Skip to content
KT Concealed Malware Discovery... Omitted Reports to Telecom Authorities and CEO

KT Concealed Malware Discovery... Omitted Reports to Telecom Authorities and CEO

Mk.Co.Kr November 21, 2025

KT Corporation (KT) has come under scrutiny for allegedly concealing evidence that a server storing personal information was infected with the BPFDoor malware last year. It was revealed that C-level executives responsible for security and technology handled the matter internally without reporting it to telecom authorities or the CEO.

On the 21st, the office of Choi Min Hee, Chairperson of the Science, ICT, Broadcasting, and Communications Committee of the National Assembly of South Korea, released documents detailing KT's timeline for detecting the cyber breach and its internal decision-making process.

On April 11 last year, Deputy General Manager A of KT's Information Security Red Team emailed Team Leader B, his direct supervisor, reporting that 'malware has been running on the corporate mobile server since March 19.' He also shared this information with Deputy General Manager C from the Security Risk Response Team.

Deputy General Manager C reported to Sangryong Moon, then Chief Information Security Officer (CISO), and Taeseon Hwang, the current CISO, stating that 'emergency vulnerability measures and individual applications are underway by each business division.' On April 18, he urgently requested the server manufacturer to conduct a manual antivirus scan and analysis, but this information did not reach top management.

KT explained, 'Sangryong Moon and Mohyeoncheol verbally briefed Phil Oh, then Executive Vice President in charge of information security, during a casual tea time, mentioning that malware had been detected.' However, KT added, 'Phil Oh perceived it as a routine security update and did not recognize the seriousness of the situation.'

Subsequent actions were also taken based on internal judgment. Starting May 13, KT began inspecting for script-based malware. On June 11, the inspection was expanded to all company servers and continued through July 31. The script-based inspection involved applying detection scripts across servers, enabling simultaneous automated checks on numerous systems.

During this period, KT did not hold a single official meeting to whether to report the cyber incident. KT explained, 'While focusing on initial analysis and containment of an unprecedented type of malware, we did not fully consider our reporting obligations.'

Choi Min Hee, Chairperson of the Science, ICT, Broadcasting, and Communications Committee of the National Assembly of South Korea, emphasized, 'This case clearly demonstrates the collapse of the information security management system at one of the nation’s leading telecommunications operators.' She urged, 'The Ministry of Science and ICT (MSIT) must use every available measure—including waiving penalties, suspending business, or requesting an investigation—to hold those responsible accountable and correct the situation. KT must also undertake a comprehensive overhaul on its own.'

This article has been translated by GripLabs Mingo AI.

Extracted Entities

Attack Types (1)

Companies (1)

Countries (1)

Industries (1)

Malware (1)