'Personal Data Breach' at KTCorporation: What Are the Criteria for the 53.97 Billion Won Fine? [Q&A]
Femtocell Hacking and Personal Information Leak Ruled a 'Serious Breach'
Although actual financial losses occurred, the classification of "extremely serious" was excluded
Taking into account the scale of the leak, the type of information, and compensation measures, among other factors
2024 Malware Infection Cases to Be Handled at a Later Date
[Edaily Reporter An Yu-ri ] KTCorporation(030200), which experienced a femtocell (small-cell base station) hacking incident last year, has been fined 53.979 billion won for violating the Personal Information Protection Act. The Personal Information Protection Commission also voted to file charges against KTCorporation, finding that the company obstructed the investigation by submitting false information during the probe.
Yang Cheong-sam, Secretary-General of the Personal Information Protection Commission, is briefing the media on the 30th at the Seoul Government Complex regarding the results of the investigation and disciplinary actions concerning the personal information leaks at KTCorporation and LGU+. (Photo = Personal Information Protection Commission)
According to the Commission’s investigation, the recent femtocell hacking incident resulted in the leakage of personal information (mobile phone numbers, IMSI, and IMEI) of 16,647 individuals, as well as the hijacking of text messages and calls on the mobile network. This figure was calculated by removing duplicates—such as accounts registered under corporate names and multiple lines—from the 22,227 individuals initially reported by KTCorporation as affected.
A total of 368 victims also suffered unauthorized micro-payment losses amounting to approximately 240 million won. The Personal Information Protection Commission deemed the incident particularly serious given that it resulted in actual financial losses and classified it as a “serious violation.”
This classification is one level below “extremely serious violation” on the severity scale under the Personal Information Protection Act. Last year, SKTelecom(017670)was assessed a fine of approximately 130 billion won for a violation that was deemed an “extremely serious violation” at the time.
In addition, the PIPC decided to refer LG Uplus to law enforcement agencies on charges of obstruction of official duties, as the company had disposed of its servers before the investigation began.
The following is a Q&A summarizing the details of the sanctions against KTCorporation—including the criteria for calculating the fine—based on a briefing by Yang Cheong-sam, Secretary-General of the Personal Information Protection Commission.
Q. What are the criteria for calculating the 53.979 billion won administrative fine and for determining the “severity” of the violation?
When calculating the administrative fine, we use relevant revenue as the basis and impose the fine within the legal cap of 3% of total revenue. Next, we assess the severity of the violation. In KTCorporation’s case, we determined it to be a serious violation.
In KTCorporation’s case, the aspects involving secondary damage were viewed as extremely significant, and there was intense debate among the commissioners regarding this issue. Discussions centered on how to determine the existence of secondary damage, the type and scale of the leaked information, the fact that authentication information was not involved, and how to evaluate that the leaked IMEI numbers and phone numbers were basic information handled by telecommunications carriers.
Criteria for Determining the Severity of Violations of the Enforcement Decree of the Personal Information Protection Act (Photo: Screenshot from the Legal Information Center) The Enforcement Decree of the Personal Information Protection Act stipulates that the criteria and procedures for calculating administrative fines must be determined by comprehensively considering factors such as: △ the severity of the violation; △ efforts to implement security measures such as encryption; △ the scale and relevance of loss, theft, leakage, forgery, alteration, or destruction; △ the impact on data subjects; and △ the extent of the damage.
The Personal Information Protection Commission has established internal criteria for this comprehensive assessment but has not made them public.
Q. Are there any differences in the administrative fine calculation process compared to previous cases, such as that of SKTelecom?
In the case of SKTelecom, the scale of the damage exceeded 20 million people, and the incident was deemed a “very serious violation” in terms of the type and scale of the leaked personal information.
While the commission members viewed the occurrence of secondary harm as a very serious factor throughout the process, the confirmed scale of the leak itself was relatively small compared to other cases. Factors such as the types of leaked information, compensation for damages, and the prompt cooperation in implementing corrective measures were taken into account.
Q. How was the range of relevant revenue calculated?
We comprehensively included both LTE and 5G revenue in the wireless communications revenue figure. Specific figures will be shared later in the resolution document.
Since femtocells are equipment primarily used in LTE, and because it takes a considerable amount of time to expand infrastructure even after the introduction of new 5G services, areas where 5G infrastructure has not yet been expanded continue to use the LTE network concurrently. Therefore, both 5G and LTE services were considered in the revenue calculation.
Q. Does this fine also include the 2024 KTCorporation malware infection incident?
The Commission did not issue a separate ruling regarding this malware infection incident.
KTCorporation first became aware of the malware infection on its servers in March 2024 but failed to report the breach to the government and limited its response to internal measures without conducting a detailed analysis to determine whether personal information had been leaked.
When the Ministry of Science and ICT’s public-private joint investigation team announced its findings, it stated, “While the infection was confirmed, no additional leakage of personal information was identified.” Subsequently, during the course of further investigations, the Personal Information Protection Commission confirmed that an SQL injection attack had occurred on the server at that time and that some personal information had been leaked in the process.
However, since the Personal Information Protection Commission has not yet completed its investigation—and further verification of the facts is expected to proceed through criminal complaints and other means—the exact facts will be confirmed and announced at a later date.
Q. Why did LG Uplus “request an investigation” instead of filing a criminal complaint, unlike KTCorporation?
The Personal Information Protection Commission became aware of the personal information leak detailed in the article “ LG Uplus(032640)” published in August 2025 by the U.S. security magazine *Phrack* and launched an investigation on September 10 of the same year. However, prior to the start of the investigation—on August 12 and August 14, 2024—LG Corp. reinstalled the operating systems (OS) on relevant servers, including the APPM server, and decommissioned them on August 25, 2025.
Since the possibility of concealment or destruction of evidence related to the personal information leak could not be ruled out, the matter was referred to the authorities for investigation.
Under current regulations, sanctions can be imposed for acts such as concealment during an investigation, but there are insufficient provisions for sanctions regarding actions taken before the investigation begins. There is a regulatory loophole where operators may believe it is actually to their advantage to conceal or destroy evidence in advance when an incident occurs. The Personal Information Protection Commission plans to improve the relevant systems in response to this issue.
SAMSUNG SDI CO.,LTD. has returned to a quarterly profit for the first time in seven quarters, driven by expanded sales of high-power batteries, the U.S. Advanced Manufacturing Production Credit (AMPC)…
“Sodium-ion batteries, which are well-suited for the long-duration energy storage system (ESS) market, have completed technical validation with our clients on a scale of hundreds of megawatt-hours (MW…
On July 29, South Korea’s domestic stock market continued to weaken, causing inverse exchange-traded funds (ETFs) tracking the KOSDAQ’s decline to dominate the list of top gainers. More than half of t…