[Anchor]
The government has slapped KT with a fine of 53.9 billion won following a customer data leak and unauthorized micro-payments caused by illegal ultra-small base station hacking. Authorities viewed the fact that actual financial damage occurred as a major violation, noting that it could have been prevented with basic security measures.
Here is a report by Choi Seung-hun.
[Reporter]
The fine imposed on KT by the Personal Information Protection Commission (PIPC) stands at 53.979 billion won.
Over an 11-month period starting in October 2024, hacking using illegal ultra-small base stations, known as femtocells, resulted in the leakage of personal information belonging to approximately 16,000 KT users.
Among them, 368 victims suffered about 240 million won in unauthorized micro-payment damages.
[Yang Jung-sam / Secretary-General, Personal Information Protection Commission: The severity is extremely high given that it did not stop at a simple personal information leak, but rather led to actual financial damage.]
According to the investigation, the hacker stole authentication certificates from lost KT femtocells and inserted them into self-made illegal femtocells to intercept personal information.
KT had set the validity period of femtocell access certificates to an excessively long 10 years and operated them in a way that allowed access from other companies or overseas.
The company also failed to establish a detection system to filter out illegal equipment.
KT argued that it was difficult to respond to an unprecedented attack, but the PIPC rejected the claim, stating that the incident could have been prevented with basic access controls.
The fine imposed on KT by the PIPC is the fourth largest ever for an individual company. Mitigating factors were taken into consideration, such as the relatively small number of leaked user records and prompt post-incident measures including damage compensation and exemption from cancellation fees.
KT stated that it takes the disciplinary outcome seriously, issued an apology, and announced plans to invest 4 trillion won in information security and IT sectors over the next three years.
Separately from this case, the PIPC filed a complaint with investigative authorities against KT on charges of failing to report malware infections on its servers and submitting false data.
Additionally, LG Uplus was referred for investigation on charges of destroying servers showing signs of data leaks prior to the investigation.
(Camera: Cho Choon-dong | Video Editing: Choi Jin-hwa)
※ Please note: This article was translated by AI and may contain errors.
"Basic Security Alone Could Have Prevented It"... KT Fined 53.9 Billion Won
Copyright Ⓒ SBS. All rights reserved. 무단 전재, 재배포 및 AI학습 이용 금지
Trending Now
-
Video News
Japan Shopping Mall Where 7 Died Was Known as Disaster Shelter, Sparking Anxiety
-
Video News
Two-Year Grace Period for Class 1 Carcinogen Alert in Bottled Water Draws Backlash
-
Video News
Text Messages Exchanged with Chung Mong-gyu Exposed... When Asked "Who Is Senior Chung?"
-
Video News
"Why Are They Acting Like This?" Clustered Together... Honeybees Die Suddenly Amid Continuing Heatwave
-
Video News
Man Arrested After 50 km Chase Following Temple Threat with Toy Gun and Firing of Live Rounds
Video News
Video News
Video News
Video News
Video News