The encyclopedia · Engineering & Operations · Technical decision · 2025
SK Telecom found hackers in 2022 and didn't investigate — it ran three more years
SK Telecom spotted intruders on its server in 2022, didn't investigate — the malware stayed until 2025, stealing 27 million SIM records, and cost it its lead.
SK Telecom · 2025-04
What happened
SK Telecom's Home Subscriber Server — the system that manages every subscriber's identity and authentication on the network — was first breached in August 2021 and again in June 2022, when attackers planted malware that later matured into variants of a Linux backdoor known as BPFDoor. In February 2022, SK Telecom discovered that hackers had reached that server. Per Korea's Ministry of Science and ICT, the company did not investigate the finding. The server, holding subscribers' authentication data, remained accessible without proper authentication checks for years afterward.
SK Telecom did not begin logging activity on the compromised servers until December 3, 2024 — meaning any data taken between June 2022 and that date left no record the company could later examine. The company only detected the intrusion on April 19, 2025, after noticing unusual traffic patterns, and disclosed it publicly on April 22. By then, 23 servers were found carrying 25 distinct types of malware.
The Personal Information Protection Commission's investigation, which concluded in August 2025, found the failures were basic and repeated: SK Telecom stored 26.1 million USIM authentication keys unencrypted, used plaintext administrator credentials, and had ignored security patches dating back to 2016. The regulator fined the company 134.8 billion won (about $97 million) — the largest penalty it has issued since forming in 2020 — and cited SK Telecom for violating a government order to preserve forensic evidence, a matter it referred for criminal investigation.
The commercial fallout outran the fine. In May 2025 alone, 933,509 Korean subscribers switched mobile carriers — a 77% jump over the historical monthly average — with KT and LG U+ absorbing the bulk of the defections and SK Telecom's market share falling below 40% for the first time in its history. The company posted a 90% drop in Q3 2025 operating profit, ending a 25-year streak of consistent earnings growth, and offered free SIM replacements to all subscribers while temporarily halting new sign-ups to manage the fallout.
Why it happened
- SK Telecom discovered hackers had reached its subscriber server in February 2022 and, per the ministry's finding, did not investigate — the intrusion continued for three more years.
- The server storing subscriber authentication data could be accessed without proper authentication checks, and 26.1 million USIM keys were stored unencrypted rather than protected.
- Security patches were left unapplied going back to 2016, and admin credentials were kept in plaintext — failures the regulator called basic rather than sophisticated evasion.
- Server activity logging that would have shown what data was taken did not start until December 2024, leaving roughly two and a half years of the intrusion with no record of what left.
The lesson
Finding an intrusion and not following up is a decision, not an oversight — the gap between detection and investigation is where a contained incident turns into a three-year breach.
Aftermath
SK Telecom was fined 134.8 billion won by the PIPC in August 2025 and referred for criminal investigation over the preserved-evidence violation; it has filed suit to challenge the fine. It offered free USIM replacements, automated blocking of unauthorized SIM and device changes, and temporarily stopped accepting new customers. By late 2025 it had lost hundreds of thousands of subscribers and posted its first major earnings collapse in 25 years, with analysts projecting losses continuing into 2026.
Sources
- BleepingComputer — SK Telecom says malware breach lasted 3 years, impacted 27 million numbers
- Korea Herald — SK Telecom hit with record privacy fine after massive data leak
spotted an error? The club wants to know.
More like this
Kakao ran South Korea's messaging on one data center — a fire took the country offline
Optus leaves an API exposed, and 10 million Australians' ID data leaks
KT advertised 5G at 20Gbps — real speeds were 3% of that, and the fine stands
Somewhere, someone solved the problem this company failed at. 2nd Opinion →

Comments · 0
Sign in to join the comments.