KT has been fined 53.979 billion won by the Personal Information Protection Commission in connection with a hacking incident involving unauthorised small-payment charges. Some expect the smaller-than-initially-forecast bill to ease part of the financial uncertainty.
Still, separate from the fine, burdens remain, including expanded security investment under corrective orders, a complaint over obstruction of the investigation and the possibility of an administrative lawsuit. Longer-term costs to restore trust and overhaul security systems, rather than the size of the fine itself, are expected to be a variable for future management.
LEGAL CAP ABOUT ONE-QUARTER... LIMITED NEAR-TERM FINANCIAL HIT
Under the current Personal Information Protection Act, if a breach of required safety measures is confirmed, authorities can impose a fine of up to 3 percent of sales related to the violation. A simple application of the cap would have allowed a fine approaching 200 billion won, and the industry analysed that it would be a major financial burden for KT.
But the commission decided on a smaller fine of 53.979 billion won. It judged 5G and LTE mobile service revenue as related sales but excluded independent revenue such as IPTV and broadband internet from the calculation. It also reflected the violation period, whether corrective action was taken and efforts to recover damages.
Given KT's business scale, analysts say the fine is not a burden that would shake its overall operations. Compared with the cap, it is about one-quarter, and it worked out to about 0.8 percent of related sales. SK Telecom, which previously suffered a SIM hacking incident, was fined 134.8 billion won, about 1 percent of sales in the related segment.
The timing for recognising the cost and the accounting items to be used for this fine have not yet been decided. KT recorded operating profit of 2.4691 trillion won on a consolidated basis and 1.3050 trillion won on a separate basis last year. The fine equals about 2.2 percent of last year's consolidated operating profit and about 4.1 percent of separate operating profit, and the industry broadly views that KT avoided a fatal blow.
An industry official said, "I don't think it is at a level that would hurt cash flow and future investment capacity," adding, "From KT's point of view, it could be the best possible conclusion."
SECURITY, LEGAL COSTS VARIABLE... BURDEN OF ACTIONS AFTER COMPLAINT
Regardless of the fine burden, follow-up steps must be implemented swiftly. KT previously rolled out customer compensation programmes after the hacking incident, including waiving cancellation fees and providing data. In addition, under the commission's corrective order, KT must inspect vulnerabilities in wireless network equipment, including femtocells, and strengthen its security system. The commission also told KT to clarify the responsibilities and role of its chief privacy officer and overhaul governance for managing personal data processing work.
KT was also recommended to expand the scope of the Information Security Management System for Personal Information certification, known as ISMS-P, which had been applied to some IT services, to include mobile telecommunications networks and systems. KT must draw up related measures within 3 months and report them to the commission.
Whether to file an administrative lawsuit is also a variable. KT plans to decide its position after closely reviewing the details as soon as it receives the written decision. The industry expects there is a strong possibility KT will later pursue an administrative lawsuit.
A complaint over obstructing the investigation is a legal risk separate from the fine. The commission judged that after the investigation began, KT obstructed the probe by stating there were no materials related to infected servers and submitting logs belatedly. It decided to file a complaint against KT under Article 73 of the Personal Information Protection Act and related standards, leaving open the possibility of additional sanctions.
An industry official said, "Thorough clarification remains as a task, including whether there was organisational involvement in concealing the hacking and violations of reporting and data preservation obligations," adding, "Additional clarification by relevant authorities is absolutely necessary."
Kyeong-hee Song (송경희), chair of the Personal Information Protection Commission, said, "This disposition should serve as an opportunity to further strengthen security capabilities across the telecommunications industry," adding, "In particular, we will improve the system so that acts of concealing or downplaying materials when an incident occurs lead to significant disadvantages for companies."