[비즈한국] Although SK Telecom017670, which recently suffered a hacking incident, has begun offering free USIM (Subscriber Identity Module) card replacements, subscriber anxiety over potential secondary damage, such as illegal USIM cloning, persists. The damage prevention measures introduced by the company are struggling to quell concerns, as the initial rollout has been marred by confusion caused by an influx of users. A shortage of supply has led to situations where consumers are left unable to replace their USIMs despite waiting in line, and even the "USIM Protection Service," considered an alternative, has been converted to an "appointment-based" system due to overwhelming demand.
Experts evaluate that replacing the USIM is a realistic measure to technically eliminate the root cause of crimes involving financial transactions. They explain that it is difficult to perform the authentication steps required by banking apps using only USIM information, and that as long as the carrier detects and accurately blocks attempted USIM cloning or theft at the central level, it will not lead to actual damage. However, some also note that this does not guarantee complete control over secondary damage.

USIM Replacement: The 'Best' Option for Now
Entering its 12th day, the SK Telecom hacking incident has sparked various issues. While there are growing voices demanding accountability and compensation for potential lapses in security management, legal concerns regarding delayed reporting, particularly from political circles, have also been raised. Criticism has also been directed at the inadequate initial response.
The practical effectiveness of the USIM replacement is the primary concern for users. According to the first investigation report released on the 29th by the joint public-private investigation team regarding the SKT breach, the information leaked in this incident includes four types of data that could be used for USIM cloning—such as subscriber phone numbers and International Mobile Subscriber Identity (IMSI) keys—as well as 21 types of management data required for USIM processing.
A notable detail is that the International Mobile Equipment Identity (IMEI), which acts as a unique ID for devices, was not leaked. Previously, because the items and scope of the leak were not public, it was difficult to predict the extent to which illegal USIM usage could spread. The Ministry of Science and ICT, which formed the investigation team, clarified that there was no leak of IMEI and stated, "We have confirmed that if a user subscribes to the USIM Protection Service currently being offered by SKT, so-called 'SIM Swapping' will be prevented." SIM swapping is a cybercrime method where hackers create a fake SIM card using stolen information to gain access to a victim’s calls, texts, or financial accounts.
SK Telecom first detected a data transfer of 9.7GB on the evening of the 18th, and after discovering malicious code at 11:20 PM that same day, internally confirmed that it had been hit by a hacking attack. The Home Subscriber Server (HSS) attacked is a core facility that manages integrated data such as USIM information and rate plans.

The consensus in the industry is that the possibility of USIM cloning occurring solely with the leaked USIM information is not high. Hwang Seok-jin, a professor at the Dongguk University Graduate School of International Information Security (a digital forensics advisor to the National Police Agency), explained, "To utilize financial information, one must go through an identity verification process, and since attackers cannot access IDs, passwords, or certificate passwords, there are practical limitations."
He also noted that even if a cloned phone were created, the potential for actual damage such as unauthorized transfers is low, provided the carrier's control measures, like the USIM Protection Service, operate properly. "Since the carrier verifies if the device is normally registered at the network level and performs detection and blocking of cloned USIMs, it is difficult for secondary damage to actually occur," added Professor Hwang.
Kwon Heon-young, a professor at the Korea University Graduate School of Information Security, stated, "It is necessary to distinguish between USIM information and information contained within the phone," adding, "We must be cautious about becoming overly heated at a stage where specific details of the leak and actual damages have not yet been confirmed."
100% Damage Prevention is a 'Question Mark'
On the 27th, SK Telecom announced additional measures, stating, "We will take responsibility if illegal USIM cloning damage occurs even after subscribing to the USIM Protection Service." While this intends to emphasize their response capability, there is skepticism that it will be difficult to determine liability once secondary or tertiary damage occurs.
Lee Ki-hyuk, a professor of Convergence Security at Chung-Ang University and chairman of the Korea Digital Authentication Association, explained, "For instance, if data from the Korea Employment Information Service, which was hacked two years ago, is being traded on the dark web, problems arise if that information is combined with data leaked from SK Telecom's HSS server and another site regarding the same individual. Hackers could perform personalized attacks." He then asked, "If damage occurs through a combination of information, would it really be possible to hold SK Telecom accountable and prove it?"
The investigation team discovered four types of 'BPFDoor' family malware. This malware is characterized by high concealment, making it difficult to detect the hacker's communication logs. Yeom Heung-yeol, professor emeritus of Information Security at Soonchunhyang University, pointed out, "While a typical backdoor is a concept where a hacker creates a 'back door' to facilitate re-entry after an initial breach, this method has a 'stealth function' that hides itself, making it quite difficult to detect. It is a small blessing that it was identified in the monitoring system."

The Next Chapter for Shaken 'Telecommunications Security'
Professor Kwon Heon-young suggested, "While recovery efforts are underway for users, we must now verify why this incident occurred." He argued that a fundamental diagnosis is needed to see if there were problems in the security management system that allowed the core data of the nation's No. 1 carrier, with 23 million subscribers, to be leaked.
SK Telecom spends less money on information security than its competitors. According to KISA’s information security disclosure portal, SK Telecom’s annual investment in information security last year was approximately 60 billion won. While this is a 9% increase from the previous year, it falls far short of the growth seen by KT and LG Uplus. KT and LG Uplus invested 121.8 billion won and 63.2 billion won, respectively.
Professor Hwang Seok-jin emphasized, "KT and LG Uplus took measures such as increasing cost investment and security personnel after experiencing their own hacking incidents," adding, "Looking at this hacking method, it is possible that information was not taken all at once but over a significant period of time. A comprehensive improvement and investment in the security system are necessary."

With the revelation that carrier servers were not included as "major information and communication infrastructure," the government's management responsibility has also been brought up. It is pointed out that while the government manages key national facilities such as telecommunications, finance, and energy for security inspections according to relevant laws, the government's authority is limited under the current system, requiring a review of the designation and management framework.
Professor Lee Ki-hyuk stated, "As telecommunications is a service used by the entire population, security standards matching that importance are necessary. Improving security vulnerabilities is the first task, and changes such as securing skilled security experts and building systems against sophisticated hacking techniques are required."
There are voices stating that SK Telecom's inventory of 1 million USIM cards is insufficient for the total number of users eligible for replacement, leading to a gap in service. It is expected that the trend of users changing devices or switching carriers will continue for the time being. SK Telecom's stance is to seek solutions through a method called "USIM Format" (provisional name), which involves changing USIM software, and by expanding the USIM Protection Service. SK Telecom stated, "We are currently developing the service so that the USIM Protection Service can also be used while roaming."
Professor Yeom Heung-yeol noted, "If you switch carriers, your USIM chip is also replaced. Even if there isn't a huge difference in the effectiveness of suppressing secondary damage, user attrition may appear as they seek to take quick action now that the USIM supply shortage has become apparent."