The Korean government has ruled that KT must waive early termination fees for subscribers who wish to cancel their contracts following a security breach. The government concluded that the fraudulent micropayment incidents caused by illegal femtocells resulted from KT's inadequate management systems. Authorities also plan to impose fines for KT's delayed and evasive breach reporting.
The Ministry of Science and ICT (MSIT) announced these findings at the Seoul Government Complex on Sunday, releasing the results of a joint public-private investigation into security breaches at KT and LG Uplus.
KT's Femtocell Management Found Broadly Deficient; Encryption Bypass Confirmed
The government determined that KT's negligence was clear in this incident and that the company violated its contractual obligation to provide secure telecommunications services. A comprehensive investigation covering three areas—fraudulent micropayments and personal data leaks through illegal femtocells, reports of certificate leaks, and suspected server intrusions—found that information from 22,227 KT subscribers was exposed, including subscriber identity numbers (IMSI), device identification numbers (IMEI), and phone numbers.
Additionally, 368 individuals suffered unauthorized micropayment fraud totaling 243 million won ($179,000) across 777 transactions. These figures match the numbers KT previously announced. However, MSIT noted that "additional damages cannot be verified for certain periods where mobile payment intermediary records no longer exist."
The investigation team concluded that "KT's femtocell management system was broadly deficient." According to findings, all KT femtocell products used identical manufacturer certificates, allowing any copied device—even unauthorized equipment—to pass internal network authentication. KT's certificate validity period was set at 10 years, meaning once a device connected, it could access internal networks for an extended period. Verification of irregular IP blocking, femtocell serial numbers, and installation location data was also inadequate.
During femtocell manufacturing, sensitive information was provided to subcontractors without proper security protocols, making extraction from storage devices easy, investigators found.
End-to-end encryption (IPSec) should be maintained between devices and core networks, but investigators confirmed that encryption could be bypassed in illegal femtocell environments. In such cases, payment authentication information via ARS or SMS could be exposed in plaintext. The government said some devices lacked proper configuration support, resulting in unencrypted SMS transmission, and ordered KT to address this issue.
"The risk of plaintext voice and text interception is not limited to some victims but exposes all KT subscribers to danger," the investigation team said.
Four of Five Legal Consultants Support Fee Waivers; Obstruction of Justice Investigation Requested
"Based on these findings, we consulted five legal institutions on the possibility of waiving termination fees, and four concluded that fee waivers are applicable due to 'KT negligence' and 'violation of key contractual obligations,'" the investigation team said.
One institution noted that fee waivers may be difficult to apply to subscribers whose data leaks were not confirmed. However, the team concluded overall that grounds for fee waivers have been established.
The government also plans to impose fines under the Information and Communications Network Act for KT's delayed and unreported breach notifications. False submissions during the investigation have been referred to police on charges of obstruction of official duties.
The investigation team will require KT to submit an implementation plan in January, complete corrective measures by April, and conduct verification by June.
LG Uplus Found to Have Obstructed Investigation; Systems Reinstalled and Destroyed After Breach
The investigation team also released findings regarding LG Uplus. The Korea Internet and Security Agency (KISA) received information in July from a tipster about data leaks at LG Uplus and notified the company of the security incident. MSIT subsequently formed its own investigation team and conducted on-site inspections.
The investigation confirmed that data was indeed leaked from LG Uplus as the tipster claimed, including server lists related to integrated server access control (APPM), account information, and employee names.
However, some servers identified as leak pathways had undergone OS upgrades, reinstallation, or disposal, making forensic analysis difficult. Claims of infiltration through hacking of partner companies could not be verified because key pathways had been eliminated.
The investigation team determined that LG Uplus's actions to reinstall and dispose of server operating systems after KISA had notified the company of the breach constituted inappropriate measures. The team classified this as "obstruction of official duties through deception" and referred the matter to the National Police Agency for investigation.






