Massive Cyberattack Hits KT and SK Telecom
The massive cyberattack on KT and SK Telecom exposed the vulnerability of Korea’s communication network. It shattered public trust in the nation’s two main carriers and raised lasting fears over digital security.…….Ed
The recent hacking incidents targeting KT and SK Telecom have shaken South Korea’s telecommunications sector, raising concerns that extend far beyond a simple cyberattack. They are now being viewed as a grave threat to national security and public trust. As the two companies account for an overwhelming share of the nation’s communication infrastructure, any disruption or data breach in their networks could severely impact not only individuals but also businesses and public institutions. Some regions have already experienced temporary service outages and restricted data access, causing significant public inconvenience. Today, telecommunications serve as the backbone of national operations, supporting not just phone and the internet services, but also financial transactions, government administration, and emergency medical systems. Advanced industries such as smart cities, autonomous vehicles, and the Internet of Things (IoT) likewise cannot function without stable networks. Thus, a hack on telecom infrastructure represents more than a data breach. It constitutes an “invisible national crisis” capable of eroding social stability and national competitiveness. This case serves as a stark reminder that, in the digital era, telecommunications security must be treated as a core element of national defense.
The first incident occurred at SK Telecom. On April 22, SKT announced that it had discovered “signs indicating that USIM information from some customer devices may have been leaked due to malware infection.” Shortly thereafter, allegations surfaced that KT and LG Uplus had also suffered cyberattacks, following the publication of related data by the U.S.-based cybersecurity magazine Phrack. According to the released information, LG Uplus had traces of unauthorized access in its server management and access privilege control systems affecting 89,238 server records, 42,526 user accounts, and the real names of 167 employees and partner companies. Similarly, KT reportedly detected signs of authentication key exposure within its web service servers. Evidence suggests that all three major carriers had been exposed to hacking attempts since as early as two to three years ago.
In late September, KT experienced a major incident involving unauthorized micro-payments. Over the course of a month, 362 subscribers were affected, with total damages estimated at approximately 240 million won. KT immediately reported the breach to the National Police Agency’s Cyber Investigation Unit. During the subsequent investigation conducted by the Ministry of Science and ICT, weaknesses in KT’s authentication servers and femtocell management system were identified as primary vulnerabilities. Around the same period, LG Uplus also detected signs of malware intrusion within its partner network, prompting the Korea Internet & Security Agency (KISA) to place the company under close monitoring.
The number of reported incidents and customer disputes has also surged. SK Telecom recorded 439 dispute cases, LG Uplus 337, and KT 325, marking the highest annual total on record. Affected subscribers reported issues such as leaked billing information, unauthorized third-party transactions, and account hacks.
Following the series of hacking incidents, university students have shown increasing anxiety and shifting perceptions. In early October, this study conducted by the author surveyed seven university students following the telecom breach reports and found that four of them had switched either their USIM cards or mobile carriers. Although none reported direct hacking damage, most expressed serious concern over cybersecurity. Five of the respondents said their trust in their telecom providers had declined and that they were considering switching carriers in the future. As one respondent put it, “I’m still using my current provider, but I’ll look into other options when changing my plan.” Conversely, three students said they made no changes, citing inconvenience or lack of time to visit a store for replacement. The findings highlight a growing awareness of telecom security issues, though this concern has yet to translate into concrete action.
The recent domestic incidents mirror patterns seen in similar telecom infrastructure breaches overseas. In 2023, the U.S. company T-Mobile disclosed that a hacker group had compromised personal data belonging to around 37 million customers. In Japan, Nippon Telegraph and Telephone Corporation (NTT) suffered a breach in 2020 after attackers stole credentials from a partner company, exposing internal network control data. In both countries, governments responded by reclassifying telecommunications networks as critical national infrastructure, and by strengthening public-private coordination and threat information-sharing systems. Similarly, South Korea’s three major carriers and relevant government ministries are now overhauling their cooperative frameworks in response to the incidents. Supply-chain breaches and poor internal security management have been identified as common vulnerabilities. The Ministry of Science and ICT, in collaboration with the Personal Information Protection Commission and the National Police Agency, has launched a joint public–private task force to reinforce telecom monitoring, improve log management, and revise authentication systems. The Presidential Office also announced plans to establish a “Comprehensive Telecom Security Strategy” during its report to the National Assembly in late September.
The KT and SK Telecom hacking incidents have laid bare the fact that South Korea’s telecommunications security framework remains ill-equipped to respond to external threats. These breaches are not isolated corporate failures but symptoms of systemic vulnerabilities within the country’s information infrastructure management. Strengthening firewalls or adopting temporary measures at the corporate level will not be sufficient. The government, industry, and academia must work together to build an integrated national cyber defense system. To achieve this, South Korea must establish real-time threat intelligence-sharing platforms, develop AI and big-data-based detection technologies, expand cybersecurity education to cultivate skilled professionals, and standardize incident response protocols. Furthermore, like other major countries, the nation should reinforce periodic governmental oversight of telecom security management. This crisis serves as a reminder that modern life rests upon technology, and that protecting communication networks is not merely a corporate responsibility but a cornerstone of national safety and future stability. The time has come for closer collaboration between the government and the telecom sector to strengthen infrastructure security and prevent future breaches.
Na Jeong-ju (ST Reporter)
njj6511@soongsil.ac.kr
Park Si-eun (Web Editor)
sally4480@soongsil.ac.kr