www.koreaherald.com KT Corp Fined ₩53.97 Billion for Femtocell Breach and Evidence Tampering
Article Content
- •KT Corp fined ₩53.97 billion for inadequate femtocell security and evidence tampering.
- •Attackers exploited a lost femtocell to gain unauthorized access to KT's network.
- •368 users experienced financial losses due to unauthorized mobile payments linked to the breach.
KT Corp was fined ₩53.97 billion (approximately $37.6 million) by South Korea's privacy regulator for failing to secure its femtocell system, allowing unauthorized access to its mobile network. The breach began in August 2024 when attackers exploited a lost femtocell, using a shared plaintext authentication certificate to connect counterfeit devices. This led to unauthorized mobile payments affecting 368 users, resulting in financial losses of 240 million won. The Personal Information Protection Commission (PIPC) found that KT deleted access logs from ten infected servers during the investigation, indicating an attempt to conceal the breach. Both KT and LG Uplus are referred for criminal investigation, marking a significant escalation in regulatory enforcement. KT has committed to rebuilding its security systems and compensating affected customers.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (8)
Following this threat?
Track Earth Bluecrow, BPFDoor and Coupang in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Iranian State Actors Deploy CHOSEN BRICK Spyware Against Dissidents On September 15, 2026, the UK, US, and Netherlands issued a joint advisory regarding a spyware campaign attributed to Iranian state actors targeting dissidents, activists, and journalists. The malware, known as CHOSEN BRICK, is delivered through spear-phishing attacks on messaging platforms like WhatsApp and Telegram.…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…