Skip to content
The True Face of the Telecom Powerhouse Revealed: KT Exempted from Penalties, LG ...

The True Face of the Telecom Powerhouse Revealed: KT Exempted from Penalties, LG ...

Mk.Co.Kr December 29, 2025

On the 29th, the Ministry of Science and ICT (MSIT) announced the final results of the joint public-private investigation into the KT breach. A comprehensive server inspection and forensic analysis found that, out of 33,000 servers, 94 were infected with 103 types of malware, including BPFDoor and Rootkit.

Analysis showed that the malware infiltrated the servers during file uploads on internet-connected systems starting in April 2022. BPFDoor is a sophisticated malware that bypasses security equipment to create backdoors, while Rootkit manipulates the operating system to conceal malicious files. The advanced intrusion methods made detection difficult.

It was also discovered that unauthorized Femtocell devices contained the certificates and IP addresses needed to access the KT network. Since the manufacturer’s certificate for Femtocell devices supplied to KT was identical, simply copying it allowed access to the KT network even with non-genuine devices. The certificate validity period was also as long as ten years. During the communication process connecting the device to the core network, encryption was disabled by the unauthorized Femtocell, making it possible to intercept authentication information used for payments, such as ARS (phone authentication) and SMS (text authentication).

MSIT concluded that KT failed to fulfill its contractual obligation to provide secure services, citing poor Femtocell management and encryption configuration issues, and thus determined that penalty exemptions under the terms and conditions were justified. The ministry also demanded improvements, including regular changes to authentication server IPs, expanded firewalls, and enhanced authority for the Chief Information Security Officer (CISO). MSIT plans to impose a fine on KT in accordance with the Act on Promotion of Information and Communications Network Utilization and Information Protection.

A KT official stated, "We take the investigation results very seriously," adding, "We will promptly inform customers once decisions regarding penalty exemptions, compensation, and information security innovation measures are finalized."

LG Uplus Corp. was also not immune to hacking issues. Previously, the Korea Internet & Security Agency (KISA) received an anonymous tip-off regarding a data leak at LG Uplus Corp. The investigation team confirmed that the list of servers related to the Automated Process Policy Management (APPM) access control solution, account information, and employee names had been leaked.

However, the main servers suspected as the source of the leak—including APPM and key partner servers—were damaged, making it difficult to determine the exact intrusion route or confirm additional damage. MSIT referred LG Uplus Corp. to law enforcement for obstruction of official duties, citing the submission of false documents, destruction of potential evidence servers, and reinstallation of operating systems, all of which hindered the investigation.

An MSIT official stated, "We will push to amend the Act on Promotion of Information and Communications Network Utilization and Information Protection to impose stricter sanctions for unreported or concealed breaches, including those involving SK Telecom Co., Ltd., KT, and LG Uplus Corp." The official also emphasized, "We will simultaneously pursue institutional improvements to enhance backbone network security and strengthen information protection capabilities for the AI era."

This article has been translated by GripLabs Mingo AI.

Extracted Entities

Attack Types (2)

Companies (1)

Countries (1)

Malware (1)

Platforms (1)