The encyclopedia · Legal & Compliance · Legal decision · 2021–2025
SK Telecom fined a record 134.8 billion won for SIM data leak affecting 23 million users
SK Telecom was fined a record $97.2M after 26.1 million SIM keys were found stored in plain text and security patches left unapplied for years.
SK Telecom · 2025-08-28
What happened
SK Telecom, South Korea's largest telecommunications carrier with 23 million subscribers, was hit with a record 134.8 billion won ($97.2 million) privacy fine on August 28, 2025. The Personal Information Protection Commission (PIPC) called it the largest penalty ever imposed under the Personal Information Protection Act, citing 'basic security failures and poor management.'
The breach began as early as 2021, with attackers remaining undetected inside SK Telecom's network for four years. When the hack was disclosed in April 2025, it emerged that the attackers had accessed 25 categories of personal data from LTE and 5G subscribers, including phone numbers, International Mobile Subscriber Identity (IMSI) numbers, device identifiers (IMEI), and USIM authentication keys.
The PIPC investigation found that SK Telecom had linked its internet, management, and internal networks onto the same system without restricting external access. Management servers were unnecessarily connected to the Home Subscriber Server (HSS), where the breach occurred. The company failed to encrypt 26.1 million SIM authentication keys, storing them in plain-text databases. It ignored intrusion detection logs and did not apply available security patches, including one from 2016. The chief privacy officer's role was limited to IT services, leaving telecom infrastructure outside oversight.
The breach forced SK Telecom to launch a free USIM card replacement programme for all 23 million subscribers, causing temporary shortages of SIM cards across the country and triggering a government investigation. The record fine sent shockwaves through South Korea's telecom industry, which had never faced a privacy penalty of this magnitude.
Why it happened
- SK Telecom linked its internet, management, and internal networks on the same system without restricting external access, allowing attackers to pivot from the internet to the core subscriber database
- The company stored 26.1 million SIM authentication keys in plain-text databases without encryption, and failed to apply security patches including one from 2016 for a known vulnerability
- The chief privacy officer's role was limited to IT services, leaving the entire telecom infrastructure outside privacy oversight
The lesson
A privacy officer who cannot touch the network is a title, not a defence. Plain-text SIM keys on an unsegmented network make a record fine not a surprise but an invoice for deferred maintenance.
Sources
- Korea Herald — SK Telecom fined record 134.8 billion won; 23 million users affected; security failures detailed (plain-text SIM keys, linked networks, ignored patches, 2016 vulnerability)
- Wikipedia — SK Telecom privacy breach background; breach timeline (2021–2025); USIM authentication keys, IMSI, IMEI, phone numbers; free USIM card replacement programme
spotted an error? The club wants to know.
More like this
Three Korean carriers ran a 'situation room' to carve up the porting market — ₩96.3B fine
Kakao Mobility blocked rival taxi calls; Korea fined it ₩15.1 billion
Korea fined Qualcomm ₩1.03 trillion — a record that survived to the Supreme Court
Somewhere, someone solved the problem this company failed at. 2nd Opinion →

Comments · 0
Sign in to join the comments.