▲ Chairperson Song Kyung-hee bangs the gavel during a plenary meeting of the Personal Information Protection Commission held at the Government Complex-Seoul in Jongno-gu, Seoul, on the 29th.
The Personal Information Protection Commission's decision to impose a massive fine amounting to 54.1 billion won on KT stems from its judgment that KT bore heavy responsibility as a major telecommunications operator for neglecting safety measures, leading to a large-scale personal information leak and triggering secondary damages such as unauthorized microtransactions.
When a corporate personal information leak occurs and a violation of safety measures is confirmed, the Personal Information Protection Commission determines the level of the fine based on revenues excluding those unrelated to the violation, within a limit not exceeding 3 percent of total sales.
The final fine is then calculated by applying weightings or reductions that take into account factors such as the severity of the legal violation, the scale of damage and impact on information subjects, and cooperation with investigations and completion of corrective actions.
The calculation of the fine for KT this year was based on the 5G and LTE communication revenues of KT's mobile communication service, where the unauthorized microtransaction accident occurred.
Unrelated independent revenues, such as IPTV and internet communication, were excluded from the relevant revenues and were not included in the criteria for calculating the fine.
The Personal Information Protection Commission pointed out that KT, as a major telecommunications operator providing mobile communication services essential to public life, failed to restrict illegal access by attackers (hackers) due to poor access control management over its internal network.
It also judged the violation to be severe based on the fact that the level of personal information infringement was quite high, as abnormal activities went undetected despite continuous access to the internal communication network, actually leading to financial damages.
In addition, the Personal Information Protection Commission explained that the final fine of 53.979 billion won was calculated by considering various factors, including the violation period, whether the violation was corrected, and efforts for damage recovery.
During the deliberation process for sanctions, KT argued that the incident was an unprecedented "new type of accident" caused by hackers fabricating femtocells to intercept communication signals transmitted from terminals, making prediction or response impossible, but this was not accepted.
The Personal Information Protection Commission pointed out, "Femtocells are not simple terminal communication equipment, but essential equipment that must be passed through to use mobile communication services. Given that this accident occurred due to poor management of femtocell equipment and insufficient access control to internal network connections, it was an accident that could have been sufficiently prevented if safety measures had been observed."
KT's obstruction of the investigation, such as submitting false data, was also taken into consideration during the process of sanctioning KT.
In the process of investigating the personal information leak via femtocells, the Personal Information Protection Commission confirmed that multiple servers had been infected and expanded its investigation, discovering that KT not only failed to report the breach facts to the government but also concluded the matter internally without conducting a detailed analysis of whether personal information was leaked.
At the time, the infected servers included a large number of systems processing user personal information.
The Personal Information Protection Commission also confirmed circumstances indicating a systematic cover-up of the breach facts, such as the deletion of logs from some of the servers where the breach occurred.
The Personal Information Protection Commission stated that KT initially "falsely stated" that there were no preserved data regarding the infected servers during the early stages of the investigation, but after digital forensics uncovered circumstances indicating that related logs had been deleted before the investigation commenced, KT delayed and obstructed the investigation by belatedly submitting logs that had been separately stored.
Apart from the fine sanctions against KT, the Personal Information Protection Commission decided to file a complaint against KT with investigative authorities in accordance with the Personal Information Protection Act and the "standards for filing complaints regarding violations of personal information protection regulations."
Article 73 of the Personal Information Protection Act stipulates that "anyone who refuses to submit data or submits false data for the purpose of concealing or minimizing legal violations in response to a data submission request" shall be punished by imprisonment for not more than two years or by a fine not exceeding 20 million won.
The Personal Information Protection Commission also attached great significance to its investigation and disposition regarding KT.
The Personal Information Protection Commission stated, "We have enhanced accountability through economic sanctions corresponding to the severity of the violation regarding a leak accident by a large-scale personal information processor providing services closely related to public life," adding, "We have once again confirmed the principle of strongly protecting the public's personal information."
It further urged, "Personal information processors must recognize that personal information leaks can lead to direct damage to public life and property, and must make every effort to prevent leak accidents from occurring."
(Photo: Yonhap News)
※ Please note: This article was translated by AI and may contain errors.
Video News
Video News