| Title | The PIPC Sanctions SKT over Data Breach | ||
|---|---|---|---|
| Department | Date | 2025.09.03 | |
| Attachment | press release The PIPC Sanctions SKT over Data Breach.pdf | ||
| Page URL | https://pipc.go.kr/eng/user/ltn/new/noticeDetail.do?bbsId=BBSMSTR_000000000001&nttId=2877 | ||
| Contents |
Press Release The PIPC Sanctions SKT over Data Breach - The PIPC decided to sanction SKT for violations of the Personal Information Protection Act (PIPA), imposing KRW 134.8 billion - Joint task force found out SKT’s complacency in key networks and systems in relation to mobile communications resulted in data breaches that include personal information of approximately 23 million subscribers - The PIPC plans to announce “Comprehensive Measures for Robust Personal Information Security Management Systems,” which encourages businesses to invest in personal data protection and security in early September 2025
August 27, 2025 (This is an unofficial translation of a press release, originally prepared in Korean.)
The Personal Information Protection Commission (PIPC) held its 17th plenary meeting of 2025 and resolved to sanction SK Telecomm Co., Ltd. (SKT) for its failure to comply with the Personal Information Protection Act (PIPA) on August 27, 2025. Administrative sanctions are as follows:
● A penalty for violations (Gwajinggeum) of KRW 134.79 billion ● A fine for wrongdoing (Gwataeryo) of KRW 91 million ● Correction orders: Enterprise-wide system examination, stronger safeguards, and privacy governance system overhauls to prevent future data breaches
1. Developments Following Data Breaches
The PIPC initiated investigations after SKT reported an anomaly in outbound traffic, which was identified as a data breach, on April 22, 2025. Given the aftermath and implications of one of the largest data breaches, the PIPC teamed up with the Korea Internet & Security Agency (KISA) to launch a task force to closely examine SKT’s data processing practices and violations since the day it reported its data breach.
Joint Task Force ● Who: Four investigators, two in-house lawyers, and one in-house accountant at the PIPC Seven investigators at the Korea Internet Security & Agency (KISA). ● How: On-site investigation, a written fact-finding survey, and digital evidence collection to examine SKT’s key personal data processing systems and the scale of a data breach. Looking into SKT’s compliance in terms of security measures under the PIPA.
2. Timeline and Findings of the Data Breach
Joint investigations showed that hackers’ attacks against several systems served as a pillar for SKT’s mobile communications services. The attacks led to a data breach, where approximately 23.24 million subscribers' data, including twenty-five types of information, was compromised. This data included phone numbers, universal subscriber identity module (USIM) authentication keys (Ki, OPc), international mobile subscriber identity (IMSI), and other details. The figure of subscribers includes the subscribers of budget mobile carriers, deduplicated.
Using a mobile for self-authentication and identification is a norm and self-authentication is widely used for accessing various services. The leaked data contains ISMI and Ki that that can be linked back to individuals. Given the aftermath, the incident has had a severe impact on people’s daily lives.
The timeline of hackers’ attacks is as follows:
● August 2021: Hackers infiltrated numerous servers within SKT’s infrastructure and installed malware for the first time ● June 2022: Hackers installed malicious programs within the Integrated Customer Authentication System (ICAS) to gain an additional foothold ● April 18, 2025: Hackers attacked SKT’s Home Subscriber Server (HSS) to hijack 9.82 gigabytes of subscribers’ personal information
3. Violations
The PIPC’s investigation found that SKT’s personal data processing practices and compliance status were vulnerable enough to be attacked due to complacency. SKT’s major violations are as follows:
1) Failures to Put Sufficient Safeguards in Place
● Insufficient Access Control
SKT’s infrastructure and security operational systems, which link the internal infrastructure and the Internet-enabled infrastructure, were vulnerable enough to prevent any illegal intrusion by hackers.
SKT operated Internet-enabled, management, core, and office automation networks technically without the implementation of network isolation, allowing unlimited access from between networks. It also failed to put sufficient access control on its personal data processing systems, e.g., by enabling Internet Protocol (IP) address at home and abroad to access its infrastructure, and unnecessary server-to-server access.
Moreover, SKT failed to take necessary measures in response to the detection of several data breach attempts, including failures to check anomaly logs of the intrusion detection system. Even after SKT became aware of a hacker’s intrusion in February 2022, during which malware was installed in its infrastructure and the HSS server was accessed, it failed to examine whether an anomaly in outbound traffic occurred or if additional malware had been installed, as well as the adequacy of its access control policy. This negligence led to the incident.
● Insufficient Control of Root Permission
SKT stored login credential data of subscribers on approximately 2,365 servers within its infrastructure, allowing direct access without setting passwords or any access control measures. Moreover, SKT also enabled access to the HSS DB and data without separate authentication procedures. Hackers exploited this complacent approach to steal login credentials, gaining access to the server in the infrastructure to install malware. It resulted in data extraction stored in the HSS DB.
● Inaction to Regularly Update Security Updates
In October 2016, a security warning was issued against DirtyCOW, a security vulnerability that the hackers exploited to install BPFDoor, and security patches were readily available. SKT was aware of the availability of security updates, but it installed the operating system (OS) that was vulnerable to DirtyCOW. Although the data breach occurred in April 2025, they failed to implement the necessary security updates.
In addition, universally available vaccine programs have detected the vulnerability execution since 2020, but SKT has not installed it as of April 2025. It even failed to take care of security measures that can replace the failure to install the vaccine. These severe mishaps led to the country's unprecedented data breach.
● Storing Ki in Plaintext, without Encryption
SKT failed to store approximately 26 million cases of Ki in the HSS DB in plaintext, without encryption. Ki is data required for subscriber authentication and telecommunications service provision. The missteps allowed hackers to secure Ki for USIM swapping in an original format.
SKT was aware that other mobile carriers stored Ki in their databases with encryption for data protection and security as part of an internal security review when the media outlets covered USIM swapping issues in 2022. However, it failed to take necessary measures for encryption, resulting in the data breach. Other mishaps include SKT neglecting to plan and establish its internal management. It also failed to store access logs and put other safeguards in place. It went so far as to violate its own internal security rules.
2) Negligence in Designating a CPO and Carrying out Tasks
Although SKT processed personal data for both the IT and communications infrastructure sectors to provide mobile communications services, it confined the CPO’s roles to the IT sector, which encompasses web and app application services.
In this regard, SKT’s CPO technically failed to manage and supervise the communications sector because the CPO did not have a clear picture of how personal data processing worked in that sector.
3) Delayed Notification of Data Breaches
SKT became aware of outbound traffic generated due to data transmission from its HSS DB on April 19, 2025. The PIPA stipulates that when a processor becomes aware of a data breach, it should notify the competent supervisory authority without undue delay and ultimately within 72 hours. The notification also extends to affected data subjects within 72 hours, but SKT failed to do so. However, SKT failed to do so, adding social turbulence in the country.
On May 2, 2025, the PIPC convened a planetary meeting to resolve its deliberations on SKT to inform subscribers of a data breach immediately. SKT notified subscribers of the possibility of a data breach on May 9, 2025. On July 28, 2025, it notified subscribers of the data breach that took place in April 2025. Given the insufficient responses to the data breach, SKT failed to fulfill its obligations stipulated under the PIPA.
4. Sanctions
The PIPC resolved to impose KRW 134.79 billion and KRW 91 million on the top mobile carrier in the country for failing to put sufficient safeguards in place and for data breaches, including those involving USIM data. It also levied KRW 9.6 million for delayed notification to the affected data subjects, which might have helped control the data breach more quickly and alleviate concerns across society.
Along with financial penalties, the PIPC issued correction orders on SKT to overhaul its governance frameworks as follows:
● Strengthening safeguards through a thorough review of the personal data processing status; ● Overhauling an enterprise-wide privacy governance framework by a CPO to supervise the workstream related to personal data processing.
Moreover, the PIPC issued a recommendation to SKT to expand the ISMS-P recognition currently granted to some customer management systems, called T World, to communications network systems, thereby enhancing the level of safeguards put in place across the business.
Before the deliberations, the PIPC held four rounds of pre-meetings to facilitate in-depth discussions and gather input from commissioners regarding the investigation results and the direction for imposing sanctions. At the eighteenth plenary meeting, SKT stated its opinion and had a Q&A session.
5. Key Takeaways
The sanction holds significance in that it serves as a wake-up call for the importance of personal data protection. Taking this opportunity, the PIPC sets an example by imposing stricter sanctions on SKT for violations of the PIPA, as the business caused privacy concerns and other damage across society. The sanctions, in particular, will prompt businesses to have a sense of urgency for strengthening their personal data management systems and implementing preventive measures.
In addition, the PIPC plans to enhance its management and oversight roles for businesses that process vast amounts of personal data, aiming to prevent a similar data breach from occurring. It will announce “Comprehensive Measures for Robust Personal Information Security Management Systems” that cover system improvements, restructuring incentive systems to encourage large-scale data processors to invest in personal data protection and security in early September 2025.
Chairperson Haksoo Ko of the PIPC stated, “Taking this opportunity, large-scale personal data processors should invest in personnel and allocate more budgets for data protection and privacy by bringing in a shift in their perspectives that it is not just an expenditure, but an investment required for their operations.” He added that, “CPOs and dedicated inside departments in each business should strengthen their roles and highlight the importance of their workstream in the age of the data economy. Building upon the endeavors, I hope the personal data protection frameworks across business and society are reinforced against potential data breaches.”
* A PDF file, formatted for better readability, is attached.
|
||