South Korea hits KT with $39 million fine after hackers ran a fake mobile tower for 11 months

A lost cellular base station gave attackers a valid certificate, letting them pose as KT's network and drain money from customer phones.

ThreatVectr Newsdesk· 4 min read
A close-up of a modern smartphone screen showing a generic messaging interface with a blank username field glowing softly, set against a blurred dark-green back
Share

Key points

  • South Korea's Personal Information Protection Commission fined KT Corporation KRW 53.979 billion (about $39 million) on data protection violations.
  • Attackers ran a rogue mobile base station inside KT's network from October 8, 2024 to September 5, 2025, nearly 11 months undetected.
  • Personal data of 16,647 KT subscribers was exposed, and at least 368 people lost a combined KRW 240 million (about $167,400) to fraudulent mobile payments.
  • Investigators also found BPFDoor malware, linked to a China-nexus spying group, on 38 KT servers dating back to March 2024, which KT never disclosed.
  • KT deleted server logs during its internal checks, so regulators say they cannot rule out further data theft.

South Korea's privacy regulator has fined KT Corporation, the country's largest telecoms company, KRW 53.979 billion (around $39 million) after hackers spent almost a year sitting inside its mobile network pretending to be part of it.

The Personal Information Protection Commission announced the penalty this week. It covers a breach that ran from October 8, 2024 until September 5, 2025.

KT serves more than 13.5 million mobile customers and carries 90% of South Korea's fixed-line traffic. So this is not a small target.

How did the hackers get in?

They used a piece of KT's own equipment. A small cellular base station called a femtocell, essentially a mini mobile tower used to boost signal indoors, had gone missing. Inside it was a valid digital certificate, the cryptographic ID card that tells KT's network "this box is one of ours".

The attackers pulled that certificate out and installed it on a device they built themselves. Once switched on, KT's core network greeted it like a trusted neighbour. Nearby phones connected to the fake tower instead of a real one.

From that vantage point the attackers scooped up mobile phone numbers, along with IMSI and IMEI numbers, which are the unique IDs of the SIM card and the handset. They also grabbed the one-time codes sent by SMS and by automated voice call, the codes used to approve small mobile payments in South Korea. That is how 368 customers ended up paying for things they never bought.

Why did nobody notice for 11 months?

Because the checks that should have caught it were not in place. The Commission says KT let femtocell certificates stay valid for a full ten years, did not restrict which internet addresses were allowed to connect, and left a route open that bypassed the server meant to manage these devices.

Here is the honest identity read: this was authentication working exactly as designed, and authorisation doing nothing useful. The certificate proved the device was "a KT femtocell". Nothing then asked whether it was one of KT's actual femtocells, in an expected location, on an expected network path. Long-lived certificates without revocation checks or context-aware access are a known weak spot, and multi-factor authentication would not have helped here because the device itself was the identity.

What is the BPFDoor part about?

Separately, regulators found that 38 KT servers had been infected with malware, including a stealthy Linux backdoor called BPFDoor, since March 2024. First reported by BleepingComputer, the finding is significant because BPFDoor has been publicly tied to a China-linked spying group known as Red Menshen that targets telecoms.

BPFDoor hides by watching network traffic quietly and only waking up when it sees a specially crafted "magic" packet. It does not open any listening ports, so standard firewall checks miss it.

The Commission says KT knew about this infection in March 2024 and did not tell the authorities or its customers. Worse, during later inspections KT deleted logs from some of the affected servers, which means investigators can no longer say for certain whether more customer data was stolen. A rival telco, LG U+, took a similar tack in an earlier incident, reinstalling operating systems and scrapping servers before regulators could examine them.

What should KT customers do?

Check your mobile bill for small charges you do not recognise, especially micro-payments approved by SMS code, and contact KT if anything looks off. If your handset has been behaving oddly, restart it so it reconnects to a fresh tower.

As part of the ruling, KT must tighten controls on its femtocells, give its Chief Privacy Officer real authority, and extend its ISMS-P security certification to cover the mobile network. The Commission also plans to push for tougher laws against companies that hide or destroy evidence during investigations.

© 2026 Threat Vectr