KT Corp. Confirms Data Breach Compromising Personal Information of Over 5,500 Users

Seoul: KT Corp. announced that personal data of over 5,500 users may have been compromised in a recent mobile payment breach, issuing a public apology for the incident at the country's second-largest mobile carrier. "We confirmed a possible leak of international mobile subscriber identity (IMSI) data affecting 5,561 users," KT said in a statement. "We reported the case to the Personal Information Protection Commission (PIPC) this afternoon and notified affected customers via text message about relief measures."

According to Yonhap News Agency, Kim Young-shub, chief executive officer (CEO) of KT, also apologized at a press conference, pledging full compensation. "We sincerely apologize to all customers affected by unauthorized mobile payments," he said. "We will do our utmost to prevent further damage and provide full compensation to victims."

Since August 27, some KT users, primarily located in southwestern Seoul, have reported unauthorized mobile transactions. In response, the government has launched a joint special team to investigate the incident. KT stated that the IMSI data might have been exposed through illegal, unregistered micro base stations connected to its communication network. IMSI data, a unique identifier for each subscriber stored in a universal subscriber identity module (USIM) chip, can be misused if leaked.

The company revealed that approximately 19,000 customers' mobile phones had connected to the illegal base stations at least once, though not all experienced unauthorized financial transactions. Of these, the IMSI data of 5,561 customers was potentially leaked.

As of Wednesday, authorities have confirmed 278 cases of unauthorized mobile payments totaling 170 million won (US$122,000) reported by KT users. KT has committed to supporting all 19,000 affected customers by replacing USIM chips free of charge and providing a USIM protection service.

This breach at KT follows a significant data leak at SK Telecom Co. just months ago, which affected more than 20 million users and heightened public concerns over data protection at local telecom companies.