Tired of ads? Enjoy an ad-free experience by signing up.
👩‍🍳 How we use AI at Tech in Asia, thoughtfully and responsibly.
🧔‍♂️ A friendly human may check it before it goes live. More news here

SK Telecom fined $97m over data breach affecting 23 million users

SK Telecom has been fined 134.8 billion won (US$97 million) after a cyberattack exposed the personal information of about 23 million people in South Korea.

The Personal Information Protection Commission imposed the penalty for inadequate protection of customer data and delayed breach reporting, and ordered SK Telecom to strengthen its data oversight.

The Ministry of Science and ICT also recommended in July that the company waive penalties for customers leaving the network after the incident.

🔗 Source: Bloomberg


🧠 Food for thought

1️⃣ South Korea’s telecom sector shows recurring vulnerability despite regulatory evolution

The SK Telecom breach continues a troubling pattern in South Korea’s telecommunications infrastructure that spans over a decade.

In 2011, SK Communications suffered a massive data breach affecting 35 million accounts on the Cyworld social network and Nate web portal, with hackers stealing phone numbers, email addresses, and encrypted passwords2.

That earlier incident led to class-action lawsuits from users fearing identity theft and prompted discussions about stronger cybersecurity measures3.

The fact that another major SK subsidiary has now been breached affecting 23 million people suggests that despite regulatory improvements, fundamental infrastructure vulnerabilities persist in South Korea’s highly connected digital economy.

This is particularly concerning given South Korea’s status as one of the most wired nations globally, where such breaches can affect nearly half the population in a single incident2.

2️⃣ Regulatory enforcement demonstrates South Korea’s strengthened data protection framework

The $97 million penalty against SK Telecom reflects South Korea’s significantly toughened approach to data protection violations through its Personal Information Protection Act (PIPA).

Under PIPA, organizations must report data breaches affecting over 1,000 individuals within 72 hours to both regulators and affected users4. SK Telecom was specifically fined for failing to protect customer data and not reporting breaches in a timely manner1.

The Personal Information Protection Commission (PIPC), which issued the fine, has authority to impose administrative penalties and corrective measures for PIPA violations5.

This enforcement action demonstrates how South Korea has evolved from the 2011 SK Communications breach, when regulatory responses were less structured, to a comprehensive framework that can impose substantial financial consequences for data protection failures.

Recent SK Telecom developments

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.