...

South Korea Fines KT Corp $37.4 Million Over Customer Data Breach

Esther Speak - Senior Reporter at Villpress
3 Min Read

South Korea’s Personal Information Protection Commission (PIPC) has fined KT Corp. 53.9 billion won ($37.4 million) over a major personal data breach that exposed the information of thousands of mobile subscribers, following an investigation into the company’s security practices. The penalty is among the largest imposed under the country’s data protection laws.

According to the regulator, the breach affected the phone numbers and International Mobile Subscriber Identity (IMSI) numbers of 16,647 users after attackers gained access to KT’s wireless network through unauthorised mobile base stations. Authorities said the hackers remained undetected between October 2024 and September 2025, with the breach only coming to light after a customer reported suspicious activity.

The watchdog said the stolen data was later used to carry out unauthorised mobile transactions, resulting in financial losses of approximately 240 million won across 368 victims. Investigators concluded that KT failed to implement adequate security measures to detect and prevent the prolonged intrusion.

In addition to the financial penalty, the PIPC ordered KT to strengthen the security of its wireless network infrastructure and improve its personal data protection framework to prevent similar incidents. The regulator said the case highlighted weaknesses in monitoring systems that allowed attackers to operate within the company’s network for an extended period.

The decision adds to growing regulatory scrutiny of cybersecurity and data privacy in South Korea. Over the past two years, the country’s privacy watchdog has imposed increasingly severe sanctions on companies found to have failed in protecting customer information, reflecting a broader effort to strengthen digital trust as cyberattacks become more sophisticated.

For KT, South Korea’s second largest telecommunications operator, the fine underscores the reputational and financial risks associated with cybersecurity failures. The company will now face the challenge of restoring customer confidence while implementing the corrective measures required by regulators.

The case also serves as a reminder that telecommunications companies remain attractive targets for cybercriminals because of the sensitive customer information they hold. As mobile networks become more integrated with financial services and digital identity systems, regulators are expected to continue tightening oversight of data security across the sector.

Support Villpress Journalism
TAGGED:
Share This Article
Esther Speak - Senior Reporter at Villpress
Senior Reporter
Follow:
Ester Speaks is a senior reporter and newsroom strategist at Villpress, where she shapes Africa-focused business, technology, and policy coverage.  She works at the intersection of journalism, and editorial systems, producing clear, high-impact news that travels globally while staying rooted in African realities.
notification icon

We want to send you notifications for the newest news and updates.

Seraphinite AcceleratorBannerText_Seraphinite Accelerator
Turns on site high speed to be attractive for people and search engines.