Tired of ads? Enjoy an ad-free experience by signing up.
👩‍🍳 How we use AI at Tech in Asia, thoughtfully and responsibly.
🧔‍♂️ A friendly human may check it before it goes live. More news here

SK Telecom ordered to pay $67 per user after data breach

South Korea’s Korea Consumer Agency has ordered SK Telecom to pay 100,000 won (US$67) in compensation to each user after a large-scale data breach earlier this year.

The order follows a mediation request by 58 consumers in May after the breach, which affected all 23 million SK Telecom users.

In April, the company disclosed that universal subscriber identity module (USIM) data was leaked from its servers.

SK Telecom offered free USIM replacements to users after the incident, and regulators launched an investigation.

SK Telecom must reduce monthly subscription fees by 50,000 won and provide an additional 50,000 won in credits per user.

The estimated compensation totals 2.3 trillion won (US$1.57 billion), which is higher than SK Telecom’s 2024 net profit of 1.4 trillion won (US$0.95 billion) and about 13% of its 2024 sales.

If SK Telecom accepts the ruling within 15 days, the agency will compensate other affected consumers.

SK Telecom said it will review the ruling.

🔗 Source: Yonhap

🧠 Food for thought

Implications, context, and why it matters.

Mass redress in Korea lacks clear enforcement precedent

  • The Korea Consumer Agency (KCA) mediates disputes under the Framework Act on Consumers (FAOC) 1. Its decision seeking compensation from SK Telecom binds only if the parties accept, and there is no cited precedent for enforcement at the 2.3 trillion won scale. SK Telecom has 15 days to respond, and the idea that acceptance triggers automatic payment to other affected consumers lacks support in the voluntary scheme in Korean law 1.
  • In August, the Personal Information Protection Commission (PIPC) fined the company 134.8 billion won, yet that process runs apart from this consumer route. PIPC handles regulatory violations 23, while the KCA handles damages under the FAOC 1. The company could pay the fine yet reject mediation, which would move punishment forward while consumer relief stalls.

Privacy SaaS and cyber-insurance markets will expand in Korea

  • Recent cases set a pattern of strict PIPC action. It fined Meta KRW 21.6 billion for inferring sensitive traits without explicit consent 2, penalized Netflix USD 190,000 for unlawful collection and overseas transfers 3, and hit Facebook for about USD 5.6 million over Personal Information Protection Act (PIPA) breaches, including facial recognition data collection 3. This looks recurrent, so privacy tools for Korean enterprises have durable demand.
  • B2B Software-as-a-Service (SaaS) vendors and Managed Security Service Providers (MSSPs) can pitch consent tools, as Meta’s bundled consent was rejected 2. Cross-border transfer checks gained urgency after AliExpress was fined 1.97 billion won for undisclosed routing 2, and AI model audits rose following the PIPC order that Alipay erase an algorithm built on Kakao Pay user data 2. Cyber-insurance in Korea should price for fines and possible mass consumer payouts.

Recent SK Telecom developments

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.