South Korea fines telco giant KT $39 million for customer data breach
AI Summary
South Korea's Personal Information Protection Commission (PIPC) fined KT Corporation approximately $39 million following a data breach that exposed the personal information of over 16,600 subscribers and enabled fraudulent mobile payments. The breach originated from a lost femtocell device that attackers exploited by cloning its authentication certificate, allowing them to intercept cellular traffic including IMSI, IMEI, and SMS authentication codes. Additionally, PIPC discovered that 38 of KT's servers were infected with BPFDoor malware, a stealthy backdoor linked to the China-nexus Red Menshen group, which had gone undetected since March 2024. KT failed to report the malware infection and deleted logs, obstructing the investigation.
AI-extracted · verify before operational use