SK Telecom hit with $97 million fine over massive data leak
- SK Telecom suffered a data breach that was discovered in April 2025
- It affected roughly 27 million people
- The company was fined for it, and will need to make significant changes to its operations
SK Telecom (SKT), one of the biggest telecommunications services providers in South Korea, was fined almost $100 million for failing to protect user data.
In April 2025, the company discovered a malware breach that allowed threat actors to lurk within its systems for years. Some researchers even claim the attack started in August 2021.
The miscreants targeted SKT’s Home Subscriber Server (HSS) and other critical infrastructure, exposing sensitive subscriber data, including USIM authentication keys (KI), International Mobile Subscriber Identity (IMSI) numbers, IMEI device identifiers, phone numbers, email addresses, and possibly other personal data.
“Very weak condition”
Approximately 27 million people were affected by the breach.
Now, Reuters reports that the government-run Personal Information Protection Commission issued a statement, confirming the fine of about 134 billion won ($96.53 million) for “neglecting its duty to take safety measures” and for “delays in notifying the leak to customers”.
The statement also claims SKT’s systems were in a “very weak condition” which allowed threat actors to access the company’s intranet. There were no passwords, or other safety measures, defending the servers from outside influence, and operating systems were outdated and running without the latest security patches.
Besides being forced to pay the fine, the company will also have to “strengthen safety rules on information protection” and revamp its governance.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Responding to a Reuters inquiry, SK Telecom said it “felt a grave responsibility” and will make protecting customer information a “top priority”.
In response, it launched an “Information Security Innovation Plan”, that includes implementing zero-trust architecture, expanding encryption, forming a red team, elevating the CISO role to report directly to the CEO, and adding cybersecurity experts to the board.
Customers received free USIM card replacements, and were offered 50% off August subscription fees. Furthermore, whoever wanted to cancel their contract prematurely was allowed to do so without extra fees.
Via Reuters
You might also like
SK Telecom suffered a data breach that was discovered in April 2025 It affected roughly 27 million people The company was fined for it, and will need to make significant changes to its operations SK Telecom (SKT), one of the biggest telecommunications services providers in South Korea, was fined almost…
Recent Posts
- FCC plans to ban companies selling DJI products under other brands
- Amazon’s Adaptive Display for Fire TVs is officially rolling out today
- Here are the 30,000 songs Sony is suing Udio’s AI music generator over
- The FCC is planning to retroactively ban disguised DJI gadgets
- The first UL 3700-compliant plug-in solar microinverter is now available in the US
Archives
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023