Tired of ads? Enjoy an ad-free experience by signing up.
👩‍🍳 How we use AI at Tech in Asia, thoughtfully and responsibly.
🧔‍♂️ A friendly human may check it before it goes live. More news here

SK Telecom SIM data leaked in cyberattack

SK Telecom announced on April 22, 2025 that it experienced a cyberattack that led to a data breach.

The incident occurred late April 19, 2025 night and involved the unauthorized exposure of subscriber identity module (USIM) data.

The company is currently assessing the extent and details of the breach.

SK Telecom confirmed that it has removed the malicious code and any potentially compromised equipment.

As of April 22, 2025 there have been no confirmed reports of misuse of the leaked data.

🔗 Source: The Korea Times


🧠 Food for thought

1️⃣ South Korea’s recurring pattern of major telecom data breaches

The SK Telecom USIM breach continues a troubling history of significant data compromises in South Korea’s telecommunications sector.

In 2011, SK Communications (under the same SK corporate umbrella) experienced one of the country’s largest data breaches, affecting 35 million users, approximately half of South Korea’s population at the time1.

This incident follows a pattern where initial breach disclosures often underestimate the full extent of the compromise, as seen with Hana SK Card, where subsequent investigations revealed significantly more data was exposed than first reported2.

These recurring breaches highlight persistent vulnerabilities in South Korea’s digital infrastructure despite the country’s reputation as one of the world’s most technologically advanced nations.

The frequency of these incidents has contributed to South Korea being described as “the most hacked nation in the world” according to previous media commentary, suggesting systemic challenges in securing sensitive telecommunications data1.

2️⃣ Robust regulatory response reflects South Korea’s evolving cybersecurity framework

The immediate involvement of multiple government agencies in the SK Telecom breach investigation demonstrates South Korea’s increasingly structured approach to cybersecurity incidents.

Within 24 hours of discovering the breach, SK Telecom reported it to the Korea Internet & Security Agency (KISA), followed by notification to the Personal Information Protection Commission, adhering to stringent reporting requirements established following previous incidents3.

Recent SK Telecom developments

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.