주메뉴바로가기본문바로가기
비즈한국 비즈한국

SKT Hacking Incident: Is Replacing Your USIM Card Enough to Feel Safe?

This article was automatically translated by AI. There may be errors compared to the original Korean article.  Read original in Korean →

[비즈한국] Although SK Telecom017670, which recently suffered a hacking incident, has begun offering free USIM (Subscriber Identity Module) card replacements, subscriber anxiety over potential secondary damage, such as illegal USIM cloning, persists. The damage prevention measures introduced by the company are struggling to quell concerns, as the initial rollout has been marred by confusion caused by an influx of users. A shortage of supply has led to situations where consumers are left unable to replace their USIMs despite waiting in line, and even the "USIM Protection Service," considered an alternative, has been converted to an "appointment-based" system due to overwhelming demand.

Experts evaluate that replacing the USIM is a realistic measure to technically eliminate the root cause of crimes involving financial transactions. They explain that it is difficult to perform the authentication steps required by banking apps using only USIM information, and that as long as the carrier detects and accurately blocks attempted USIM cloning or theft at the central level, it will not lead to actual damage. However, some also note that this does not guarantee complete control over secondary damage.

Amid the commencement of free USIM replacements by SK Telecom, subscriber concerns regarding secondary damage continue. On the morning of the 28th, USIM replacements are being conducted at a T-World flagship store in Jongno-gu, Seoul. Photo=Reporter Park Jung-hoon
Amid the commencement of free USIM replacements by SK Telecom, subscriber concerns regarding secondary damage continue. On the morning of the 28th, USIM replacements are being conducted at a T-World flagship store in Jongno-gu, Seoul. Photo=Reporter Park Jung-hoon

USIM Replacement: The 'Best' Option for Now

Entering its 12th day, the SK Telecom hacking incident has sparked various issues. While there are growing voices demanding accountability and compensation for potential lapses in security management, legal concerns regarding delayed reporting, particularly from political circles, have also been raised. Criticism has also been directed at the inadequate initial response.

The practical effectiveness of the USIM replacement is the primary concern for users. According to the first investigation report released on the 29th by the joint public-private investigation team regarding the SKT breach, the information leaked in this incident includes four types of data that could be used for USIM cloning—such as subscriber phone numbers and International Mobile Subscriber Identity (IMSI) keys—as well as 21 types of management data required for USIM processing.

A notable detail is that the International Mobile Equipment Identity (IMEI), which acts as a unique ID for devices, was not leaked. Previously, because the items and scope of the leak were not public, it was difficult to predict the extent to which illegal USIM usage could spread. The Ministry of Science and ICT, which formed the investigation team, clarified that there was no leak of IMEI and stated, "We have confirmed that if a user subscribes to the USIM Protection Service currently being offered by SKT, so-called 'SIM Swapping' will be prevented." SIM swapping is a cybercrime method where hackers create a fake SIM card using stolen information to gain access to a victim’s calls, texts, or financial accounts.

SK Telecom first detected a data transfer of 9.7GB on the evening of the 18th, and after discovering malicious code at 11:20 PM that same day, internally confirmed that it had been hit by a hacking attack. The Home Subscriber Server (HSS) attacked is a core facility that manages integrated data such as USIM information and rate plans.

SK Telecom is also providing guidance on the USIM Protection Service to TV customers via their screens. Photo=Provided by reader
SK Telecom is also providing guidance on the USIM Protection Service to TV customers via their screens. Photo=Provided by reader

The consensus in the industry is that the possibility of USIM cloning occurring solely with the leaked USIM information is not high. Hwang Seok-jin, a professor at the Dongguk University Graduate School of International Information Security (a digital forensics advisor to the National Police Agency), explained, "To utilize financial information, one must go through an identity verification process, and since attackers cannot access IDs, passwords, or certificate passwords, there are practical limitations."

He also noted that even if a cloned phone were created, the potential for actual damage such as unauthorized transfers is low, provided the carrier's control measures, like the USIM Protection Service, operate properly. "Since the carrier verifies if the device is normally registered at the network level and performs detection and blocking of cloned USIMs, it is difficult for secondary damage to actually occur," added Professor Hwang.

Kwon Heon-young, a professor at the Korea University Graduate School of Information Security, stated, "It is necessary to distinguish between USIM information and information contained within the phone," adding, "We must be cautious about becoming overly heated at a stage where specific details of the leak and actual damages have not yet been confirmed."

100% Damage Prevention is a 'Question Mark'

On the 27th, SK Telecom announced additional measures, stating, "We will take responsibility if illegal USIM cloning damage occurs even after subscribing to the USIM Protection Service." While this intends to emphasize their response capability, there is skepticism that it will be difficult to determine liability once secondary or tertiary damage occurs.

Lee Ki-hyuk, a professor of Convergence Security at Chung-Ang University and chairman of the Korea Digital Authentication Association, explained, "For instance, if data from the Korea Employment Information Service, which was hacked two years ago, is being traded on the dark web, problems arise if that information is combined with data leaked from SK Telecom's HSS server and another site regarding the same individual. Hackers could perform personalized attacks." He then asked, "If damage occurs through a combination of information, would it really be possible to hold SK Telecom accountable and prove it?"

The investigation team discovered four types of 'BPFDoor' family malware. This malware is characterized by high concealment, making it difficult to detect the hacker's communication logs. Yeom Heung-yeol, professor emeritus of Information Security at Soonchunhyang University, pointed out, "While a typical backdoor is a concept where a hacker creates a 'back door' to facilitate re-entry after an initial breach, this method has a 'stealth function' that hides itself, making it quite difficult to detect. It is a small blessing that it was identified in the monitoring system."

Customers are waiting in line in front of a T-World flagship store in Jongno-gu, Seoul, on the morning of the 28th, when SK Telecom began free USIM replacements. Photo=Reporter Im Jun-seon
Customers are waiting in line in front of a T-World flagship store in Jongno-gu, Seoul, on the morning of the 28th, when SK Telecom began free USIM replacements. Photo=Reporter Im Jun-seon

The Next Chapter for Shaken 'Telecommunications Security'

Professor Kwon Heon-young suggested, "While recovery efforts are underway for users, we must now verify why this incident occurred." He argued that a fundamental diagnosis is needed to see if there were problems in the security management system that allowed the core data of the nation's No. 1 carrier, with 23 million subscribers, to be leaked.

SK Telecom spends less money on information security than its competitors. According to KISA’s information security disclosure portal, SK Telecom’s annual investment in information security last year was approximately 60 billion won. While this is a 9% increase from the previous year, it falls far short of the growth seen by KT and LG Uplus. KT and LG Uplus invested 121.8 billion won and 63.2 billion won, respectively.

Professor Hwang Seok-jin emphasized, "KT and LG Uplus took measures such as increasing cost investment and security personnel after experiencing their own hacking incidents," adding, "Looking at this hacking method, it is possible that information was not taken all at once but over a significant period of time. A comprehensive improvement and investment in the security system are necessary."

Movements to switch carriers are also notable due to USIM shortages and security concerns. A SKT PS&M branch in Jung-gu, Seoul, where USIM replacement services are being conducted on the morning of the 28th. Photo=Reporter Park Jung-hoon
Movements to switch carriers are also notable due to USIM shortages and security concerns. A SKT PS&M branch in Jung-gu, Seoul, where USIM replacement services are being conducted on the morning of the 28th. Photo=Reporter Park Jung-hoon

With the revelation that carrier servers were not included as "major information and communication infrastructure," the government's management responsibility has also been brought up. It is pointed out that while the government manages key national facilities such as telecommunications, finance, and energy for security inspections according to relevant laws, the government's authority is limited under the current system, requiring a review of the designation and management framework.

Professor Lee Ki-hyuk stated, "As telecommunications is a service used by the entire population, security standards matching that importance are necessary. Improving security vulnerabilities is the first task, and changes such as securing skilled security experts and building systems against sophisticated hacking techniques are required."

There are voices stating that SK Telecom's inventory of 1 million USIM cards is insufficient for the total number of users eligible for replacement, leading to a gap in service. It is expected that the trend of users changing devices or switching carriers will continue for the time being. SK Telecom's stance is to seek solutions through a method called "USIM Format" (provisional name), which involves changing USIM software, and by expanding the USIM Protection Service. SK Telecom stated, "We are currently developing the service so that the USIM Protection Service can also be used while roaming."

Professor Yeom Heung-yeol noted, "If you switch carriers, your USIM chip is also replaced. Even if there isn't a huge difference in the effectiveness of suppressing secondary damage, user attrition may appear as they seek to take quick action now that the USIM supply shortage has become apparent."

This article was automatically translated by AI. There may be errors compared to the original Korean article.
강은경 기자

기술과 산업을 취재하고 씁니다.

gong@bizhankook.com
저작권자 ⓒ 비즈한국 무단전재 및 재배포 금지