KT Mobile Payment System Breached by Rogue Femtocell Device in South Korea

Abstract digital illustration of a pen writing on a digital surface.

A security breach affecting KT (Korea Telecom) mobile payment systems has been linked to unauthorized micro-payments targeting subscribers, with hackers reportedly using an illegal mini base station device known as a femtocell to gain unauthorized network access. The incident follows a series of high-profile telecommunications security breaches in South Korea, including recent major data compromises at SK Telecom that exposed millions of USIM records.

The unauthorized transactions were detected primarily in southwestern Seoul and Gyeonggi Province’s Gwangmyeong city from late August 2024, occurring mostly during early morning hours. Total reported damages have reached approximately 45.8 million won (US$33,000). The attack method using femtocells raises particular concerns as these devices are designed to extend cellular network coverage but can be manipulated to intercept mobile communications when compromised.

KT confirmed that the breach originated from a rogue femtocell device not registered in its management system, while stating that its authorized equipment remained secure. The telecommunications company has emphasized that there is no evidence of direct system hacking, though investigators are examining whether sensitive subscriber data such as International Mobile Subscriber Identity (IMSI) numbers or encryption keys were compromised. IMSI numbers serve as crucial identifiers in mobile networks and their compromise could potentially enable various forms of network-based attacks, similar to those seen in recent SS7 protocol exploits.

The Ministry of Science and ICT has established a special investigation team to probe the incident. “In order to minimize damage to the public, we will seek to promptly identify the cause and contain the spread of the damage through the team joined by the country’s top experts,” said Second Vice Science Minister Ryu Je-myung. The response comes as part of the Ministry’s recent efforts to strengthen mobile security protocols, particularly given South Korea’s expanding cross-border payment systems.

KT has officially reported the breach to the Korea Internet & Security Agency and implemented blocks on unusual payment requests. “We deeply regret the damage and concern caused to our customers. We will fully cooperate with the government and police investigation to help resolve the case,” the company stated.

A public-private advisory group of technical experts has been formed to assist with the ongoing investigation, which aims to determine how the rogue femtocell accessed KT’s core network and whether personal data was compromised. The fact that only KT customers were affected has prompted authorities to examine possible insider involvement or internal vulnerabilities. The incident highlights ongoing concerns about network security vulnerabilities in modern telecommunications infrastructure.

Sources: Korea Bizwire, Korea Bizwire, Mobile World Live