Femtocell Hacking Scandal, KT Fined 54 Billion Won

이겨례 Reporter

KT, which suffered a massive personal information leak through illegal femtocells (small base stations) and unauthorized micro-payment damages, has been fined approximately 54 billion won by the Personal Information Protection Commission.

In particular, as it was confirmed that KT deleted logs after the accident and made false statements during the investigation, the Personal Information Protection Commission decided to refer KT for investigation obstruction.

▲ Personal information of 16,000 people leaked through illegal femtocells

The Personal Information Protection Commission held a full meeting on the 29th and announced on the 30th that it decided to impose a fine of 53.979 billion won on KT for violating the Personal Information Protection Act, along with corrective orders, improvement recommendations, and publication orders.

According to the investigation, hackers extracted certificates from a lost KT femtocell, installed them in an illegally manufactured femtocell, and accessed the KT mobile network. They then intercepted communication information flowing between user terminals and the internal network to obtain personal information.

Hackers combined the acquired communication data with additional personal information such as names and dates of birth to attempt micro-payments, and proceeded with unauthorized payments by stealing payment authentication text messages (SMS) and automated response systems (ARS).

In this process, mobile phone numbers, International Mobile Subscriber Identity (IMSI), and International Mobile Equipment Identity (IMEI) of 16,647 users, including budget mobile subscribers, were leaked, and 368 people suffered unauthorized micro-payment damages totaling approximately 240 million won.

▲ 11-month network penetration... Total failure in security management

The Personal Information Protection Commission judged that this incident was not a simple hacking attack but a result of multiple security management shortcomings by KT.

KT set the validity period of femtocell certificates to 10 years and did not restrict accessible internet addresses (IP), allowing access from overseas or other company networks.

Additionally, there was a path to bypass the femtocell management server, and management of Cell IDs used when accessing the core network was not properly conducted, resulting in virtually no system to detect or block unauthorized equipment access.

Due to these vulnerabilities, hackers accessed KT's internal network for approximately 11 months without additional authentication procedures, but KT only recognized the abnormal access after complaints about unauthorized micro-payments occurred.

KT Gwanghwamun headquarters [provided by KT]
KT Gwanghwamun headquarters [provided by KT]KT Gwanghwamun headquarters [provided by KT]

▲ Malware infection also concealed... Self-handled without government reporting

The Personal Information Protection Commission confirmed a separate malware infection incident.

In March 2024, KT discovered that hackers had infiltrated through vulnerabilities in its roaming rental service website and 38 servers were infected with malware such as BPF Door, but it handled the situation in-house without reporting to the government.

Additionally, hackers conducted SQL injection attacks on the administrator page and were found to have accessed and leaked names, phone numbers, and account information of some KT employees and partner company employees.

However, network logs were not preserved at the time of the incident, making it impossible to confirm whether additional personal information of users was leaked.

▲ Log deletion and false statements confirmed... Personal Information Protection Commission decides to refer KT

The background for the heaviest responsibility being imposed in this sanction involved investigation obstruction.

It was confirmed that KT deleted logs from 10 compromised servers in April of last year while checking for malware infections.

Initially, KT stated that related materials did not exist, but when the Personal Information Protection Commission confirmed the log deletion circumstances through digital forensics, KT reversed its statement and belatedly submitted separately stored logs.

The Personal Information Protection Commission determined this to be a clear investigation obstruction act and decided to refer KT.

▲ LG U also referred for investigation... Evidence destruction controversy

Separate measures were taken against LG U in this investigation.

The Personal Information Protection Commission initiated an investigation after confirming personal information leak circumstances through a U.S. security magazine and confirmed that employee and partner company employee information was actually stored in the integrated password management system (APPM).

However, LG U was found to have reinstalled the operating system of the APPM server or disposed of the server before the investigation began, making it difficult to confirm the exact circumstances of the leak and additional damages.

Although the action took place before the investigation began, making it difficult to apply investigation obstruction provisions under the Personal Information Protection Act, the Personal Information Protection Commission determined it constitutes obstruction of government business and decided to refer it to investigative authorities.

▲ Personal Information Protection Commission to strengthen penalties for evidence destruction

The Personal Information Protection Commission decided to pursue legal and institutional improvements to enhance investigation effectiveness following this incident.

The commission plans to pursue amendments to relevant laws to allow criminal punishment or fines of up to 3% of total sales even when evidence is concealed or destroyed before investigation initiation.

The commission also plans to introduce a whistleblower reward system and impose compliance enforcement fines of 0.3% of daily sales on businesses that fail to cooperate with investigations or fail to comply with corrective orders.

Additionally, the commission plans to pursue amendments to the Personal Information Protection Act to allow immediate issuance of data preservation orders when personal information breach incidents occur.

Copyright © JKN. Unauthorized reproduction or redistribution prohibited.