The Korean authority sanctions KT for a massive personal data breach via an illegal femtocell

The South Korean data protection authority sanctioned the telecommunications operator KT for major security flaws on its femtocell network that led to a data breach and direct financial harm to users. The authority also initiated proceedings against KT and its competitor LGU+ for obstruction of the investigation, notably through the destruction of evidence.

Facts and context

The South Korean authority, the Personal Information Protection Commission (PIPC), today published a sanction decision against KT (including the imposition of a fine of 53,979,000,000 South Korean won (approximately 36 million euros)) for failures related to securing its telecommunications network and obstruction of an investigation.

The case originated from reports of fraudulent micro-payment transactions and press articles, which led the PIPC to open an investigation on September 10, 2025, into a potential data breach.

Grounds for the decision

The investigation revealed two distinct sets of failings. The first concerns the data breach via KT's femtocell network, while the second relates to acts of obstruction to the investigation by KT and the operator LGU+.

Regarding the data breach, the authority found the following failure by KT:

  • Obligation to ensure the security of personal data: The authority judged that KT, as operator and owner of the femtocells (mini base stations installed at customers' premises), was responsible for securing access to its central network. However, the investigation revealed serious deficiencies in access control measures. An attacker was able to extract a certificate from a lost femtocell, implant it on unauthorized equipment, and connect to KT's internal network for nearly 11 months (from October 8, 2024, to September 5, 2025) without detection. The authority noted several technical negligence points: certificate validity was 10 years, no IP address restrictions were applied to femtocell connections (allowing connections from abroad), and no system was in place to detect abnormal connections based on cell identifiers. These flaws allowed the data of 16,647 users (phone number, international mobile subscriber identity (IMSI), international mobile equipment identity (IMEI)) to be leaked and directly caused financial harm amounting to approximately 240 million won through fraudulent micro-payments.

Regarding obstruction to investigations, the authority found serious actions by both operators. On one hand, KT was implicated for concealing a security incident in March 2024, during which 38 of its servers were infected by malware. The company did not notify the incident, deleted part of the connection logs before the investigation, and initially provided false information to the authority by denying the existence of logging data. On the other hand, LGU+ was investigated following the revelation of a data breach in August 2025. However, before the PIPC investigations began, the company reinstalled operating systems or discarded the affected servers, making it impossible to determine the origin and extent of the breach.

Authority's decision

Consequently, the authority imposed a fine of 53,979,000,000 South Korean won (approximately 36 million euros) on KT for failing its security obligation.

Furthermore, the authority ordered KT to publish the sanction on its website, conduct a vulnerability audit of its wireless network equipment, strengthen its access control measures, clarify the responsibilities of its data protection officer, and report back within three months. It also recommended that the company extend its personal information protection management system certification (ISMS-P) to its telecommunications network systems. Additionally, the authority decided to file a complaint against KT for obstruction of the investigation and to request the opening of a criminal investigation against LGU+ for destruction of evidence.

Lessons learned

This decision reminds that:

  • The responsibility for securing network equipment deployed at customers' premises (such as femtocells or internet boxes) lies entirely with the operator who provides them and controls access to its central network.
  • The absence of fundamental security measures, such as limiting access by IP address, strict certificate management, and monitoring of abnormal connections, constitutes a serious breach of the security obligation.
  • Concealing a security incident or destroying evidence, including before the official launch of an investigation by an authority, constitutes serious offenses that may lead to criminal prosecution separate from administrative sanctions.
  • The materialization of direct financial harm to data subjects following a data breach is a major aggravating factor in determining the amount of the fine.
  • The data protection officer must have real authority and responsibilities to oversee data security across all company scopes, including technical and network infrastructures.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire