The South Korean government has ruled that KT must waive early termination fees for subscribers who wish to cancel their contracts following a security breach, determining that the telecommunications carrier's negligence was the direct cause of unauthorized micropayment fraud through illegal femtocells. Authorities also plan to impose fines on KT for delaying and evading breach notification requirements.
The Ministry of Science and ICT (MSIT) announced these findings Sunday at the Seoul Government Complex, releasing the results of a joint public-private investigation into security breaches at KT and LG Uplus.
KT's Femtocell Management Found Systematically Deficient
The government concluded that KT's negligence was clear and that the company violated its contractual obligation to provide secure telecommunications services. The investigation examined three incidents: micropayment fraud and personal data leaks through illegal femtocells, reported certificate leaks, and suspected server intrusions.
According to the findings, personal information of 22,227 subscribers was exposed, including subscriber identity numbers (IMSI), device identification numbers (IMEI), and phone numbers. Additionally, 368 individuals suffered 243 million won in damages from 777 unauthorized micropayment transactions. These figures match KT's own disclosed estimates. However, MSIT noted that additional damages cannot be verified for certain periods where mobile payment records are no longer available.
The investigation team concluded that "KT's femtocell management system was systematically deficient overall." All of KT's femtocell products used identical manufacturer certificates, allowing unauthorized devices to pass internal network authentication simply by copying the certificate. KT's certificates had a 10-year validity period, enabling long-term internal network access after a single connection. Verification of abnormal IP blocking, femtocell serial numbers, and installation location data was also inadequate.
During femtocell manufacturing, sensitive information was provided to subcontractors without proper security controls, making it easily extractable from storage devices.
The investigation also confirmed that end-to-end encryption (IPSec), which should be maintained between devices and the core network, could potentially be disabled in illegal femtocell environments. This would expose payment authentication information such as ARS and SMS messages in plain text. Some devices were found to transmit SMS in plain text due to inadequate configuration support, prompting government-ordered remediation by KT.
"The risk of plain-text voice calls and text messages being intercepted is not limited to identified victims but exposes all KT subscribers to danger," the investigation team stated.
Legal Experts Support Penalty Waivers; Obstruction Charges Filed
The investigation team consulted five legal advisory bodies on whether termination fee waivers could be applied. Four concluded that waivers were justified based on "KT's negligence" and "violation of key contractual obligations." One body expressed concerns about applying waivers to subscribers whose data was not confirmed as leaked, but the investigation team ultimately determined that grounds for fee waivers were established.
Authorities also plan to impose fines under the Information and Communications Network Act for KT's delayed and incomplete breach notifications. False submissions during the investigation have been referred to police on charges of obstruction of official duties. The investigation team will require KT to submit an implementation plan by January, complete remediation by April, and undergo verification by June.
LG Uplus Referred for Obstruction of Justice Over Evidence Destruction
The investigation team also released findings on LG Uplus. The Korea Internet & Security Agency (KISA) received a tip in July regarding alleged data leaks at LG Uplus and notified the company of the suspected breach. MSIT subsequently formed an investigation team for on-site inspection.
The investigation confirmed that data was indeed leaked as claimed by the informant, including server lists related to integrated server access control (APPM), account information, and employee names. However, some servers identified as leak pathways had undergone OS upgrades, reinstallation, or disposal, making forensic analysis difficult. Claims of intrusion through compromised contractor systems could not be verified as critical pathways had been eliminated.
Given that LG Uplus's server OS reinstallations and disposals occurred after KISA notified the company of the breach, the investigation team deemed these actions inappropriate and has referred the matter to the National Police Agency on charges of obstruction of official duties through deception.






