. It also included expanding a zero-trust framework, upgrading integrated security monitoring, strengthening access controls and encryption, and blocking and retrieving unused femtocells as recurrence-prevention measures. KT explained it invested 127.6 billion won in information security in 2025, maintaining annual investment of more than 100 billion won for four consecutive years.

Financially, the closer the fine comes to the legal ceiling, the heavier the burden becomes. KT’s 2025 operating profit on a separate basis was 1.305 trillion won and its consolidated operating profit was 2.4691 trillion won. If the fine nears 200 billion won, the system’s cap, it would amount to about 15 percent of last year’s separate operating profit and about 8 percent of consolidated operating profit.

As a one-off cost, it is not at a level to shake the company’s financial stability, but if combined with customer compensation, SIM replacement and five years of security investment, plus a fine, it could still weigh on profit and cash flow for the period.

Keyword

#KT #Personal Information Protection Commission #SK Telecom #IMSI #femtocell
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.