South Korea hits KT with $39 million fine after hackers ran a fake mobile tower for 11 months

A lost cellular base station gave attackers a valid certificate, letting them pose as KT's network and drain money from customer phones.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 4 min read
A close-up of a modern smartphone screen showing a generic messaging interface with a blank username field glowing softly, set against a blurred dark-green back
Share

Key points

  • South Korea's Personal Information Protection Commission fined KT Corporation KRW 53.979 billion (about $39 million) for data protection violations.
  • Attackers ran a rogue mobile base station inside KT's network from October 8, 2024 to September 5, 2025, nearly 11 months undetected.
  • Personal data of 16,647 KT subscribers was exposed, and at least 368 people lost a combined KRW 240 million (about $167,400) to fraudulent mobile payments.
  • Investigators found BPFDoor malware, linked to the China-nexus Red Menshen espionage group, on 38 KT servers dating back to March 2024, which KT never disclosed.
  • KT deleted server logs during its internal checks, so regulators cannot rule out further data theft.

South Korea's privacy regulator has fined KT Corporation, the country's largest telecoms company, KRW 53.979 billion (around $39 million) after hackers spent almost a year inside its mobile network pretending to be part of it.

The Personal Information Protection Commission announced the penalty this week. It covers a breach running from October 8, 2024 until September 5, 2025. For context on how aggressively the PIPC is now wielding its powers, we reported in June that the regulator levied a ₩624.6 billion penalty against Coupang over a 37-million-record breach tied to access-control failures.

KT serves more than 13.5 million mobile customers and carries traffic for 90% of South Korea's fixed-line subscribers. Not a soft target.

How did the hackers get in?

They used a piece of KT's own equipment. A femtocell, a small cellular base station used to boost indoor signal, had gone missing. Inside it was a valid digital certificate, the cryptographic credential that tells KT's network "this box is one of ours".

The attackers pulled that certificate and installed it on a device they built themselves. KT's core network greeted it like a trusted neighbour. Nearby phones connected to the fake tower instead of a real one.

From there, the attackers collected mobile phone numbers, IMSI codes (the unique identifier on a SIM card) and IMEI codes (the unique identifier of the handset itself). They also grabbed the one-time codes sent by SMS and by automated voice call to approve small mobile payments. That's how 368 customers ended up paying for things they never bought.

Why did nobody notice for 11 months?

Because the checks that should have caught it weren't in place. The Commission says KT let femtocell certificates stay valid for ten years, didn't restrict which IP addresses were allowed to connect, and left a route open that bypassed the server meant to manage these devices.

Here's the honest identity read: this was authentication working exactly as designed, and authorisation doing nothing useful. The certificate proved the device was "a KT femtocell". Nothing then asked whether it was in an expected location or on an expected network path. Long-lived certificates without revocation checks are a known weak spot. Multi-factor authentication wouldn't have helped here, because the device itself was the identity.

What is the BPFDoor part about?

Separately, regulators found that 38 KT servers had been infected with malware since March 2024, including a Linux and Solaris backdoor called BPFDoor. PwC has publicly linked BPFDoor's use to Red Menshen, a China-nexus group that targets telecoms operators.

BPFDoor uses Berkeley Packet Filter technology to watch network traffic quietly, waking only when it receives a specially crafted "magic" packet. It opens no listening ports, so standard firewall scans miss it entirely.

KT knew about this infection in March 2024 and told neither the authorities nor its customers. During later inspections KT deleted logs from some affected servers, which means investigators can no longer say for certain whether additional customer data was taken. The Commission notes that LG U+, a rival telco, took a comparable approach after its own breach, reinstalling operating systems before regulators could examine the machines.

Should you worry if you're a KT customer?

Check your mobile bill for small charges you don't recognise, particularly micro-payments approved by SMS code, and contact KT if anything looks off. If your handset has been behaving oddly, restart it to force a fresh connection to a legitimate tower.

As part of the ruling, KT must tighten controls on its femtocells, give its Chief Privacy Officer real authority, and extend its ISMS-P security certification to cover the mobile network. The Commission also plans to push for tougher laws penalising companies that destroy evidence during investigations.

The detail that keeps this story uncomfortable is the log deletion. The fine accounts for what regulators could prove. What they couldn't prove, because KT wiped the record, may be the more important number.

© 2026 Threat Vectr