← SK Telecom

2025 SK Telecom — USIM / SIM data breach (~23.2M); PIPC fine ₩134.8B

2025 23.2M records affected Share on X

Data compromised

Phone numbers, IMSI, SIM authentication keys, and related subscriber authentication fields

Technical writeup

South Korea’s largest mobile carrier SK Telecom disclosed a hacking incident in April 2025 that exposed SIM-related authentication data for more than 23 million subscribers (about 23.2 million people across 25 data categories in PIPC findings), including phone numbers, IMSI identifiers, and SIM authentication keys. Investigators said attackers had prolonged access and that SKT had failed to encrypt roughly 26.1 million SIM authentication keys held in plaintext databases, alongside weak network segmentation between internet-facing and management systems. The company began a mass USIM replacement program. On 28 August 2025, the Personal Information Protection Commission imposed a then-record administrative fine of ₩134.8 billion (~US$97M) plus a smaller administrative penalty for basic security failures. SKT acknowledged responsibility while disputing how remedial steps were weighed; later reporting said the carrier challenged the fine in court.

Root cause

Network intrusion into subscriber/authentication systems; inadequate encryption and segmentation (per PIPC)

References