Back to the archive

The encyclopedia · Legal & Compliance · Legal decision · 2021–2025

SK Telecom fined a record 134.8 billion won for SIM data leak affecting 23 million users

SK Telecom was fined a record $97.2M after 26.1 million SIM keys were found stored in plain text and security patches left unapplied for years.

SK Telecom · 2025-08-28

What happened

SK Telecom, South Korea's largest telecommunications carrier with 23 million subscribers, was hit with a record 134.8 billion won ($97.2 million) privacy fine on August 28, 2025. The Personal Information Protection Commission (PIPC) called it the largest penalty ever imposed under the Personal Information Protection Act, citing 'basic security failures and poor management.'

The breach began as early as 2021, with attackers remaining undetected inside SK Telecom's network for four years. When the hack was disclosed in April 2025, it emerged that the attackers had accessed 25 categories of personal data from LTE and 5G subscribers, including phone numbers, International Mobile Subscriber Identity (IMSI) numbers, device identifiers (IMEI), and USIM authentication keys.

The PIPC investigation found that SK Telecom had linked its internet, management, and internal networks onto the same system without restricting external access. Management servers were unnecessarily connected to the Home Subscriber Server (HSS), where the breach occurred. The company failed to encrypt 26.1 million SIM authentication keys, storing them in plain-text databases. It ignored intrusion detection logs and did not apply available security patches, including one from 2016. The chief privacy officer's role was limited to IT services, leaving telecom infrastructure outside oversight.

The breach forced SK Telecom to launch a free USIM card replacement programme for all 23 million subscribers, causing temporary shortages of SIM cards across the country and triggering a government investigation. The record fine sent shockwaves through South Korea's telecom industry, which had never faced a privacy penalty of this magnitude.

Why it happened

  • SK Telecom linked its internet, management, and internal networks on the same system without restricting external access, allowing attackers to pivot from the internet to the core subscriber database
  • The company stored 26.1 million SIM authentication keys in plain-text databases without encryption, and failed to apply security patches including one from 2016 for a known vulnerability
  • The chief privacy officer's role was limited to IT services, leaving the entire telecom infrastructure outside privacy oversight
What it cost1,348亿 won fine — largest privacy penalty in Korea's historycostly

The lesson

A privacy officer who cannot touch the network is a title, not a defence. Plain-text SIM keys on an unsegmented network make a record fine not a surprise but an invoice for deferred maintenance.

Sources

spotted an error? The club wants to know.

Comments · 0

    Sign in to join the comments.

    More like this

    Somewhere, someone solved the problem this company failed at. 2nd Opinion →