Back to the archive

The encyclopedia · Legal & Compliance · Legal decision · 2018–2023

LG Uplus ran its login system on dead software — hackers took 297,117 customer files

The system that authenticated customers ran on end-of-life software, with 2009 webshells still inside. PIPC's ₩6.8B fine was Korea's largest at the time.

LG Uplus · 2023-07-12

What happened

On 12 July 2023 South Korea's Personal Information Protection Commission sanctioned LG Uplus with a ₩6.8 billion ($5.3M) surcharge and a ₩27 million fine over a breach disclosed that January: hackers had taken 297,117 customers' personal data — names, phone numbers, addresses, birth dates and USIM identifiers among 26 fields. It was the largest surcharge yet imposed on a Korean company for a data leak.

The commission traced the intrusion to a customer authentication system running software that was already end-of-life at the presumed time of the breach, June 2018; basic intrusion-prevention equipment was absent or misconfigured, and webshells uploaded in 2009 and 2018 had sat undiscovered on the servers. More than 10 million production records with personal data were left unattended in development and testing environments.

LG Uplus was also faulted for failing to notify affected customers individually within 24 hours of learning of the leak. The commission ordered it to strengthen the role of its privacy chief, rebuild its internal management plan, inspect its systems comprehensively — and follow through on the information-protection investments it had publicly promised.

Why it happened

  • An authentication system is the highest-value target a telco runs, and it was maintained least — attackers probe exactly where upkeep stopped.
  • Old webshells persist because nobody looks for them: a foothold planted in 2009 was still usable in 2023.
  • Notification duties are part of breach response; knowing about a leak and missing the 24-hour window to tell each victim is a separate sanctionable failure.
What it cost₩6.8B surcharge + ₩27M finecostly

The lesson

Security follows maintenance budgets, not org charts — a server that authenticates users and runs on unsupported software is a breach waiting to be attributed.

Sources

spotted an error? The club wants to know.

Comments · 0

    Sign in to join the comments.

    More like this

    Somewhere, someone solved the problem this company failed at. 2nd Opinion →