Tired of ads? Enjoy an ad-free experience by signing up.
👩‍🍳 How we use AI at Tech in Asia, thoughtfully and responsibly.
🧔‍♂️ A friendly human may check it before it goes live. More news here

LG Uplus, KT face government scrutiny over data breaches

South Korea’s Ministry of Science and ICT said that internal data at LG Uplus was compromised in a cyberattack, following a joint investigation with the Korea Internet & Security Agency on December 29.

LG Uplus delayed formally reporting the breach for several months after being notified by authorities, prompting an on-site inspection and a joint task force.

Investigators said the breach exposed server configuration data, user authentication credentials, and employee records, identifying the company’s internal automated process policy management system as the source.

Authorities said inconsistencies in forensic evidence and the erasure of key servers hampered efforts to trace the attack’s origin.

The ministry criticized LG Uplus for insufficient transparency and referred the case to the Korean National Police Agency.

In a separate incident, KT Corp. was found to have suffered a cyberattack through unauthorized femtocell devices, resulting in the theft of personal data from about 22,000 users, with unauthorized transactions affecting 368 customers and totaling 243 million won.

KT was ordered to submit a corrective action plan by next month, with a compliance review scheduled for June 2026.

🔗 Source: The Korea Herald

🧠 Food for thought

Implications, context, and why it matters.

Korea telecom breach penalties track user harm, and late reporting brings tougher action

  • SK Telecom paid $97 million for 23 million affected users 12, or about $4.22 each. KT’s femtocell (a small, low-power cellular base station typically used indoors) incident hit 22,000 users and drew corrective orders, not an immediate fine. Penalties track scale and negligence, not flat rates.
  • LG Uplus faces heat for months-long reporting delays after authorities gave notice. Key server erasure and mismatched forensic artifacts raise concerns. Police now have the case, and no fine has been announced. Regulators fined SK Telecom for weak controls, including not encrypting Universal Subscriber Identity Module (USIM) authentication keys 12.

Korean carriers and private 5G operators need rogue base station detection

  • KT’s intrusion through unauthorized femtocell devices hit 22,000 users and exposes a class of risk. Private 5G is growing as Airbus and BMW plan global private networks 3.
  • Security vendors and Managed Security Service Providers (MSSPs) can serve Korean firms running private 4G or 5G in manufacturing, ports, and energy 3. Offer rogue small-cell detection as the three carriers manage 36.11 million 5G connections 4, with wider indoor and rural coverage raising exposure. Regulators can levy up to 3% of Korea-derived revenue for violations 5. KT must submit a corrective action plan by next month, with a compliance review set for June 2026.

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.