Deliberation on Disposition Plan at Plenary Session on the 29th
Up to 3% of Related Business Sales Could Be Fined… Maximum Estimate at 193 Billion Won
Final Decision to Consider Severity of Violations, Scale of Damage, and Other Factors
The level of sanctions against KT regarding its hacking incident and the leakage of personal information will be decided on July 29, 2026. Since SK Telecom and Coupang previously received hefty fines for similar incidents, industry experts predict that KT will face corresponding penalties.
The Personal Information Protection Commission will hold a plenary session on July 29, 2026, in the afternoon to review a disposition plan outlining whether KT violated personal information protection laws, including details on possible fines and sanctions. However, if, during the meeting, commission members decide that further examination of the facts or the criteria for calculating fines is necessary, the resolution of the disposition plan could be postponed to the next meeting.
In September of last year, KT experienced a data breach in which the personal information of 22,227 subscribers in the southwestern part of the Seoul metropolitan area, such as subscriber identity numbers (IMSI), device identity numbers (IMEI), and phone numbers, was leaked due to an attack exploiting illegal small-scale base stations (femtocells).
According to an investigation by the joint private-public team of the Ministry of Science and ICT, 368 people out of the KT femtocell hacking victims suffered a total of 777 cases of unauthorized small-sum payments, amounting to approximately 243 million won. KT’s failure to manage femtocell security properly, allowing illegal femtocell equipment to access its internal network, is seen as an aggravating circumstance.
Additionally, the Personal Information Protection Commission also conducted an investigation into infections from the BPFdoor malware. BPFdoor was also used in the hacking of USIM information at SK Telecom.
According to the Personal Information Protection Act in effect at the time of the KT data breach, if a serious violation such as failure to fulfill security obligations occurred, a fine of up to 3% of relevant sales could be imposed. Here, the relevant sales figure is calculated based on the average sales for the three years immediately preceding the incident.
KT’s standalone wireless business division reported an average sales revenue of approximately 6.4463 trillion won for 2022 to 2024. Based on this, the maximum possible fine could reach about 193 billion won.
However, the actual fine will be determined by considering the severity of KT’s violations at the time of the data leak, the scale of damage, and how the company responded. In previous cases, the Personal Information Protection Commission set SKT’s fine at about 134.8 billion won (1% of mobile network operator sales), and Coupang’s fine at 624.6 billion won (1.8% of e-commerce sales).
For the KT incident, the occurrence of actual financial damages and the company’s insufficient network security measures could serve as factors for increasing the fine.
Hot Picks Today
Meanwhile, since the KT data breach happened before the amended Personal Information Protection Act took effect, the rule imposing punitive fines of up to 10% of sales does not apply in this case.
This content was produced with the assistance of AI translation services.
© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.
Click Here For The Original Source.

![[Exclusive] SK hynix Plans New Headquarters at Le Meridien Hotel Site in Gangnam, Establishing Central Seoul Base](https://i0.wp.com/nationalcybersecurity.com/wp-content/uploads/2026/07/2022123100091569866_1672412955.png?w=1150&ssl=1)