INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
KT Fined $38m for Misleading Femtocell Campaign Advertisements
| 2026-08-03 09:36 CRITICAL HIGH DATA BREACH
Executive Summary
AI-generated
On August 3, 2026, South Korea's largest telco KT was fined $38 million by the country's data protection regulator after serious security failings enabled hackers to defraud its customers. The breach affected over 16,647 users, with some 368 customers losing a total of 240 million won ($175,000) via unauthorized micropayments. Hackers exploited a stolen femtocell certificate and managed to access KT's internal network without proper authentication controls in place. This allowed them to intercept transmission and reception information between user terminals and the internal network, ultimately leading to the fraudulent transactions. The regulator mandated improvements to security posture through vulnerability checks for wireless communication equipment and improved governance, following an 11-month breach that went unnoticed due to insufficient detection and response capabilities.
Technical Mitigations AI-generated
• Regularly update femtocell certificates issued for internal network access to a shorter validity period, such as 5 years.
• Restrict the IP addresses of femtocells accessing the internal network and implement strict authentication mechanisms.
• Implement robust detection and response capabilities, including regular vulnerability checks for wireless communication equipment.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
BPFDoorBPFDoor
Target & Sectors
KR
telecommunicationstelecommunications
Incident Timeline
September 2025
Threat actors used backdoor malware to infect 38 internal servers at KT, resulting in unauthorized micropayments totaling $175,000.
Click on any entity below to view its context and source!
infrastructure
38 internal servers
PIPC Uncovers Backdoor Malware
There was more bad news for KT after investigators found evidence that 38 internal servers had been infected with various strains of malware including the BPFDoor backdoor.
victims
368 customers
Some 368 customers were defrauded to the tune of 240 million won ($175,000) via unauthorized micropayments.
financial
$175,000 tune
Some 368 customers were defrauded to the tune of 240 million won ($175,000) via unauthorized micropayments.
2026/08/03
Threat actors used a stolen femtocell to defraud KT's customers, resulting in $38 million stolen or extorted funds.
Click on any entity below to view its context and source!
financial
$38 Stolen / Extorted Funds
Korea’s Largest Telco KT Fined $38m After Femtocell Campaign.
Tactical Metrics
Metrics
financial
38,000,000
Stolen / Extorted Funds
Click for context!
Korea’s Largest Telco KT Fined $38m After Femtocell Campaign.
Metrics
infrastructure
38
Internal Servers
PIPC Uncovers Backdoor Malware
There was more bad news for KT after investigators found evidence that 38 internal servers had been infected with various strains of malware including the BPFDoor backdoor.
Metrics
victims
368
Customers
Some 368 customers were defrauded to the tune of 240 million won ($175,000) via unauthorized micropayments.
Metrics
financial
175,000
Tune
Some 368 customers were defrauded to the tune of 240 million won ($175,000) via unauthorized micropayments.
Intelligence Sources
Infosecurity-Magazine
2026-08-03
Korea’s Largest Telco KT Fined $38m After Femtocell Campaign
Infosecurity-Magazine
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T07:12
Comprehensive Tactical Telemetry
Highly Correlated Entities
13x
organisation
Identified Entity
Korea’s Largest Telco KT Fined
entity
4x
timeline
Temporal Reference
September 2025
date
Contextual Telemetry
Context Block
10 METRICS
target region
Target Country
Korea, Republic of
country
industry
Targeted Sector
Government
sector
tactic
Cyber Operation Type
Data Breach
tactic
financial
Stolen / Extorted Funds
38,000,000
$
tactic
MITRE ATT&CK Technique
T1588.001 - Malware
technique
malware
Malware Payload
BPFDoor
tool
infrastructure
Internal Servers
38
internal servers
victims
Customers
368
customers
general metric
Tune
240,000,000
tune
financial
Tune
175,000
tune
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.