South Korea Fines KT Corp $37.4 Million Over Customer Data Breach

South Korea's Personal Information Protection Commission (PIPC) has imposed a 54 billion won ($37.4 million) fine on telecommunications giant KT Corp after an investigation found the company failed to adequately protect customer data and did not properly report a major cybersecurity incident.

The regulator said hackers stole sensitive customer information, including personal and payment details, leading to fraudulent transactions and raising concerns over corporate cybersecurity practices.

South Korea Fines KT Corp $37.4 Million Over Major Customer Data Breach — photo 1

KT Data Breach Exposed Customer Information

According to the commission, cybercriminals accessed the personal information and payment data of more than 16,600 KT mobile service customers.

Investigators said the stolen information was used to carry out unauthorized payments totaling approximately 240 million won, resulting in financial losses for affected customers.

South Korea Fines KT Corp $37.4 Million Over Major Customer Data Breach — photo 2

The breaches occurred during 2024 and 2025, according to the regulator.

Regulators Cite Multiple Security Failures

The Personal Information Protection Commission said its investigation uncovered multiple malware infections across KT's servers.

South Korea Fines KT Corp $37.4 Million Over Major Customer Data Breach — photo 3

Officials also alleged that the company attempted to conceal evidence of the cyber intrusion and failed to notify government authorities within the timeframe required under South Korean data protection laws.

The findings contributed to one of the country's largest regulatory penalties for a personal data leak.

South Korea Fines KT Corp $37.4 Million Over Major Customer Data Breach — photo 4

South Korea Strengthens Data Protection Enforcement

The fine reflects South Korea's increasingly strict approach to enforcing personal information and cybersecurity regulations.

Authorities have continued to tighten oversight of companies handling large volumes of customer data as cyberattacks become more sophisticated and frequent.

The latest enforcement action highlights the legal obligations businesses face to promptly disclose security incidents and protect consumer information.

KT Yet to Respond Publicly

KT officials did not immediately comment following the commission's announcement.

The company has not publicly responded to the findings regarding the alleged malware infections, reporting failures, or regulatory violations.

Further actions could depend on whether KT challenges the decision or implements additional security measures recommended by regulators.

Outlook

The case underscores the growing financial and reputational risks companies face following major cybersecurity incidents.

As regulators worldwide strengthen privacy and data protection rules, businesses are expected to invest more heavily in cybersecurity, incident reporting, and customer data protection to avoid similar penalties.