[비즈한국] A large-scale leak of SIM card information due to hacking has occurred at SK Telecom017670, the top telecommunications company in South Korea, sparking significant controversy. While SKT has stepped in to mitigate the situation by offering free SIM replacements and a "SIM Protection Service," subscriber anxiety shows no signs of subsiding. This is because past cases of SIM cloning crimes have led to financial losses, including the theft of virtual assets. Amid growing concerns over when and where additional damage might occur, we examined court rulings related to SIM cloning crimes from 2022 to 2024 to see how hacking leads to asset theft.

The aftermath of the SKT SIM information hacking incident that occurred on April 19 is growing. In a notice issued on the 25th, SKT stated, "Personal identification information such as names, addresses, and resident registration numbers were not included." Regarding the scale of the damage, they noted, "We are investigating the cause and scale of the incident in cooperation with relevant authorities."
SKT is the number one mobile carrier in Korea. As of the end of 2024, its market share reached 45.3% (Ministry of Science and ICT). SKT stated it has approximately 23 million subscribers. Although SKT has not disclosed the exact scale of the damage, it is assumed to be significant given their market share. Rep. Choi Min-hee of the Democratic Party of Korea previously announced that the leaked information amounted to 9.7 gigabytes (GB).
Although a week has passed since the leak became public, subscribers remain anxious. This is due to growing fears of becoming a target of SIM cloning crimes. "Illegal SIM cloning attacks," a new type of crime that has emerged in Korea over the last three years, involve illegally collecting an individual's SIM information to clone the SIM and steal financial assets. Compared to financial fraud like phishing, the methods of this crime are less well-known.
Therefore, we examined three criminal court rulings from the last three years (2022–2024) related to illegal SIM cloning crimes to see how the leak of SIM information leads to financial theft. The crimes were organized and executed to steal the victims' assets. Furthermore, the criminal groups secured not only the victims' SIM information but also personal information such as their names and resident registration numbers.
The modus operandi generally consists of three stages. First, the group collects the SIM information and personal data of specific carrier subscribers through illegal channels. After cloning the SIM using the collected data, they insert it into an empty device and intercept identity verification messages from various sites. Using the intercepted verification information, they access the victim's portal accounts, virtual asset exchanges, etc., to make small payments or transfer virtual assets to other wallets.
A recent case occurred in June 2023, where approximately 365 million won in virtual assets was stolen. Intermediaries were deployed at each stage, from gathering the victim's SIM information to extracting the assets. The roles were divided sequentially: "SIM information thieves" who gather data via hacking; "SIM swap agents" who insert the cloned SIM into other devices to change device information; "Communication information thieves" who intercept verification messages using the cloned device; and "Virtual asset thieves" who access the victim’s exchange account with the stolen verification info to move assets to other wallets. The group operated mainly out of China, with activities in cities like Gwangju and Incheon.

In this case, when a domestic intermediary connected a SIM cloner and a router to a laptop, the group in China used remote access software to clone the SIM. The virtual asset theft took place between 3:00 AM and 5:00 AM—a time when it is difficult for victims to realize they have been hacked, or even if they do, to respond immediately.
In February 2022, there was also a case where a SIM cloning group exploited vulnerabilities in the authentication process of an MVNO (budget phone) site to issue SIM cards non-face-to-face. They bypassed the authentication process by using fake general-purpose public digital certificates. This was only possible because the criminal group had already secured the victims' names and resident registration numbers.
SKT has also been a target of illegal SIM cloning attacks in the past. In a case from May–June 2022, according to court documents, the criminal group cloned the SIMs of more than 15 SKT subscribers.
Following this incident, SKT advised that illegal SIM cloning or device theft is difficult to commit. They explained that their "Fraud Detection System (FDS)," which detects illegal SIM usage, is active, and that subscribing to the "SIM Protection Service" can prevent damage as effectively as a SIM replacement. The SIM Protection Service is a service that blocks access to communication services from cloned SIMs on other devices. SKT stated that they developed this service in 2023 in cooperation with the Seoul Metropolitan Police Agency's Cyber Investigation Unit.
Looking at previous precedents, criminal groups secured victims' personal information through various means to steal financial assets. As SKT stated that personal identification information was not leaked, the possibility of secondary damage remains uncertain. On the 27th, SKT drew criticism by stating, "If a case of illegal SIM cloning damage occurs to a subscriber of the SIM Protection Service, SKT will take responsibility and compensate them," limiting the 100% compensation target to service subscribers. SKT stated, "This is intended to emphasize the stability of the SIM Protection Service and encourage enrollment."
Experts also believe that if SKT's security system is functioning properly, the possibility of it leading to financial damage is low. Yeom Heung-yeol, professor emeritus of the Department of Information Security at Soonchunhyang University, analyzed, "Technically, the risk of financial asset theft is not high. SIM information consists mainly of three things: International Mobile Subscriber Identity (IMSI), SIM authentication keys, and International Mobile Equipment Identity (IMEI). I understand that the IMEI was not leaked. In that case, connection of cloned phones can be blocked through the FDS."
According to the initial investigation results of the public-private joint investigation team under the Ministry of Science and ICT, in addition to the IMEI, four types of information that could be used for SIM cloning—including the IMSI and phone numbers—and 21 types of information used by SKT for SIM information management were leaked.
However, Professor Yeom pointed out that people should remain vigilant. He advised, "The assumption that the risk of additional damage is low is based on the premise that SKT's user protection system and FDS are working properly. Subscribers should still replace their SIM cards or sign up for the SIM Protection Service to prepare for potential accidents."