Thursday, September 17, 2026

KT Fined 53.9 Billion Won and Referred to Prosecutors Over Data Leak and Investigation Obstruction

Input
2026-07-30 13:19:10
Updated
2026-07-30 13:19:10
[Financial News] KT was hit with a fine of 53.9 billion won after allowing illegal small base stations, or femtocells, to access its core mobile network, which led to the leak of subscribers’ mobile phone numbers and even financial damage through unauthorized small-value mobile payments. It was also referred to prosecutors on charges of obstructing a government investigation by failing to report a malware infection and instead deleting logs.
LG Uplus was found to have signs of subscriber personal data leaks caused by a malware infection, but it destroyed evidence by discarding servers before the government investigation, and will now face a formal probe by investigators.
The Personal Information Protection Commission (PIPC) said on the 30th that it held a plenary meeting on the 29th and decided to impose a fine of 53.979 billion won on KT for violating its duty to take safety measures under the Personal Information Protection Act. The commission also approved corrective orders, improvement recommendations and a public disclosure order.
KT's weak network management went unnoticed for 11 months

According to the PIPC's investigation, hackers extracted certificates from a lost KT femtocell, inserted them into a self-made illegal femtocell, and then accessed KT's core mobile network. They stole the mobile phone numbers, subscriber identification numbers (IMSI), and device identification numbers (IMEI) of 16,647 KT subscribers, including mobile virtual network operator users.
KT was fined 53.9 billion won after allowing illegal small base stations, or femtocells, to access its core mobile network, which led to the leak of subscribers’ mobile phone numbers and even financial damage through unauthorized small-value mobile payments. It was also referred to prosecutors on charges of obstructing a government investigation by failing to report a malware infection and instead deleting logs. LG Uplus was found to have signs of subscriber personal data leaks caused by a malware infection, but it destroyed evidence by discarding servers before the government investigation, and will now face a formal probe by investigators. (Source: Yonhap News Agency)

In particular, unauthorized small-value mobile payments amounting to about 240 million won were made involving 368 people. The PIPC said, "KT's data leak incident is a serious case in which a telecom company's personal data breach led to actual financial damage."
The PIPC said, "The hackers' illegal femtocells accessed KT's internal network without a separate authentication process for 11 months, from Oct. 8, 2024, to Sept. 5, 2025, and stole personal data, but KT's network management was so poor that it failed to detect the abnormal access. It was only after multiple complaints about secondary damage, including small-value mobile payments, that it realized the abnormal connections," criticizing KT's responsibility for network management.
In addition to the fine, the PIPC ordered KT to submit a report within three months on measures such as inspecting vulnerabilities in wireless communication network equipment, including femtocells, and clarifying the responsibilities and roles of the chief privacy officer (CPO).
A system that favors obstruction and evidence destruction will be changed

In April last year, SK Telecom reported to the government that the personal data of more than 23 million subscribers had been leaked in a hacking incident, and this year it was fined 134.791 billion won. During the government's full inspection of telecom companies' servers after that incident, it was revealed that KT had learned in March 2024 that it had been infected with malware but did not report it to the government. Instead, it handled the matter internally without analyzing whether personal data had been leaked. It was also confirmed that KT obstructed the investigation by deleting logs from some malware-infected servers during the government's full inspection.
Yang Cheong-sam, secretary general of the PIPC, speaks at Government Complex Seoul in Jongno-gu, Seoul, on the morning of the 30th as he announces the results of the plenary meeting on corrective measures for businesses that violated personal information protection laws, including KT's fine. The PIPC said it would impose a fine of 53.979 billion won on KT for violating its duty to take safety measures in connection with the leak of personal data through illegal femtocells. /Photo=Newsis

LG Uplus was also found to have gone as far as destroying evidence before the government's full inspection began, including reinstalling operating systems on servers and other systems and discarding some servers. In the end, the PIPC was unable to fully determine the scope of the personal data leaks involving KT and LG Uplus, and could only impose fines on the cases it had confirmed.
As a result, some companies developed the mistaken belief that "it is better for a company to obstruct an investigation by destroying evidence than to honestly report to the PIPC and be punished."
In response, the PIPC decided to refer KT to prosecutors and request a formal investigation into LG Uplus by law enforcement authorities.
It also plans to push for institutional reforms to prevent obstruction of investigations. By the end of this year, it will revise the Personal Information Protection Act to establish criminal penalties for concealing or destroying evidence before an investigation begins. It also plans to impose a fine of 3% of total sales for evidence concealment or destruction, while introducing a reward system for reporting such acts in order to encourage whistleblowing.
KT and LG Uplus: "We bow our heads in apology... We will do everything we can to restore customer trust"

Regarding the PIPC's decision, KT said, "We take the outcome of the sanctions seriously, and once again bow our heads to offer our deepest apologies for causing great concern and anxiety to our customers and the public over the recent incident. We are rebuilding our entire personal information protection system from the ground up, and we will devote all our capabilities to preventing a recurrence and restoring customer trust by expanding security investment and strengthening companywide privacy protection capabilities."
LG Uplus also said, "Police investigations into the same matter are already under way, and we are faithfully cooperating with them. We will continue to do so."
[email protected] Lee Gu-soon Reporter