South Korea’s Personal Information Protection Commission (PIPC) has fined KT Corp. 53.9 billion won ($37.4 million) after finding that weak network access controls allowed hackers to expose the personal information of 16,647 mobile customers.
The regulator said hackers accessed KT’s wireless network through an unauthorized femtocell, a small base station used to extend mobile coverage, and stole customer information, including phone numbers and device identification numbers.
The stolen data was later used to carry out unauthorized transactions, resulting in about 240 million won ($166,600) in losses for 368 victims.
The PIPC said the intrusion went undetected between October 8, 2024, and September 5, 2025, and KT only became aware of the incident after a customer complaint. Those affected included customers using mobile virtual network operators.
The regulator also found additional security problems while investigating the breach. According to The Korea Herald, 38 servers connected to KT’s personal information systems were infected with malware, including BPFDoor.
“KT was aware of the malware infection on its servers in March last year but failed to report the security breach to the government,” a PIPC official said, according to The Korea Herald. “During a full-scale inspection of KT’s servers, we found signs suggesting an organized attempt to conceal the incident, including the deletion of logs from 10 compromised servers.”
The PIPC said it would refer the case for criminal investigation over KT’s handling of the incident, including alleged failures to report the breach and deletion of server logs.
A warning for telecom security
The size of the penalty highlights how regulators are increasingly treating telecom networks as critical infrastructure rather than ordinary corporate systems. A breach involving mobile networks can expose not only personal information but also create direct financial risks for customers.
For telecom operators, the incident shows that protecting customer data requires more than securing traditional databases. Network equipment, third-party systems and smaller access points such as mobile base stations can become entry points for attackers if they are not properly managed.
KT said it accepted the regulator’s decision and apologized to customers. A KT official said the company was rebuilding its privacy protection systems and increasing security investment “to prevent similar incidents and restore customer trust,” according to The Korea Herald.
Check out our breach response guide for the steps MSPs should take before, during, and after a suspected compromise affecting their own systems or a client environment.





