South Korea's Personal Information Protection Commission imposed about 54 billion won in fines on KT over a personal data leak that led to unauthorised micropayment losses. It judged the occurrence of actual financial damage as a major factor, but also reflected the small scale of the leak and the limited types of data exposed.
The watchdog said on July 30 it had decided at its 15th plenary meeting on July 29 to impose a 53.979 billion won fine on KT for violating the Personal Information Protection Act. It also decided on corrective orders, recommendations for improvement and an order to disclose the sanction.
It decided to file a complaint with investigative authorities against KT over its failure to report a malware infection to the government and its submission of false materials during the probe. It also requested an investigation into LG Uplus over its reinstallation or disposal of server operating systems linked to suspected personal data leaks.
Financial damage judged major factor; leak scale split fine level
Under the current Personal Information Protection Act, if a violation of safety obligations is confirmed, authorities can impose a fine of up to 3 percent of total revenue. The fine is calculated based on related revenue excluding sales not tied to the violation, reflecting the severity of the breach, the scale of the leak, the extent of damage and corrective efforts. KT's average wireless service revenue over the past 3 years is about 6.5 trillion won. Applying the legal cap of 3 percent would yield a fine of about 195 billion won.
The watchdog included LTE and 5G mobile service revenue as related revenue in calculating the fine. It considered that the femtocell used in the incident was an LTE device, but 5G services in some areas also use the LTE network. It excluded revenue not directly related to the incident, such as IPTV and high-speed internet.
The watchdog stressed it viewed it seriously that leaked data was used for unauthorised micropayments, causing secondary damage. It also considered that the leak involved 16,647 people, relatively smaller than a previous SKT case, and that the leaked data was limited to three types including mobile phone numbers, International Mobile Subscriber Identity (IMSI) and International Mobile Equipment Identity (IMEI).
It also reflected that compensation and corrective measures were carried out quickly, setting the fine at 53.979 billion won, below initial market expectations. The watchdog said it would disclose specific related revenue and the applied rate after the written decision is finalised.
Lax management of illegal femtocells; bypass access route existed
A public-private joint investigation team had previously announced that 22,227 instances of personal data leakage had occurred. The watchdog said it selected the actual number of data subjects after excluding duplicates such as corporate accounts and multiple lines among the leaked information.
The watchdog cited KT's overall poor management of femtocells as the cause of the incident. KT set the validity period of femtocell certificates used for internal network access at 10 years. It also did not restrict femtocell access IP addresses, allowing access to KT's internal network through other companies' internet networks or overseas IPs. A route also existed to access the internal network by bypassing the femtocell management server. KT also failed to properly manage cell IDs, identifiers assigned when femtocells connect to the core network, leaving an inadequate system to detect or block abnormal access by unauthorised equipment.
As a result, the hacker accessed KT's internal network for about 11 months from October 2024 to September 2025 without additional authentication procedures. KT identified the abnormal access only after micropayment losses and user complaints occurred. During deliberations, KT argued it was difficult to predict or respond in advance because it was an unprecedented type of incident in which the hacker directly produced a femtocell and intercepted communication signals.
Further sanctions possible; room to resume LG Uplus probe
The watchdog ordered KT to disclose the fine on its corporate website. It issued corrective orders to inspect vulnerabilities in wireless network equipment and strengthen safety measures for personal data. It also recommended improving governance centred on the chief privacy officer and expanding the scope of Information Security Management System-Personal Information (ISMS-P) certification to mobile telecommunications networks and systems.
In the femtocell incident probe, authorities also confirmed that 38 KT servers were infected in March 2024 with backdoor malware including 'BPFdoor'. It decided to file a complaint, viewing as obstruction that KT did not report the incident to the government, deleted some logs, reversed statements during the probe and submitted materials late.
In a subsequent probe, the watchdog also confirmed circumstances suggesting that an SQL injection attack occurred on the servers at the time and that some personal data was leaked. With the malware incident probe still under way, it can impose separate sanctions if new facts are secured through the investigation.
It also signalled the possibility of further investigation into LG Uplus. After recognising signs of a personal data leak, LG Uplus reinstalled the operating system of related servers and disposed of some servers before the watchdog began its investigation. The watchdog said it was difficult to rule out the possibility of hiding or destroying evidence, requested an investigation and has suspended its probe. If new facts are confirmed by the investigation, it plans to resume investigation and sanctions procedures.
The watchdog is also pushing a system to impose a separate fine of up to 3 percent of total revenue for acts of hiding or destroying evidence. A bill to introduce a noncompliance penalty and an evidence preservation order system has also been proposed in parliament. The new system, however, will apply only to acts occurring after the law takes effect and will not be applied retroactively to this case.
KT said it would accept the sanction. KT said, "We take the outcome of the sanction seriously, and once again deeply apologise for causing great concern and anxiety to customers and the public."
It added, "We will rebuild the overall personal information protection system from the ground up, expand security investment and strengthen company-wide personal information protection capabilities, and devote all our capabilities to preventing a recurrence and restoring customer trust."