View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

South Korea fines KT $39M for 11-month customer data breach via rogue

๐Ÿ’ฅ BREACHES & INCIDENTS

  • South Korea fines KT $39M for 11-month customer data breach via rogue femtocell South Korea fined KT $39 million for a prolonged customer data breach exploiting a rogue femtocell.
    • Applies to KT Corporation, South Korea's largest telecom operator serving over 13.5 million mobile subscribers
    • Data breach exposed personal info of 16,647 customers and caused fraudulent micropayments totaling $167,400
    • Attackers used a lost femtocell with a valid certificate to intercept cellular traffic and capture sensitive data
    • KT's security flaws included 10-year valid femtocell certificates and lack of IP restrictions, enabling 11 months undetected access
    • Investigation found BPFDoor malware on 38 KT servers since March 2024, linked to Chinese espionage group Red Menshen ๐Ÿ“Ž Coverage: bleepingcomputer.com ยท ๐Ÿ‘ via BleepingComputer

๐Ÿ”“ CVEs & KEV

  • Other: 16 CVEs (worst 6.5)

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check