KT on edge over "bomb" of potential fines amid data leak and hacking cover-up allegations

Jul 20, 2026, 10:06 am

print page small font big font

facebook share

tweet share


The size of the fine against KT, which caused a data breach affecting approximately 22,000 subscribers last year, is expected to be finalized soon. As the Personal Information Protection Commission (PIPC), the competent regulatory authority, prepares to deliberate on sanctions against KT later this month, possibilities are arising that the company could face a fine of up to 200 billion KRW. Following the high-intensity government sanctions leveled against SK Telecom and subsequently Coupang over data breach incidents, KT remains on high alert. Industry insiders and experts view that the key to mitigating the fine will hinge on how effectively the company can demonstrate its efforts to prevent recurrences through information security investments and post-incident management.

According to industry sources on July 19, the PIPC is scheduled to review and deliberate on the punitive measures, including the administrative fine for the KT data breach, during its plenary session on July 29. The PIPC wrapped up its investigation into the incident in May and issued a prior notice containing the tentative sanctions, the deadline for submitting opinions, and a list of evidence. Consequently, the official scale of the fine is highly anticipated to be announced as early as late this month or by early next month at the latest.

KT's data leak controversy initially flared up in August last year, triggered by unauthorized micro-payment damages reported by a segment of its subscribers. Hackers unlawfully exploited femtocells—ultra-small base stations installed to eliminate coverage dead zones—to infiltrate KT's core network and exfiltrate the personal data of 22,227 subscribers, according to an investigation by the Ministry of Science and ICT (MSIT). The leaked personal information included International Mobile Subscriber Identity (IMSI) numbers, International Mobile Equipment Identity (IMEI) numbers, and phone numbers. The unauthorized micro-payments totaled 777 cases affecting 368 individuals, with damages estimated at around 243 million KRW.

The sharpest focus centers on the magnitude of the fine. Under the current Personal Information Protection Act, the statutory cap for administrative fines is set at 3% of a company's average revenue from the preceding three years. For KT, the mobile communications revenue directly linked to the data breach serves as the baseline for calculation. According to KT's business reports, its mobile communications revenue over the past three years stood at 6.7134 trillion KRW in 2022, 6.8696 trillion KRW in 2023, and 6.9599 trillion KRW in 2024. Based simply on the three-year average of 6.8476 trillion KRW, the theoretical maximum fine translates to 205.4 billion KRW. This figure surpasses the 134.791 billion KRW fine previously slapped on SK Telecom for its own data breach. However, the prevailing industry outlook suggests it is unlikely the fine will reach the absolute legal ceiling, given that revenues unrelated to the violation are excluded during the calculation process, and mitigating factors—such as post-incident response efforts—are comprehensively weighed.

KT has announced a commitment to invest approximately 200 billion KRW annually in information security from this year through 2030. This marks a surge of over 50% compared to last year's security investment of 127.6 billion KRW. Recently, the telecom giant launched an Information Security Advisory Committee to preemptively counter cyber threats and establish a highly reliable security framework. In relation to this, KT CEO Park Yun-young emphasized, "Information security goes beyond the realm of technology; it is the most fundamental promise a corporation makes to its customers. We will translate the insights of the nation's top experts into action to complete a Zero Trust-based preemptive prevention system." Earlier this year, as a corrective measure to take responsibility for the breach, KT implemented a two-week waiver on contract termination fees and operated a six-month "Customer Reward Program" offering benefits across telecommunications, content, and lifestyle services. Observations indicate that if these remedial measures are favorably factored into the assessment, the fine could be lowered to the 100 billion KRW range, comparable to SK Telecom's case.

On the flip side, some corners of the market point out the potential for an aggravated fine due to substantive financial damages and allegations of a hacking cover-up. According to government announcements, KT initially maintained that there were no signs of an intrusion despite repeated recommendations from the MSIT to report the hacking, only officially filing a report with the Korea Internet & Security Agency (KISA) around mid-September last year. In a recent statement, the civic group Citizens' Coalition for Consumer Sovereignty asserted, "A fine on the scale of 200 billion KRW is not merely a punishment; it serves as a societal warning to remind the entire telecommunications industry of the critical importance of security investments and personal data protection. This measure is the minimum level of accountability required to safeguard citizens' personal information and communications safety, and it must serve as an important turning point to prevent similar incidents from recurring in the future."

                                                                                                           Yeon Chan-mo
#KT 
Copyright by Asiatoday