A decision on the fine for KT Corporation regarding its massive personal data leak is anticipated this week, with industry observers keenly watching the potential penalty amount. Following substantial fines levied against SK Telecom and Coupang, expectations are high for the scale of the repercussions KT may face.
Personal Information Protection Commission to Review KT Fine
Sources indicate that the Personal Information Protection Commission (PIPC) is scheduled to discuss the KT data breach case during its plenary session this week. Song Kyung-hee, the chairperson of the PIPC, had previously informed KT of the impending review and was awaiting their official statement. She had also announced that a decision would be made in the near future.
The core of the deliberation revolves around the calculation of the fine. The PIPC typically determines fines based on a percentage of revenue related to the incident, with a maximum of 3% applied to the revenue generated from services where the violation occurred. In the case of SK Telecom, the commission notably excluded revenue from its overall telecommunications services and instead focused on the revenue specifically from its LTE and 5G customer services. This precedent suggests that KT’s fine could also be calculated based on its wireless service revenue.
Details of the KT Data Breach Incident
The incident at KT dates back to September of the previous year when a data breach occurred due to hacking via unauthorized femtocells (small base stations). This breach resulted in the leakage of customer information, including IMSI (International Mobile Subscriber Identity), IMEI (International Mobile Equipment Identity), and phone numbers. Subsequently, a secondary incident of financial fraud occurred, with the personal information of 368 customers being misused, leading to approximately 243.19 million won in fraudulent charges.
An investigation by the Ministry of Science and ICT revealed that KT took 11 months to acknowledge the hacking incident. Furthermore, the investigation pointed to inadequate security measures, including the prolonged failure to block malicious code used in the attack. While the number of affected individuals was revised down from an initial estimate of 22,227 to approximately 16,000, the occurrence of actual financial damages means the severity of this breach cannot be underestimated.
Key Factors in Determining the Fine
A critical factor in the PIPC’s decision-making process is expected to be KT’s own actions following the discovery of the breach. Specifically, the company’s decision to self-destruct 43 servers that were found to be infected with malicious code during the investigation is under scrutiny. The joint investigation team from the Ministry of Science and ICT and the police is reportedly investigating KT’s disposal of these servers between March and July of the current year.
A source familiar with the matter noted that the destruction of these servers has made it difficult to fully ascertain the scope of the data leakage. This aspect is likely to be considered significant in assessing the penalty. “There is an understanding that the disposal of servers during an investigation needs to be viewed very seriously,” the source explained. “This message could be reflected in the level of the fine imposed this time.”
KT’s Remedial Actions and Future Plans
Since the data breach, KT has implemented several customer support measures. In January, the company waived all subscription fees for affected customers. From February to the current month, KT has been operating a customer compensation program totaling approximately 450 billion won.
In terms of strengthening its information security infrastructure, KT has announced plans to invest 1 trillion won in data protection by 2030. This includes restructuring its information security division and separating the roles of Chief Information Security Officer (CISO) and Chief Personal Information Protection Officer (CPO) to enhance accountability and oversight. These measures are part of KT’s broader strategy to prevent future data security incidents.
The upcoming decision from the PIPC is expected to set a significant precedent for how data breach penalties are calculated and applied in South Korea, particularly concerning the revenue base used for fine calculation and the company’s response to the breach itself.
