Tired of ads? Enjoy an ad-free experience by signing up.
👩‍🍳 How we use AI at Tech in Asia, thoughtfully and responsibly.
🧔‍♂️ A friendly human may check it before it goes live. More news here

S Korea’s top telecoms hit by hacking breaches, leadership shakeups

SK Telecom, KT, and LG Uplus are facing leadership turbulence after recent large-scale hacking incidents.

SK Telecom appointed Jung Jai-hun as CEO, replacing Ryu Young-sang, after posting its first-ever quarterly operating loss of 52.2 billion won (US$36.5 million) and a 16.8% year-on-year revenue drop to 2.7 trillion won (US$1.9 billion) in Q3.

The company cited significant one-off costs from a data breach affecting nearly 27 million users, including about 500 billion won (US$350 million) in compensation and contract cancellation fee waivers, and a 134.8 billion won (US$94 million) fine from the Personal Information Protection Commission.

KT’s CEO Kim Young-shub is under pressure after a mobile payment breach, with the company’s board set to vote on the CEO appointment process next week.

At LG Uplus, CEO Hong Bum-shik is likely to retain his position despite the company confirming a possible cyberattack, with no clear evidence of data loss so far.

🔗 Source: The Korea Times

🧠 Food for thought

Implications, context, and why it matters.

PIPC and government probes may shape telco remediation in South Korea

  • The Personal Information Protection Commission (PIPC) opened investigations into KT and LG Uplus on September 10, 2025 after they skipped breach notices despite unauthorized micropayment charges and suspected hacking 1. In May 2025 the PIPC fined an internet service provider about 15.14 billion won, signaling outcomes if breaches are confirmed 2.
  • Article 63 of the Personal Information Protection Act lets the PIPC request materials and run inspections 1. The Ministry of Science and ICT said its probe into KT and LG Uplus continues with no timeline, and regulators have not said if they will order fixes across all three carriers 3. TechCrunch said fragmentation and expert shortages have slowed responses 3.

Security and compliance vendors should plan around ISMS timelines as enforcement rises

  • Companies that meet either the 10 billion won annual sales threshold or 1 million average daily users must get Information Security Management System (ISMS) certification, a national baseline security standard, by August 31 of the year after the triggering fiscal year 2. Recent telecom incidents may speed voluntary Information Security Management System-Personal information (ISMS-P) adoption, an enhanced variant that adds privacy controls, now about 25% of ISMS applicants 2.
  • Managed Security Service Providers (MSSPs), identity providers, and data protection vendors can help enterprises pursuing ISMS-P, which can cut administrative penalties by up to 40% in breach cases 2. Recent incidents raise regulatory and cyber risk, so enterprises should fund certified security frameworks before deadlines 2.

Recent SK Telecom developments

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.