INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
KT Fined $39 Million for Customer Data Breach Incident
| 2026-07-30 22:28 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
On October 8, 2024, a nearly 11-month internal network compromise at KT Corporation persisted until September 5, 2025. The Personal Information Protection Commission (PIPC) fined the company KRW 53.979 billion ($39 million) for data protection violations following an investigation that began on September 10, 2025, after user reports of fraudulent micropayments. Approximately 16,647 KT subscribers had their personal information exposed due to the breach, resulting in at least 368 customers experiencing fraudulent mobile payments totaling KRW 240 million ($167,400). The attackers exploited a lost cellular base station called a femtocell, which contained a valid authentication certificate that was not restricted by source IP addresses or expiration date. This allowed them to intercept communications between users' devices and KT's core network for nearly an entire year without being detected.
Technical Mitigations AI-generated
• Limit femtocell certificate validity to a shorter period, such as 6 months.
• Restrict connections by source IP addresses for femtocells and other telecommunications equipment.
• Implement logging and monitoring of network traffic on all servers, including those infected with BPFDoor malware.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
BPFDoorBPFDoor
Target & Sectors
KR
governmentgovernment
telecommunicationstelecommunications
Incident Timeline
March 2024
Threat actors using the stealthy Linux and Solaris backdoor BPFDoor evaded detection for more than five years before being linked to the China-nexus Red Menshen espionage group.
Click on any entity below to view its context and source!
infrastructure
Linux
BPFDoor is a stealthy Linux and Solaris backdoor
publicly documented in 2022
that evaded detection for more than five years.
September 10, 2025
Threat actors used BFDoor malware to compromise 38 KT IT service network servers in March 2024.
Click on any entity below to view its context and source!
victims
5,500 customers
A day later, the company filed its initial data breach notification, reporting that data of roughly 5,500 customers had been exposed.
infrastructure
38 KT network servers
BFDoor malware infection
During the investigation, PIPC also discovered that 38 KT IT service network servers had been compromised by malware, including BPFDoor, in March 2024.
2026/07/30
South Korea's Personal Information Protection Commission fined telco giant KT Corporation $39 million for customer data breach.
Click on any entity below to view its context and source!
financial
$39 KT
South Korea fines telco giant KT $39 million for customer data breach.
Tactical Metrics
Metrics
financial
39,000,000
Kt
Click for context!
South Korea fines telco giant KT $39 million for customer data breach.
Metrics
victims
5,500
Customers
A day later, the company filed its initial data breach notification, reporting that data of roughly 5,500 customers had been exposed.
Metrics
infrastructure
Linux
Affected Product
BPFDoor is a stealthy Linux and Solaris backdoor
publicly documented in 2022
that evaded detection for more than five years.
Metrics
infrastructure
38
Kt Network Servers
BFDoor malware infection
During the investigation, PIPC also discovered that 38 KT IT service network servers had been compromised by malware, including BPFDoor, in March 2024.
Intelligence Sources
BleepingComputer
2026-07-30
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T07:13
Comprehensive Tactical Telemetry
Highly Correlated Entities
16x
organisation
Identified Entity
KT
entity
9x
timeline
Temporal Reference
September 10, 2025
date
3x
industry
Targeted Sector
Telecommunications
sector
2x
tactic
Cyber Operation Type
Data Breach
tactic
2x
general metric
%
54
%
Contextual Telemetry
Context Block
8 METRICS
target region
Target Country
Korea, Republic of
country
financial
Kt
39,000,000
kt
general metric
Corporation Krw
53,979,000,000
corporation krw
source region
Origin Country
China
country
victims
Customers
5,500
customers
infrastructure
Affected Product
Linux
software
malware
Malware Payload
BPFDoor
tool
infrastructure
Kt Network Servers
38
kt network servers
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.