SEOUL: South Korea’s Personal Information Protection Commission has fined telecom operator KT Corp 54 billion won ($37.43 million) over a customer data breach that exposed personal information and payment details, the regulator said on Thursday.
The commission said hackers stole data belonging to more than 16,600 KT mobile service customers and used the information to carry out illegal payments worth 240 million won.
The breach occurred between 2024 and 2025, according to the findings of the regulator’s investigation.
What Did the Investigation Find?
The Personal Information Protection Commission said it discovered multiple malware programs on KT’s servers while investigating the incident.
The panel accused KT of attempting to conceal the cyber intrusion and failing to report the breach to authorities as required under South Korean law.
The regulator did not provide further details on the nature of the malware or how the attackers gained access to the company’s systems.
KT officials did not immediately respond to requests for comment.
How Serious Was the Data Breach?
The incident adds to growing concerns in South Korea over cybersecurity risks affecting companies that manage large amounts of consumer data.
Telecommunications firms hold extensive customer information, including personal details and payment-related data, making them frequent targets for cyberattacks.
The commission’s penalty is among the latest regulatory actions taken in South Korea as authorities increase scrutiny of companies’ data protection practices.
