← KT Corporation

2025 KT — illegal femtocell breach; ~16,847 PI victims (PIPC fine Jul 2026)

2025 16.8K records affected Share on X

Data compromised

Names, gender, dates of birth and related subscriber data used in unauthorized micropayments; IMSI/subscriber identity data per earlier KT notices; separate Mar 2024 internal malware leak of employee/partner names, phones, accounts (concealed, per PIPC)

Technical writeup

Verified regulator action — South Korea PIPC plenary (Jul 29, 2026) imposed a ~KRW 53.979 billion fine (~USD $37.6M) on KT plus corrective orders after the illegal femtocell / mini base-station intrusion. PIPC findings: attackers used certificates from a lost KT femtocell on a rogue cell, accessed the mobile network, combined stolen PI (names, gender, DOB) with intercepted ARS/SMS auth codes for unauthorized micropayments — ~16,847 users’ personal information leaked and ~KRW 240M micropayment losses for 368 people. PIPC also cited a March 2024 malware infection of 38 KT IT servers leaking employee/partner worker names, phones, and accounts that KT handled internally without required reporting and allegedly deleted logs on 10 servers. Earlier Sep 2025 KT notices had cited ~5,561 data victims among ~19k customers connected to rogue cells; catalog count updated to the PIPC-attested 16,847 PI-leak figure. Sources: DataBreaches.net / Seoul Economic Daily coverage of the Jul 30, 2026 fine.

Root cause

Illegal femtocell / rogue mini base-station interception of mobile traffic

References