Back www.bleepingcomputer.com Sk Telecom Says Malware Breach Lasted 3 Years Impacted 27 Million Numbers
SK Telecom is the largest mobile network operator in South Korea, holding roughly half of the national market.
On April 19, 2025, the company detected malware on its networks and responded by isolating the equipment suspected of being hacked.
This breach allowed attackers to steal data that included IMSI, USIM authentication keys, network usage data, and SMS/contacts stored in the SIM.
On May 8, 2025, a government committee investigating the incident declared that the malware infection compromised 25 data types .
An update SK Telecom published yesterday informs that they will soon notify 26.95 million customers that they are impacted by the malware infection, which exposed their sensitive data.
The telecom firm mentions that it identified 25 distinct malware types in 23 compromised servers, so the extent of the breach is far more extensive than initially anticipated.
Simultaneously, a joint public-private investigation team examining SK Telecom's 30,000 Linux servers released a report the initial web shell infection was on June 15, 2022 .
This means that malware went undetected in the company's systems for nearly three years, during which the attackers introduced several payloads across 23 servers.
That investigation claims that 15 of the 23 infected servers contained personal customer information, including 291,831 IMEI numbers, though SK Telecom explicitly denied this in its latest press release.
The investigation team also noted that SK Telecom started logging activity on the impacted servers on December 3, 2024. Therefore, any data exfiltration that may have occurred from June 2022 until then would not have been detected.
"We are technically ensuring that illegal USIM and device changes are completely blocked. However, if any damage does occur despite these efforts, we will take 100% responsibility," announced SK Telecom.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
