South Korea fined telecom provider KT after attackers spent about 11 months inside parts of its network, exposing subscriber data and helping drive fraudulent mobile micropayments. Regulators said a lost femtocell base station with a still-valid certificate was turned into a rogue device that intercepted phone numbers, IMSI and IMEI identifiers, and SMS and phone-call authentication codes; the probe also found 38 KT IT servers had been infected with BPFDoor malware and that KT did not properly report that incident.
Why it matters: KT customers were exposed to identity and payment fraud, and the regulator says the full impact may be unknowable because logs were deleted. Telecom operators should review certificate lifetimes, rogue base-station controls, logging, and breach-reporting practices, while affected users should monitor mobile billing and account activity.
Bill Toulas
2026.07.30
100% relevant
This article establishes a distinct story centered on PIPC's enforcement against KT for a specific 2024-2025 breach involving a rogue femtocell and separate BPFDoor-compromised internal servers.
← Back to all stories