▲ Citizens walk past a KT store in Seoul on the 29th.
KT has been hit with a fine of approximately 54 billion won after a hack involving illegal small base stations, known as femtocells, led to the personal information leakage of about 16,000 users and unauthorized small-sum payments.
The Personal Information Protection Commission (PIPC) also decided to file a complaint against KT for obstructing investigations by deleting logs and making false statements.
The PIPC announced today (July 30) that it held a plenary meeting yesterday (July 29) and resolved to impose a fine of 53.979 billion won on KT for violating the Personal Information Protection Act, along with issuing corrective orders, improvement recommendations, and public announcements.
According to the investigation, a hacker extracted a certificate from a discarded KT femtocell, embedded it into a self-made illegal femtocell, and connected to KT’s mobile network to intercept communication data flowing between user terminals and the internal network.
The hacker then combined the acquired information with additional personal data such as names and dates of birth to attempt small-sum payments, successfully executing unauthorized transactions by hijacking payment authentication text messages (SMS) and automated response systems (ARS), the investigation showed.
In the process, the mobile phone numbers, International Mobile Subscriber Identities (IMSI), and International Mobile Equipment Identities (IMEI) of 16,647 users, including budget phone subscribers, were leaked, and a total of 368 people suffered approximately 240 million won in unauthorized small-sum payment damages.
The number of leaked individuals was calculated by taking KT's initial report of 22,227 people and filtering out duplicates such as corporations and multi-line accounts.
KT set the validity period of femtocell certificates to 10 years and operated them without restricting connection Internet Protocol (IP) addresses, allowing access via third-party or overseas IPs.
A bypass route bypassing the femtocell management server existed, and cell IDs—identifiers assigned when femtocells connect to the core network—were improperly managed, leaving the company without a system to detect or respond to abnormal connections from unauthorized cell IDs.
Consequently, the hacker accessed KT’s internal network without separate authentication for about 11 months from October 8, 2024, to September 5 of last year, while KT only became aware of the abnormal connection after small-sum payment damage complaints were filed.
The PIPC ordered KT to pay the fine, strengthen the security of its wireless communication network equipment, and overhaul its personal information protection governance.
In addition, the commission recommended improvements to expand the scope of the Personal Information Protection Management System (ISMS-P) certification to include mobile communication network systems.
The PIPC also confirmed a separate malware infection incident at KT.
KT was found to have been aware that hackers infiltrated its roaming rental service website through vulnerabilities in March 2024, infecting 38 servers with multiple pieces of malware including BPF Door, but handled the situation internally without reporting it to the government.
Circumstances were also uncovered in which hackers used a SQL (Structured Query Language) injection attack on the roaming rental service administrator page to view and leak the names, phone numbers, and accounts of some KT executives, employees, and partner company staff.
However, because network logs from the time of the incident did not remain, it could not be verified whether additional personal information of users processed on the infected servers was leaked.
KT even deleted the logs of 10 compromised servers during a comprehensive inspection for malware infections in April of last year.
Initially, KT stated to the PIPC during the early stages of the investigation that no preserved data existed, but after digital forensics confirmed circumstances of log deletion, KT retracted its statement and belatedly submitted logs it had kept separately.
The PIPC regarded these actions by KT as an obstruction of the investigation and decided to file a complaint.
Meanwhile, the PIPC concluded that LG Uplus committed acts obstructing the performance of official duties and decided to request an investigation by law enforcement authorities.
The PIPC initiated an investigation after learning of LG Uplus's personal information leakage through the U.S. security magazine Phrack in August of last year.
Upon inspecting whether text files containing the names and accounts of employees and partner staff were leaked, it was confirmed that the information was actually held and managed within LG Uplus's Integrated Password Management System (APPM).
However, LG Uplus was found to have reinstalled the operating systems (OS) of APPM servers or discarded the servers before the PIPC launched its investigation, making it difficult to verify the exact leakage routes and whether additional leaks occurred.
The PIPC explained that because the concealment and destruction of evidence took place before the investigation began, the obstruction of investigation provisions under the Personal Information Protection Act could not be applied, but it requested an investigation based on the obstruction of the performance of official duties.
Taking this incident as an opportunity, the PIPC is also pushing for institutional improvements to enhance investigation effectiveness.
It plans to introduce measures to criminally punish or impose fines of up to 3% of total sales if evidence is concealed or destroyed before an investigation starts, alongside introducing a reporting reward system.
Furthermore, the PIPC is pushing for amendments to the Personal Information Protection Act to impose compulsory compliance fines amounting to 0.3% of daily sales on businesses that are uncooperative with investigations or fail to implement corrective orders, and to issue data preservation orders when infringement incidents occur.
(Photo: Yonhap News)
※
Copying, redistribution, and unauthorized use in AI training are strictly prohibited.