A hacking allegation against LG Uplus (032640.KS) raised in July has been confirmed, but a proper investigation has been impossible because the telecom company destroyed the relevant servers. The government has referred the case to police on charges of obstruction of official duties through deception.
A joint public-private investigation team announced these findings Wednesday while releasing the results of its probe into cyber breach incidents at KT (030200.KS) and LG Uplus.
The Korea Internet & Security Agency (KISA) obtained information about a data leak from LG Uplus on July 18 and shared the details with the company. The Ministry of Science and ICT formed its own investigation team and conducted on-site inspections at LG Uplus starting August 25, with the investigation team operating from October 24.
The investigation confirmed that information connected to LG Uplus's integrated server access control solution (APPM) was actually leaked from the company. The team conducted detailed forensic analysis on the APPM server submitted by LG Uplus, but found that the APPM server from which data was presumed to have been leaked had undergone operating system upgrades and other work, making it impossible to verify traces of the breach. The OS upgrade appears to have been performed around August 12.
The team also attempted to verify allegations that attackers had infiltrated LG Uplus after hacking a partner company that provided the APPM solution. However, the investigation was impossible because key servers along the network path from the partner company employee's laptop to LG Uplus's APPM server had all been reinstalled or destroyed.
Considering that LG Uplus's server OS reinstallation and destruction occurred after KISA's breach notification on July 19, the investigation team deemed this an inappropriate action and referred the case to the National Police Agency on charges of obstruction of official duties through deception.
Deputy Prime Minister Bae Kyung-hoon said, "Following the SK Telecom breach, these incidents at KT and LG Uplus are serious matters that have exposed security vulnerabilities in the nation's core telecommunications infrastructure." He emphasized that "companies must recognize that creating a safe service environment that the public can trust is essential for survival, and must make information security a core management value."






