The Personal Information Protection Commission imposed about 54 billion won in penalty surcharge on KT for causing customer data leaks and unauthorized small mobile payments due to poor femtocell management.
The Personal Information Protection Commission said on the 30th that it held its 15th plenary meeting on the 29th and decided to impose a 53.979 billion won penalty surcharge on KT for violating the Personal Information Protection Act, along with a corrective order, improvement recommendation, disclosure, and a disclosure order.
It also decided to file a complaint over acts that obstructed the probe, including submitting false materials during the investigation of the malware infection incident, and voted to request an investigation into LG Uplus for destroying evidence by scrapping servers before the investigation began.
According to the Personal Information Protection Commission, a hacker extracted a certificate from a lost KT femtocell and embedded it into a self-made femtocell to attempt exfiltration. A femtocell is a small base station installed in homes, offices, or underground areas with weak wireless signals to improve wireless communication quality. The hacker accessed KT's mobile network for about a year from Oct. 2024 to September last year using the self-made femtocell.
In the process, the hacker induced user devices to route through the illegal femtocell and intercepted information exchanged between the devices and the internal network. Combined with separately obtained personal information such as users' names, gender, and dates of birth, it was found that the hacker attempted small mobile payments.
As a result, personal information of a total of 16,647 KT users, including budget phone subscribers, was leaked, and 368 people suffered unauthorized small mobile payment losses totaling about 240 million won. Earlier, the government-private joint investigation team at the Ministry of Science and ICT released the leak size as 22,227 cases, but the Personal Information Protection Commission explained it calculated the figure by excluding duplicates such as corporate and multi-line accounts.
◇Personal Information Protection Commission: "KT neglected internal network access controls… other carriers and overseas IPs could also connect"
The Personal Information Protection Commission judged that the incident occurred because KT neglected basic access control to its internal network while managing and operating femtocells.
Personal data processing systems on KT's internal network, such as the Home Subscriber Server (HSS), authenticate subscribers and devices using mobile phone numbers, International Mobile Subscriber Identity (IMSI), and International Mobile Equipment Identity (IMEI). Because devices in coverage shadow areas access the internal network through femtocells, only authorized femtocells should be allowed internal network access, the Personal Information Protection Commission said.
However, at the time of the incident, KT did not restrict the internet protocol (IP) addresses of femtocells connecting to the internal network, allowing access to KT's internal network via other carriers' or overseas IPs. It was also confirmed that a path existed that bypassed the femtocell management server.
The Personal Information Protection Commission said it calculated the penalty surcharge based on 5G and LTE revenue from KT's mobile services where unauthorized small payments occurred, and determined the final amount after comprehensively considering the severity and duration of the violation, whether corrective action was taken, and efforts to remedy the damage.
◇KT failed to report malware infection despite knowing… "log deletion and false statements"
The Personal Information Protection Commission decided to file a complaint with investigative authorities, saying KT obstructed its investigation into the malware infection incident. During the probe into the femtocell case, the Personal Information Protection Commission found that in March 2024, 38 servers on KT's IT service network were hacked and infected with multiple types of malware, including "BPFDoor."
It was found that the hacker exploited a security vulnerability on KT's roaming rental service website to penetrate the internal network and upload malware files, infecting numerous servers. On the roaming rental service admin page, indications were also found of SQL injection attacks used to view and leak some KT employees' and partner staff's names, phone numbers, and account information.
KT identified the malware infection on its servers in March 2024 but did not report the breach to the government. It was also confirmed that the company systematically concealed the breach, including by deleting logs on 10 compromised servers.
In addition, KT initially said during the Personal Information Protection Commission's investigation that it had no preserved materials related to the infected servers, but after the commission confirmed through digital forensics that relevant logs had been deleted before the probe began, KT reversed its position and submitted logs that had been stored separately.
◇"LG Uplus reinstalled and scrapped servers before probe… investigation requested for obstruction of official duties"
The Personal Information Protection Commission decided to request an investigation into LG Uplus on suspicion of obstructing official duties, saying the company made it difficult to verify facts by reinstalling or scrapping servers related to the suspected data leak before the probe began.
The Personal Information Protection Commission became aware of the suspected LG Uplus personal data leak published in the U.S. security magazine "Phrack" in August last year and launched an investigation on Sept. 10 of the same year. During the investigation, a text file containing names and accounts of LG Uplus employees and partner staff was verified as information actually held and managed by LG Uplus in its Application Password Portal Management (APPM) system.
However, before the Personal Information Protection Commission began its investigation, on Aug. 12 and 14 last year, LG Uplus reinstalled the operating systems (OS) of related servers, including the APPM server, and on the 25th of the same month, scrapped some servers.
Meanwhile, the Personal Information Protection Commission will push to improve the system to prevent businesses from hiding or destroying evidence related to data leaks to evade investigations and sanctions. First, it plans to establish provisions allowing criminal punishment of businesses that hide or destroy materials before an investigation begins.
It will also pursue a system to impose a penalty surcharge of up to 3% of total sales on businesses that hide or destroy evidence, and to pay whistleblower rewards to those who report such conduct by businesses and thereby contribute to the investigation and disposition.
In addition, for businesses that do not cooperate with investigations or fail to comply with corrective orders, a compliance order penalty of 0.3% of daily sales will be imposed, and the Personal Information Protection Act will be amended to allow the Personal Information Protection Commission to issue data preservation orders so that related materials cannot be deleted or altered when a personal data breach occurs.
Song Gyeong-hee, Chairperson of the Personal Information Protection Commission, said, "This action should serve as an opportunity to further strengthen security capabilities across the telecom industry, which provides services essential to people's daily lives."