To ensure the best browsing experience, please enable JavaScript in your web browser. Without it, many website features are inaccessible.


Total Tests:
485,773,462
737,046
130,956

South Korea’s Major Telecoms Firm KT Fined ₩54B Over Data Breach

August 4, 2026

Read also: TIM fined over €9M for violating privacy rules; South Korea’s Lotte Card faces a business suspension after a hack; and more.

Views: 1.5k Read Time: 4 min.

South Korea’s Major Telecoms Firm KT Fined ₩54B Over Data Breach

South Korea fines KT nearly ₩54 billion over major customer data breach

South Korea's Personal Information Protection Commission (PIPC) has fined telecommunications company KT Corporation ₩53.979 billion, which is about €33.6 million, for serious data protection failures.

The investigation found that hackers had access to KT's internal network for nearly 11 months, from October 2024 to September 2025. During that time, the personal information of 16,647 customers was exposed. At least 368 customers were affected by fraudulent mobile micropayments, with total losses reaching ₩240 million (about €149,000).

According to the PIPC, the attack began when hackers obtained a lost KT femtocell, a small cellular base station used to cover spots with weak wireless signal. The device contained a valid authentication certificate, which the attackers copied onto a fake device. This allowed the fake device to appear as part of KT's network and intercept data from nearby mobile phones. The attackers collected sensitive information, including customers' phone numbers, IMSI and IMEI numbers. They later combined this information with intercepted SMS and automated phone verification codes to carry out fraudulent mobile payments.

The commission said KT's security measures were not strong enough. Authentication certificates for femtocells remained valid for 10 years, network connections were not limited by source IP addresses, and a system route allowed attackers to bypass normal security checks. During the investigation, the PIPC also found that 38 KT IT service network servers had been infected with malware, including the BPFDoor backdoor, as early as March 2024. The commission said KT knew about the malware but did not report it to authorities and instead handled the incident internally.

The watchdog also said KT deleted network logs while inspecting the malware. Because some records had been wiped, the commission said it could not determine whether additional customer data had been stolen.

As part of the enforcement action, the PIPC ordered KT to strengthen security for femtocells and other telecommunications equipment, improve its personal data protection system, give its Chief Privacy Officer a greater oversight role, and expand its Information Security Management System (ISMS-P) certification to include its mobile network systems.

Austrian court upholds €13M penalty against a data broker for illegally selling data

Austria's Supreme Administrative Court (VwGH) has confirmed that Österreichische Post must pay a €13 million administrative fine for illegally processing and selling data on the alleged political affiliations of 2.2 million Austrians. The court also ruled that the company only has to pay €100,000 in administrative costs instead of 10% of the fine. The decision ends the case after three rounds before the VwGH (case no. Ro 2025/04/0007).

The case stems from data processing between May 2018 and February 2019, when Österreichische Post, acting as a data broker, sold estimated political affinity data without the individuals' consent. In 2019, Austria's data protection authority fined the company €18 million for this practice.

Following several appeals, the VwGH had confirmed that political affinity is sensitive personal data. The fine was briefly annulled because the authority had not identified responsible individuals within the company, but it was reinstated after the European Court of Justice clarified that this is not required for fines against legal entities.

The court also dismissed the company's argument that the fine should be based only on the turnover connected to the offense. Instead, it confirmed that group-wide annual turnover is the correct basis for calculating GDPR fines, following the European Data Protection Board's 2022 guidelines. In the end, the VwGH set the final fine at €13 million while reducing the administrative costs to €100,000.

Portugal regulator fines Vodafone €160,000 over contract changes

Portugal’s communications regulator ANACOM has fined Vodafone €160,000 for changing customer contracts without giving the required advance notice.

According to the watchdog, Vodafone updated its contract terms to include mandatory advertising in its automatic TV recording service for around 449,000 subscribers. ANACOM said the company failed to provide customers with at least 30 days’ written notice and didn’t inform users that they could cancel their contracts without extra costs if they did not agree with the new terms.

The regulator said the decision was based on rules under the previous Electronic Communications Law (LCE), specifically Article 48(16), which protected customers’ rights when contract terms were changed.

Under current law, telecom operators must still notify customers of contract changes at least one month in advance, using a clear and lasting format, and explain any right to end the contract without penalties. Vodafone has appealed the decision to Portugal’s Competition, Regulation and Supervision Court.

ImmuniWeb Newsletter

Get Cybercrime Weekly, invitations to our events and webinars in your inbox:


Private and Confidential Your data will stay private and confidential

Italy fines TIM €9.516 million for breaking privacy and telemarketing rules

The Italian Data Protection Authority (Garante per la protezione dei dati personali) has fined the country’s largest telecom operator TIM €9.516 million for breaking privacy and telemarketing rules after investigating unauthorized call centers that made promotional calls on the company's behalf.

The investigation was initiated after authorities received 7,000 complaints in 2025 about unwanted marketing calls, many of which used spoofed phone numbers or numbers not registered with Italy's communications regulator. Many of the calls also targeted people who had signed up to the Public Register of Opposition to avoid telemarketing.

The Authority found that the call centers used a scheme to make their sales activities appear legitimate. Users were sent text messages from disguised phone numbers with links to forms on an official TIM partner's website. Once users completed the forms, the call centers contacted them again using registered numbers, creating the appearance of a valid customer request.

The Authority said the company failed to properly monitor its sales partners and did not ensure the privacy rules were followed throughout its telemarketing network. It also found that TIM often failed to respond to customer requests to access, delete, or object to the use of their personal data and made it unnecessarily difficult for users to unsubscribe from marketing.

In addition to the penalty, TIM has been ordered to improve its lead generation process, strengthen oversight of its sales network, and update its procedures for handling customer privacy rights.

ImmuniWeb can help you to prevent data breaches and meet regulatory requirements.

South Korea slaps Lotte Card with ₩5B penalty over a data breach

South Korea’s financial services watchdog has imposed a ₩5 billion (a little over €3 million) penalty on the country’s major credit and financial services company Lotte Card in accordance with the Specialized Credit Finance Business Act and the Credit Information Use and Protection Act, following the August 2025 hack that saw credit information of 2.97 million customers leaked.

Also, the company's operations will be suspended for 1.5 months. This marks the first time in the country that such a measure has been imposed in response to a hacking incident.

The Financial Supervisory Service launched an investigation in September last year after Lotte Card reported a hacking-related information leak to the financial authorities.

The inspection found several violations of security requirements under the Specialized Credit Financial Business Act and the Credit Information Use and Protection Act. The violations included the failure to apply security patches to information systems, the failure to encrypt resident registration numbers and passwords, and the failure to install antivirus software while operating Lotte Card's online payment system.

What’s next:

Talk to an Expert