SK Telecom filed a lawsuit with the Seoul Administrative Court seeking to revoke a record 135 billion won (US$91 million) penalty imposed by South Korea’s Personal Information Protection Commission (PIPC) following a cyberattack and subsequent data leak affecting the carrier’s entire 23 million-user base. Reporting indicates the fine was issued after SK Telecom belatedly disclosed a breach of its servers that exposed universal subscriber identity module (USIM) information, and the company moved to challenge the decision just ahead of the deadline to seek revocation.
The PIPC penalty is described as the largest ever issued by the regulator since its establishment, exceeding the combined fines levied against Meta and Google in 2022. In response to the incident and regulatory scrutiny, SK Telecom offered free USIM replacements to users and is expected to argue that its post-incident security spending and reforms, along with the absence of reported direct subscriber financial losses, warrant reconsideration and that the fine is disproportionate compared with prior enforcement actions.

See the reporting duties and controls this puts on the clock.
5 events from the most recent confirmed update back to the earliest known activity.
South Korea's Ministry of Science and ICT announced that SK Telecom, KT, and LG Uplus will provide more than seven million subscribers with unmetered 400 Kbps data after monthly allowances are exhausted. The measure was presented as a consumer-protection obligation tied to recent telecom security incidents, including the SK Telecom data leak.
SK Telecom filed suit with the Seoul Administrative Court to revoke the 135 billion-won penalty one day before the filing deadline. The company is expected to argue that it made major security improvements after the incident and that the fine was unfair.
South Korea's Personal Information Protection Commission imposed a record 135 billion-won fine on SK Telecom over the delayed disclosure and data leak. The decision was made in August 2025 and was described as the agency's largest penalty since its establishment.
After the incident was disclosed, SK Telecom offered free USIM replacements to all users. The disclosure was described as delayed, prompting regulatory scrutiny over the company's handling of the breach.
An April cyberattack compromised SK Telecom servers and exposed universal subscriber identity module (USIM) information. The breach reportedly affected the company's entire subscriber base of about 23 million users.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
4 references tracked. Mallory keeps watching after this page renders.
tomshardware.com
Open sourcekoreatimes.co.kr
Open sourcescworld.com
Open sourcedatabreaches.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.