2025 KT — illegal femtocell breach; ~16,847 PI victims (PIPC fine Jul 2026)
Data compromised
Names, gender, dates of birth and related subscriber data used in unauthorized micropayments; IMSI/subscriber identity data per earlier KT notices; separate Mar 2024 internal malware leak of employee/partner names, phones, accounts (concealed, per PIPC)
Technical writeup
Verified regulator action — South Korea PIPC plenary (Jul 29, 2026) imposed a ~KRW 53.979 billion fine (~USD $37.6M) on KT plus corrective orders after the illegal femtocell / mini base-station intrusion. PIPC findings: attackers used certificates from a lost KT femtocell on a rogue cell, accessed the mobile network, combined stolen PI (names, gender, DOB) with intercepted ARS/SMS auth codes for unauthorized micropayments — ~16,847 users’ personal information leaked and ~KRW 240M micropayment losses for 368 people. PIPC also cited a March 2024 malware infection of 38 KT IT servers leaking employee/partner worker names, phones, and accounts that KT handled internally without required reporting and allegedly deleted logs on 10 servers. Earlier Sep 2025 KT notices had cited ~5,561 data victims among ~19k customers connected to rogue cells; catalog count updated to the PIPC-attested 16,847 PI-leak figure. Sources: DataBreaches.net / Seoul Economic Daily coverage of the Jul 30, 2026 fine.
Root cause
Illegal femtocell / rogue mini base-station interception of mobile traffic
References
- https://www.telecomtv.com/content/security/south-korea-s-kt-admits-data-breach-53816/
- https://andopen.co.kr/kt-telecom-hack-explained-how-it-happened-and-whats-next/
- https://www.pipc.go.kr/np/cop/bbs/selectBoardArticle.do?bbsId=BS074&mCode=C020010000&nttId=11499
- https://databreaches.net/2026/07/30/kr-kt-fined-54-billion-won-over-data-breach-via-illegal-base-stations/
- https://en.sedaily.com/technology/2026/07/30/kt-fined-54-billion-won-over-data-breach-via-illegal-base
- https://www.koreaherald.com/article/10825672