KT hit with W54b penalty over data breach
South Korea’s privacy regulator fined KT Corp. 53.98 billion won ($37.4 million) for an August data breach tied to inadequate security of its femtocell system. The breach exposed 16,647 subscribers’ IDs and phone numbers and led to unauthorized mobile payments for 368 users, with losses of about 240 million won. The PIPC also cited malware on servers and possible log deletion, and may refer the case for criminal investigation.
How this was made

The 30-second read
Why it matters
The regulator cites unauthorized access, exposure of subscriber identifiers, unauthorized mobile payments, malware on servers, and alleged failure to report plus log deletion. It also plans a criminal referral and separately signals an investigation into LG Uplus.
Market read
This is a concrete enforcement action with quantified breach impact and alleged concealment, creating a fresh compliance and legal-risk overhang for KT.
What to watch
Follow-on outcomes (criminal investigation scope, appeal timing, and whether regulators expand to other operators) could dominate the stock reaction more than the headline fine.
Background
The Personal Information Protection Commission (PIPC) attributes the breach to KT’s failure to secure its femtocell/small-cell base station system, enabling hackers via illegally manufactured femtocells.
Ticker impact
South Korea’s privacy regulator fined KT 53.98 billion won for a femtocell breach, including unauthorized access and payments.
Downward bias for KT shares on risk-off sentiment; magnitude depends on market pricing of regulatory risk and any follow-on criminal/procedural developments.
The article discloses a specific regulator fine, breach mechanics, affected users, and alleged concealment (log deletion), which typically increases uncertainty and expected costs.
Market effects
Highlights heightened cyber and privacy enforcement risk across South Korean telecom operators and small-cell infrastructure vendors.
May pressure other Korean telcos’ compliance posture and increase scrutiny of network equipment supply chains.
Reinforces global trend of regulators tying telecom cyber incidents to financial penalties and potential criminal referrals.
Counterpoint
Because the fine is below the statutory maximum and KT says it is rebuilding controls, the market may treat this as contained remediation rather than a systemic failure.
Key entities
- companyKT Corp.
Subject of the PIPC fine for a femtocell-linked data breach, including alleged concealment and failure to report.
- regulatorPersonal Information Protection Commission (PIPC)
South Korea’s privacy regulator issuing the fine and referring the case for criminal investigation.
- companyLG Uplus
Another telecom operator flagged for a potential investigation related to alleged server disposal before a probe.




