Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Korea’s Largest Telco KT Fined $39m After Femtocell Campaign

August 3, 2026

Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack

August 3, 2026

Midnight Blizzard Targets Travelers via Captive Portals

August 3, 2026
Facebook X (Twitter) Instagram
Monday, August 3
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Korea’s Largest Telco KT Fined $39m After Femtocell Campaign
News

Korea’s Largest Telco KT Fined $39m After Femtocell Campaign

Team-CWDBy Team-CWDAugust 3, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


South Korea’s largest telco has been handed a multimillion-dollar fine by the country’s data protection regulator after serious security failings enabled hackers to defraud its customers.

KT, formerly Korea Telecom, serves over 13 million mobile subscribers, the majority of the domestic market, and nearly half of the country’s high-speed internet users.

However, Seoul’s Personal Information Protection Commission (PIPC) opened an investigation into the company in September 2025 after reports that customers were impacted by fraudulent micropayments.

The firm subsequently notified the PIPC about a breach of personally identifiable information (PII).

Read more on South Korean breaches: South Korean Police Raid Coupang Over Data Breach as CEO Resigns

The PIPC traced the fraud back to theft of a femtocell: a small, low-powered cellular base station usually designed for home or small business use.

“The hacker extracted a certificate from a lost KT femtocell, embedded it into a self-made femtocell, and then accessed the KT mobile network. Subsequently, the hacker induced user terminals to pass through the hacker’s femtocell to intercept transmission and reception information between the terminals and the internal network,” the PIPC explained.

“By combining this information with additionally obtained personal information (name, gender, date of birth), the hacker requested a mobile phone micropayment and then stole ARS and SMS messages containing payment authentication codes, successfully making unauthorized micropayments.”

In total, mobile phone number, subscriber identification number (IMSI), and device identification number (IMEI) details on 16,647 users were compromised in this way. Some 368 customers were defrauded to the tune of 240 million won ($175,000) via unauthorized micropayments.

A Mandate to Improve Security Posture

The regulator ruled that the incident stemmed from a lack of “basic access control management” for KT’s internal network, which allowed the threat actors to connect their rogue femtocell.

“KT’s femtocell management system was generally inadequate, allowing unauthorized femtocells to easily access KT’s internal network,” the PIPC said.

“KT had set the validity period of femtocell certificates issued for internal network access to a long period of 10 years and did not restrict the IP addresses of femtocells accessing the internal network, allowing access from other companies or overseas IP addresses.”

The regulator also noted that individuals were able to bypass the femtocell management server, and that insufficient detection and response capabilities meant the breach went unnoticed for 11 months.

The PIPC mandated the strengthening of security posture through vulnerability checks for wireless communication equipment, and improved governance.

PIPC Uncovers Backdoor Malware

There was more bad news for KT after investigators found evidence that 38 internal servers had been infected with various strains of malware including the BPFDoor backdoor.

“Upon investigation, it was confirmed that in March 2024, a hacker infiltrated the network by exploiting a vulnerability on the KT Roaming Rental Service website and infected multiple servers by uploading a malicious code file,” the PIPC said.

“There were indications that the hacker viewed and leaked the personal information (name, phone number, account) of KT employees and some employees of partner companies through an SQL injection attack* on the Roaming Rental Service administrator page.”

The regulator was unable to determine if the breach scope extended further due to the absence of network logs.

KT didn’t report the breach to the government at the time, instead choosing to deal with it internally without conducting a detailed analysis into whether PII had been leaked.

The PIPC has subsequently filed a complaint over this, as well as the deletion of server logs, submission of false data, retraction of statements by KT during its investigation.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleClaude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack
Team-CWD
  • Website

Related Posts

News

Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack

August 3, 2026
News

Midnight Blizzard Targets Travelers via Captive Portals

August 3, 2026
News

Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process

August 3, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA

July 11, 20268 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

2025’s most common passwords were as predictable as ever

January 21, 2026

What are brushing scams and how do I stay safe?

December 24, 2025

Scams target soccer fans with fake World Cup tickets, merchandise

May 22, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.