South Korea’s Personal Information Protection Commission fined KT Corporation KRW 53.979 billion (about $39 million) after finding major security failures tied to a long-running compromise of its mobile network. Investigators said attackers used a lost KT femtocell, extracted its valid authentication certificate, and loaded it onto a rogue device to impersonate legitimate network equipment, intercept subscriber traffic, and capture data including phone numbers and authentication codes. The intrusion ran from October 8, 2024, to September 5, 2025, exposing the personal information of 16,647 subscribers and enabling fraudulent mobile micropayments totaling KRW 240 million that affected at least 368 customers.
The regulator said KT’s controls were inadequate, citing overly long-lived femtocell certificates and missing IP address restrictions that helped enable the abuse. In a separate finding, the commission said 38 KT IT service network servers were infected with BPFDoor malware in March 2024, and alleged that KT failed to report the incident promptly and deleted logs from some compromised systems, obstructing the investigation. Alongside the fine, authorities ordered KT to strengthen femtocell and telecom equipment security, improve privacy governance, expand ISMS-P certification coverage across mobile network systems, and are considering legislative changes related to concealment of evidence.

See the reporting duties and controls this puts on the clock.
6 events from the most recent confirmed update back to the earliest known activity.
KT submitted its initial data breach notification on September 11, 2025. The company initially reported that data belonging to about 5,500 customers had been exposed.
PIPC opened an investigation on September 10, 2025, after users reported fraudulent micropayments. The probe later examined both the subscriber-data breach and KT's handling of earlier malware infections.
The internal KT network compromise lasted until September 5, 2025. PIPC later said the incident exposed 16,647 subscribers' personal information and enabled KRW 240 million in fraudulent mobile payments affecting at least 368 people.
On October 8, 2024, attackers began abusing a lost KT femtocell's valid authentication certificate on a rogue device to impersonate legitimate network equipment and intercept subscriber traffic. The compromise ultimately enabled theft of telecom identifiers and authentication data used in fraudulent mobile micropayments.
Investigators later found that 38 KT IT service network servers had been compromised by malware, including BPFDoor, in March 2024. PIPC alleged KT knew of the infection, did not promptly report it, and deleted logs from some compromised systems, hindering the investigation.
South Korea's Personal Information Protection Commission fined KT Corporation KRW 53.979 billion over data protection violations tied to the breach and ordered the company to strengthen femtocell and telecom equipment security, reinforce privacy governance, and expand ISMS-P certification coverage. PIPC also said it would pursue legislative changes to impose stronger penalties for concealing or destroying evidence during investigations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.