South Korea's science ministry has released the final investigation into security incidents at KT Corp. (KRX:030200) and LG Uplus (KRX:032640), finding KT responsible for unauthorized mobile micropayments affecting 368 users and the leakage of 22,227 numerical identifiers and phone numbers.
The breach, totaling 243 million won, stemmed from poor femtocell security management. Attackers used cloned femtocells with KT certificates and server IPs to intercept communications, bypassing encryption and capturing authentication codes. Malicious software also infected 94 KT servers with 103 types of malware.
The ministry ordered KT to strengthen femtocell security, enforce end-to-end encryption, expand security monitoring, and implement a centralized governance structure with a Chief Information Security Officer (CISO). The breach allows affected users to potentially waive KT contract penalties.
For LG Uplus, investigators could not verify the breach due to falsified reports and destroyed servers. The ministry has requested a police investigation for obstruction of official duties.
Comments