Internet

'Femtocell Hacking': KTCorporation Fined 53.9 Billion Won for Personal Information Leak

Personal Information Leaked and Financial Losses Result from Femtocell Hacking Failure to Comply with Safety Measures… KTCorporation Fined 53.979 Billion Won Mismanagement of Certificates and Access Controls Cited as Cause of Incident Personal Information Protection Commission: "Taking Action Against Allegations of Systematic Cover-Up, Including Log Deletion"

An Yu-ri
2026-07-30 10:21:51
[Edaily Reporter An Yu-ri ] KTCorporation(030200), which experienced a femtocell (small-cell base station) hacking incident last year, has been fined 53.979 billion won for violating the Personal Information Protection Act.

A view of KTCorporation’s headquarters in Jongno-gu, Seoul, on November 4, 2025. (Newsis)

The Personal Information Protection Commission determined that KTCorporation obstructed the investigation—including by submitting false documents during the probe—and voted to file charges against the company.

The Personal Information Protection Commission announced on the 30th that it held its 15th plenary meeting on the 29th and imposed a fine of 53.979 billion won on KTCorporation—which suffered a personal information leak last year due to a femtocell hack—while also issuing a corrective order and recommendations for improvement.

The investigation confirmed that negligence in managing access controls to core mobile communication networks and systems via femtocells led to the leakage of personal information (mobile phone numbers, IMSI, IMEI) of 16,647 individuals, as well as the hijacking of text messages and calls on the mobile network. This figure represents the actual number of data subjects after removing duplicates—such as corporate accounts and multiple lines—from the initial 22,227 people who reported the breach.

A total of 368 victims also suffered unauthorized micro-payments amounting to approximately 240 million won.

The Personal Information Protection Commission deemed the incident extremely serious, noting that this was a case where personal information leaked through a femtocell hack last year resulted in actual financial damage.

It also determined that KTCorporation had violated its obligation under the Personal Information Protection Act to implement security measures to prevent unauthorized access and security breaches via information and communications networks.

The investigation revealed that the hacker extracted a certificate from a lost KTCorporation femtocell, installed it on a self-made femtocell, and used it to access KTCorporation’s mobile network. The hacker then redirected users’ devices to route through the hacker’s femtocell, intercepting data transmitted between the devices and the internal network. By combining this data with additional personal information obtained (name, gender, date of birth), the hacker requested small-amount mobile payments, intercepted the automated voice response (ARS) and SMS messages containing payment authentication codes, and successfully made unauthorized small-amount payments.

The Personal Information Protection Commission viewed this incident as extremely serious, noting that it went beyond a simple leak of personal information and was a case where personal information leaked via a femtocell led to actual financial damage.

Personal Information Protection Commission
: “KTCorporation Neglected Management and Control of Femtocells… Violated Obligation to Implement Security Measures”
Song Kyung-hee, Chairperson of the Personal Information Protection Commission, strikes the gavel during the 15th plenary session held at the Seoul Government Complex on the 29th. (Photo: Personal Information Protection Commission)


The commission determined that the incident occurred due to KTCorporation’s negligence in managing basic access controls for its internal network and that KTCorporation violated its obligation to implement security measures as mandated by the Personal Information Protection Act.

A femtocell is a small base station that KTCorporation has introduced and operated since November 2016 to eliminate dead zones with weak wireless signals. KTCorporation installation technicians install them directly for customers using KTCorporation Internet, and they are not sold to users.
KTCorporation is responsible for managing network access authorization, authentication systems, internal network access permissions, security controls, and operations related to the femtocells’ access to KTCorporation’s wireless network.

The Personal Information Protection Commission determined that KTCorporation is the de facto operator of the femtocells and that KTCorporation holds the authority to manage and control the user authentication process required for femtocell access to the mobile network and service provision, as well as the transmission of personal information during this process.

At the time of the incident, KTCorporation’s femtocell management system was generally inadequate, allowing unauthorized femtocells to easily access KTCorporation’s internal network. According to the PIPC, KTCorporation set the validity period of the femtocell certificates issued for internal network access to a long term of 10 years and operated the system without restricting the IP addresses of femtocells accessing the internal network, thereby allowing access even from third-party or overseas IP addresses.

Furthermore, there were routes that bypassed the femtocell management server, and since KT did not manage the Cell ID—the identifier assigned when a femtocell connects to the core network—the system operated without a detection and response mechanism for abnormal access attempts using unauthorized Cell IDs.

As a result, hackers were able to access KTCorporation’s internal network for approximately 11 months, from October 8, 2024, to September 5, 2025, and KTCorporation failed to detect these abnormal access activities. It was only after secondary damages, such as unauthorized micro-payments, occurred and numerous customer complaints were received that the company was able to identify the abnormal access.
Failure to Report Malware Infection, Log Deletion… “Evidence of Systematic Cover-Up”
Although KTCorporation first became aware of malware
infection
on its servers in March 2024, it did not report the breach to the government and limited its response to internal measures without conducting a detailed analysis of whether personal information had been leaked. At the time, many of the infected servers included systems that processed users’ personal information.

Furthermore, evidence was found that KTCorporation systematically covered up the breach—including deleting logs from some of the compromised servers (10 units)—during a government-led comprehensive investigation following the SKTelecom incident.

The Personal Information Protection Commission also stated that KTCorporation initially made a false statement during the investigation, claiming it had no preserved data regarding the infected servers; however, once the Commission uncovered evidence through digital forensics that the relevant logs had been deleted prior to the start of the investigation, KTCorporation retracted its statement and belatedly submitted logs that had been stored separately, thereby delaying the investigation.

To prevent a recurrence of such behavior, the PIPC plans to take strict measures against acts that obstruct the Commission’s investigation by concealing or destroying relevant evidence to evade investigation or sanctions, and to pursue institutional reforms to enhance the effectiveness of its investigations.

Song Kyung-hee, Chairperson of the Personal Information Protection Commission, stated, “We will improve the system so that concealing or downplaying data in the event of an incident results in significant disadvantages for companies, thereby instilling a mindset throughout the industry that transparent disclosure is the most reasonable choice.”

KTCorporation stated, “We take the sanctions very seriously and once again bow our heads in deep apology for causing great concern and anxiety to our customers and the public due to the recent incident.” The company added, “We are completely overhauling our entire personal information protection system from the ground up, and we will devote all our resources to preventing a recurrence of this incident and restoring customer trust by expanding security investments and strengthening company-wide personal information protection capabilities.”

Economy

Corporation

IT·Science

Economy

“Chinese ESS Companies Face Limited Expansion in U.S. Market… Strengthening Local Production and SI Capabilities”—LG Energy Solution Conference Call

“Due to U.S. regulations regarding Foreign Entities of Concern (FEOC), it is difficult for Chinese companies to secure benefits such as the Advanced Manufacturing Production Credit (AMPC) or the Inves…
2026-07-30 11:39:03

Corporation

“Long-Cycle Sodium Battery Technology for ESS Verified… Discussions on Commercialization Underway”—LG Energy Solution Conference Call

“Sodium-ion batteries, which are well-suited for the long-duration energy storage system (ESS) market, have completed technical validation with our clients on a scale of hundreds of megawatt-hours (MW…
2026-07-30 11:40:56

IT·Science

'Posting a Loss Amid the Semiconductor Boom': Samsung MX Seeks Turnaround with Z8 and Hyper-Personalized AI (Comprehensive Report 2)

On the 28th, as pre-orders for SamsungElectronics’ Galaxy Z8 series began, citizens were seen examining new products such as the Galaxy Z Fold 8 and Flip 8 at Samsung Gangnam in Seocho-gu, Seoul. (Pho…
2026-07-30 11:24:56