주메뉴바로가기본문바로가기
비즈한국 비즈한국

‘3.24 Million Won per Person’: Why KT Received a Massive 54 Billion Won Fine

This article was automatically translated by AI. There may be errors compared to the original Korean article.  Read original in Korean →

[비즈한국]  KT has been fined 53.979 billion won due to a personal information leak caused by femtocell (micro-base station) hacking. This is about 40% of the fine (134.791 billion won) imposed on SK Telecom for a USIM information leak last year. When calculated as a fine per affected user, it amounts to approximately 3.24 million won, which is over 550 times that of SK Telecom (approximately 5,800 won). This is interpreted as a heavy reflection of the management responsibility of the telecommunications network operator and the actual financial damages incurred, on top of the scale of the leak.

KT providing free USIM replacements to all customers as a follow-up measure after the hacking incident last November. Photo = Reporter Lee Jong-hyun

“KT is the entity responsible for managing femtocells”

On the 30th, the Personal Information Protection Commission (PIPC) imposed a fine of 53.979 billion won and a penalty of 7.2 million won on KT for violating the Personal Information Protection Act, while also issuing corrective orders, improvement recommendations, and publication orders. The commission decided to file a criminal complaint against KT for obstruction of investigation, including submitting false data during the investigation process. LG Uplus, which discarded relevant servers before the investigation began, was referred to investigative authorities on charges of obstruction of justice.

The scale of the personal information leak was finalized at 16,647 people, which is lower than the 22,227 cases initially announced by the joint public-private investigation team. This result comes from recalculating based on actual data subjects, excluding corporate lines and multiple lines owned by the same individual. Actual financial damages of approximately 240 million won occurred for 368 people.

The incident began when a hacker copied certificates from lost KT femtocells to create illegal, self-made femtocells and connected them to the KT mobile network. Femtocells are small base stations introduced by KT in 2016 to resolve wireless communication blind spots. The hacker induced user devices to pass through the hacker's femtocells to steal mobile phone numbers, International Mobile Subscriber Identities (IMSI), and International Mobile Equipment Identities (IMEI). By combining this with separately obtained personal information, the hacker requested micropayments and even intercepted ARS and SMS authentication to proceed with unauthorized transactions.

In terms of total amount, the level of sanctions is lower than that of SK Telecom. Although the PIPC classified KT as having committed a "serious violation," one level lower than SK Telecom, it judged that: "As a major telecommunications operator providing mobile services essential to the lives of the public, the company was negligent in managing access control to its internal network. It failed to restrict illegal access by attackers and could not detect continuous abnormal behavior, leading to actual financial damages." While the level of personal information infringement was deemed quite high, the final fine was calculated by comprehensively considering the relatively smaller scale of confirmed leaks and the fact that the leaked information was limited to three types: mobile phone numbers, IMSI, and IMEI.

Source = Personal Information Protection Commission

Some observers speculated that because femtocells are equipment installed only for certain subscribers, only related revenue could be reflected; however, the actual criteria for calculating the fine was determined by the 5G and LTE telecommunication revenue of KT's mobile communication services. Unrelated, independent revenue sources such as IPTV and internet communication were excluded.

The core issue of this deliberation was who should be held responsible for the management of femtocells. During the deliberation process, KT argued, "This was an unprecedented new type of attack that intercepted device communication signals using femtocells manufactured by the hacker, making it impossible to predict or respond to."

The PIPC determined that "the actual operating entity of the femtocells is KT, and the management and control rights over the user authentication process for mobile network access and service provision, as well as the transmission of personal information during this process, belong to KT." It also pointed out that the equipment is company property installed directly by KT technicians and not sold to users.

Loopholes in the management system were also specifically pointed out. The commission viewed this as an accident that could have been sufficiently prevented if equipment management and internal network access control had been handled properly. At the time of the incident, KT's femtocell management system was generally poor, leaving the internal network in a state where unauthorized femtocells could easily connect. Factors considered included: △ the long 10-year validity period set for femtocell certificates, △ the lack of restrictions on internal network access IPs, allowing connections from overseas or third-party IPs, △ the existence of paths bypassing the management server, and △ the lack of a system to detect or respond to unauthorized Cell IDs.

As a result, even though the hacker accessed the internal network and leaked personal information for about 11 months, KT failed to detect it and only confirmed the abnormal access after receiving complaints regarding micropayment damages.

Risks Under Scrutiny Following Consecutive Accidents at Three Major Telecoms

With large-scale personal information leaks and allegations of accident cover-ups emerging one after another at SK Telecom, KT, and now LG Uplus, the deficiencies in the security risk management systems of the entire telecommunications industry have come to the surface.

KT's response after the accident was also brought to the table. Even after KT first became aware of the server's malicious code infection in March 2024, it did not report the breach to the government and handled the matter internally without a detailed analysis of whether personal information was leaked. Later, during a process of inspecting all servers triggered by leaks at other companies, circumstances of systematic cover-ups, such as deleting some logs on the breached server, were also identified.

KT Headquarters located in Gwanghwamun. Photo = Reporter Im Jun-sun

The PIPC decided to file a criminal complaint against KT for obstruction of investigation, as the company initially stated there were no preserved materials but later changed its testimony and belatedly submitted the logs once digital forensics revealed the deletion of the files.

Following this case, as amendments to the Personal Information Protection Act are being pushed—centering on criminal punishment and fines for evidence concealment/destruction before investigations, the imposition of enforcement fines for non-cooperation with investigations, and the introduction of data preservation orders—the "cover it up first" style of response to accidents is expected to no longer be effective. With improvement recommendations issued to expand the Information Security Management System (ISMS-P) certification scope, which was previously limited to some IT services, to include mobile communication network systems, it is evaluated that telecommunication network facilities, which were previously in a blind spot for certification, will now fall under the government's regular inspection targets.

Along with the fine, KT will also be subject to a corrective order requiring it to conduct vulnerability assessments of wireless communication network equipment, strengthen personal information access control systems, and reinforce the responsibilities and roles of the Chief Privacy Officer (CPO).

A KT official stated, "We take the PIPC's disciplinary results gravely, and we once again deeply apologize for causing great concern and anxiety to our customers and the public due to this incident," adding, "We will do our utmost to prevent recurrence and restore customer trust by fundamentally reorganizing the entire personal information protection system and expanding security investments."

Following the PIPC's decision, companies can review the disciplinary details after receiving the written decision and potentially file an administrative lawsuit. Given that there are many cases where large-scale fines lead to administrative litigation, attention is focused on KT's response. The KT official said, "We will determine our stance after carefully reviewing the content once we receive the written decision."

This article was automatically translated by AI. There may be errors compared to the original Korean article.
강은경 기자

기술과 산업을 취재하고 씁니다.

gong@bizhankook.com
저작권자 ⓒ 비즈한국 무단전재 및 재배포 금지