SK Telecom Data Breach Exposes 26.9 Million USIM Records in South Korea

Abstract digital illustration of a pen writing on a digital surface.

A major data breach at South Korean telecommunications provider SK Telecom (SKT) has compromised approximately 9.32 gigabytes of USIM-related data, including 26.9 million IMSI numbers, according to findings from an ongoing investigation. The breach, which began on June 15, 2022, remained undetected until April 22, 2025, when SKT reported it to the Korea Internet & Security Agency (KISA). The incident represents one of the largest telecommunications security breaches in South Korea’s history, following several smaller-scale attacks on the country’s digital infrastructure.

The attack involved malware installations on 23 of SKT’s servers, affecting four different types of USIM (Universal Subscriber Identity Module) data. IMSI numbers, which are unique identifiers used to authenticate mobile subscribers on cellular networks, were among the compromised data. The breach potentially affects nearly all of SKT’s subscriber base, which includes approximately 25 million customers served directly and through mobile virtual network operator partners. The exposure is particularly concerning as IMSI numbers can be exploited for SIM-swapping attacks and unauthorized network access.

A joint public-private investigation team has identified 25 different types of malware used in the attack, along with 21 new types of malicious code discovered during the investigation. Forensic and log analysis has been completed on 15 of the affected servers, with investigations of the remaining eight servers expected to conclude by the end of May. The sophistication of the attack suggests a well-organized threat actor, according to cybersecurity experts familiar with the investigation.

Two of the compromised servers temporarily stored personal customer data, including names, date of birth, phone numbers, and email addresses, though the extent of exposure for this information remains under investigation. The breach has affected various connected devices, including smartphones, smartwatches, and other IoT devices. The widespread impact is particularly significant as South Korea prepares to launch its nationwide digital ID system on smartphones in 2025.

“The investigators confirmed that the amount of leaked (universal subscriber identity module, or USIM) information was 9.82 gigabytes, which equals to about 26.69 million units of the IMSI,” said Choi Woo-hyuk, director general of the Cyber Security & Network Policy Bureau at the Science Ministry, during a press briefing at the Government Complex Seoul.

The incident has prompted increased international cybersecurity cooperation, including discussions between US Federal Communications Commission chair Brendan Carr and Korean Minister of Science and ICT Yoo Sang regarding enhanced security collaboration between the two nations. The partnership strengthens existing bilateral efforts to improve telecommunications security and comes amid recent global concerns about emerging authentication bypass techniques and mobile security vulnerabilities.

Sources: Total Telecom, Telecoms Tech News, Business Korea, Korea Herald, Korea Times