Government Refers LG Uplus to Police Over Server Destruction During Hacking Probe

Technology|
|
By Seo Ji-hye
|

A hacking allegation against LG Uplus (032640.KS) raised in July has been confirmed, but a proper investigation has been impossible because the telecom company destroyed the relevant servers. The government has referred the case to police on charges of obstruction of official duties through deception.

A joint public-private investigation team announced these findings Wednesday while releasing the results of its probe into cyber breach incidents at KT (030200.KS) and LG Uplus.

The Korea Internet & Security Agency (KISA) obtained information about a data leak from LG Uplus on July 18 and shared the details with the company. The Ministry of Science and ICT formed its own investigation team and conducted on-site inspections at LG Uplus starting August 25, with the investigation team operating from October 24.

The investigation confirmed that information connected to LG Uplus's integrated server access control solution (APPM) was actually leaked from the company. The team conducted detailed forensic analysis on the APPM server submitted by LG Uplus, but found that the APPM server from which data was presumed to have been leaked had undergone operating system upgrades and other work, making it impossible to verify traces of the breach. The OS upgrade appears to have been performed around August 12.

The team also attempted to verify allegations that attackers had infiltrated LG Uplus after hacking a partner company that provided the APPM solution. However, the investigation was impossible because key servers along the network path from the partner company employee's laptop to LG Uplus's APPM server had all been reinstalled or destroyed.

Considering that LG Uplus's server OS reinstallation and destruction occurred after KISA's breach notification on July 19, the investigation team deemed this an inappropriate action and referred the case to the National Police Agency on charges of obstruction of official duties through deception.

Deputy Prime Minister Bae Kyung-hoon said, "Following the SK Telecom breach, these incidents at KT and LG Uplus are serious matters that have exposed security vulnerabilities in the nation's core telecommunications infrastructure." He emphasized that "companies must recognize that creating a safe service environment that the public can trust is essential for survival, and must make information security a core management value."

Original reporting by Seo Ji-hye for Seoul Economic Daily.

AI-translated from Korean. Quotes from foreign sources are based on Korean-language reports and may not reflect exact original wording.

Watch · Seoul Economic Daily

More →
5:11

AI KEY

Preview
Korean Corporate Intelligence HubKOSPI · KOSDAQ · 12 sectors

A live, cap-weighted view of every KOSPI and KOSDAQ sector, with same-day Korean reporting distilled by company — built for foreign investors, correspondents and analysts who need to scan Korea before the next session.

Korea Company Atlas

Preview
Market Ontology · The Feedback LoopKFTC 2025 · 92 groups · 121,954 articles

An English ontology of the Korean market — how companies, the media, the government and the National Assembly move each other in a loop. Korea's named controlling persons and designated business groups are a mechanism, not a risk to be priced blind.

SIGNAL

Pre-register
English Edition · Capital MarketsM&A · IPO · PE · Fund Flows

Pre-register for SIGNAL English Edition — a premium subscription bringing Korean capital markets coverage (M&A, IPOs, private equity, fund flows) to global institutional investors. First access to the 50% introductory rate.