South Korea’s privacy regulator has fined wireless carrier KT Corp. 53.9 billion won (about $37.4 million) after a major data breach exposed the personal information of more than 16,000 mobile users and led to unauthorized financial transactions.
The country’s Personal Information Protection Commission (PIPC) announced the penalty on Thursday, saying the breach was caused by unauthorized mobile base stations that gained access to KT’s wireless network. Along with the fine, the regulator ordered the telecom company to strengthen the security of its network equipment and improve its personal data protection measures.
According to the commission, the breach affected the phone numbers and mobile device identification numbers of 16,647 users. Attackers later used the stolen information to carry out unauthorized mobile payment transactions, causing total losses of 240 million won across 368 victims.
Investigators said the attackers were able to access KT’s wireless network from October 8, 2024, until September 5, 2025, without being detected. The company reportedly discovered the intrusion only after receiving a complaint from one of its users.
The investigation also highlighted weaknesses in KT’s management of femtocells—small, low-power cellular base stations commonly used in homes and small businesses to improve mobile coverage. KT outsources the installation and management of these devices, and the company acknowledged that security controls were inadequate.
During a parliamentary hearing, KT CEO Kim Young-shub admitted the company found numerous vulnerabilities after reviewing its femtocell management following the incident. He said KT has since introduced measures to prevent unauthorized femtocells from connecting to its network.
KT previously disclosed that unregistered femtocells connected to its network in late August, allowing attackers to access the personal data of hundreds of users. Lawmakers also criticized the company’s initial investigation for focusing only on breaches involving its automated response system (ARS), prompting KT to expand its review to cover all authentication data.
The case marks one of South Korea’s largest privacy enforcement actions against a telecommunications provider and underscores the growing cybersecurity risks facing mobile network operators as attackers increasingly target network infrastructure rather than traditional IT systems.





