Security News

Cybersecurity news aggregator

MEDIUM Attacks SC Media

KT Corporation fined $39 million for 11-month data breach

  • What: Data breach at KT Corporation exposed subscriber information
  • Impact: 16,647 users had personal data compromised over 11 months
Read Full Article →

Breach KT Corporation fined $39 million for 11-month data breach July 31, 2026 Share By SC Staff (Adobe Stock) South Korea's Personal Information Protection Commission (PIPC) has fined KT Corporation, the country's largest telecommunications operator, KRW 53.979 billion (approximately $39 million) for significant data protection violations. The penalty stems from an internal network compromise that allowed attackers to access subscriber data for nearly 11 months, with further coverage provided by Bleeping Computer. The breach, which lasted from October 8, 2024, to September 5, 2025, exposed the personal information of 16,647 KT subscribers. Attackers exploited a lost KT femtocell, a small cellular base station, by retrieving its authentication certificate. They then used this certificate on a rogue device to intercept cellular traffic, including phone numbers and authentication codes, leading to fraudulent mobile payments totaling KRW 240 million for at least 368 customers. The PIPC cited inadequate security controls, including long-lived femtocell certificates and a lack of IP address restrictions, as contributing factors. Additionally, the investigation revealed that 38 KT servers were compromised by BPFDoor malware in March 2024. The PIPC alleges KT failed to report this malware infection promptly and deleted logs from compromised servers, hindering the investigation into potential further data exposure. The commission has ordered KT to strengthen security measures and is considering legislative changes for concealing evidence. Source: Bleeping Computer SC Staff Related Breach UK Department for Education confirms data breach affecting over 600,000 records SC Staff July 30, 2026 The breach, claimed by the ExfilSquad hacking group, exposed names, job titles, and phone numbers of head teachers, university staff, and government officials. Breach Brinks Home confirms data breach after ShinyHunters claims attack SC Staff July 30, 2026 Brinks Home identified the attack on July 20, though the ShinyHunters extortion gang claimed the breach occurred on July 13. Breach Stack Sports notifies users of payment card data exposure SC Staff July 29, 2026 Stack Sports discovered suspicious activity on June 8, 2026, after its internal security monitoring systems detected unauthorized activity affecting the Sports Affinity platform. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Attack Vector You can skip this ad in 5 seconds

Share this article