{"id":167099,"date":"2025-05-08T21:30:00","date_gmt":"2025-05-08T21:30:00","guid":{"rendered":"https:\/\/entertainment.runfyers.com\/index.php\/2025\/05\/08\/a-timeline-of-south-korean-telco-giant-skts-data-breach-techcrunch\/"},"modified":"2025-05-08T21:30:00","modified_gmt":"2025-05-08T21:30:00","slug":"a-timeline-of-south-korean-telco-giant-skts-data-breach-techcrunch","status":"publish","type":"post","link":"https:\/\/entertainment.runfyers.com\/index.php\/2025\/05\/08\/a-timeline-of-south-korean-telco-giant-skts-data-breach-techcrunch\/","title":{"rendered":"A timeline of South Korean telco giant SKT&#8217;s data breach | TechCrunch"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p id=\"speakable-summary\" class=\"wp-block-paragraph\">In April, South Korea\u2019s telco giant SK Telecom (SKT) was hit by a cyberattack that led to the theft of personal data on approximately 23 million customers, equivalent to almost half of the country\u2019s 52 million residents.<\/p>\n<p class=\"wp-block-paragraph\">At a National Assembly hearing in Seoul on Thursday, SKT chief executive Young-sang Ryu said about 250,000 users have switched to a different telecom provider following the data breach. He said he expects this number to reach 2.5 million, more than tenfold the current amount, if the company waives cancellation fees.<\/p>\n<p class=\"wp-block-paragraph\">The company could lose up to $5 billion (around \u20a97 trillion) over the next three years if it decides not to charge cancellation fees for users who want to cancel their contract early, Ryu said at the hearing.<\/p>\n<p class=\"wp-block-paragraph\">\u201cSK Telecom considers this incident the most severe security breach in the company\u2019s history and is putting forth our utmost effort to minimize any damage to our customers,\u201d a spokesperson at SKT told TechCrunch in an emailed statement. \u201cThe number of customers affected and the entity responsible for the hacking is under investigation,\u201d the spokesperson added.<\/p>\n<p class=\"wp-block-paragraph\">A joint investigation involving both public and private entities is currently underway to identify the specific cause of the incident.\u00a0<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.pipc.go.kr\/eng\/index.do\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">The Personal Information Protection Committee (PIPC)<\/a> of South Korea<a href=\"https:\/\/www.pipc.go.kr\/np\/cop\/bbs\/selectBoardArticle.do?bbsId=BS074&amp;mCode=C020010000&amp;nttId=11182\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"> announced<\/a><a href=\"https:\/\/www.mk.co.kr\/en\/it\/11311609\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"> on Thursday<\/a> that 25 different types of personal information, including mobile phone numbers and unique identifiers (IMSI numbers), as well as USIM authentication keys and other USIM data, had been exfiltrated from its central database, known as its home subscriber server. The compromised data can put customers at greater risk of <a href=\"https:\/\/techcrunch.com\/2025\/04\/25\/techcrunch-reference-guide-to-security-terminology\/#sim-swap\" target=\"_blank\" rel=\"noopener\">SIM swapping attacks<\/a> and government surveillance.<\/p>\n<p class=\"wp-block-paragraph\">After<a href=\"https:\/\/news.sktelecom.com\/211423\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"> its official announcement of the incident on April 22<\/a>, SKT has been offering SIM card protection and free SIM card replacements to prevent further damage to its customers.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWe detected possible information leakage regarding SIM on April 19,\u201d the spokesperson at SKT told TechCrunch. \u201cFollowing the identification of the breach, we immediately isolated the affected device while thoroughly investigating the entire system.\u201d<\/p>\n<p class=\"wp-block-paragraph\">\u201cTo further safeguard our customers, we are currently developing a system that can protect users\u2019 information through the SIM protection service while allowing them to use roaming services seamlessly outside of Korea by May 14,\u201d the spokesperson said.<\/p>\n<p class=\"wp-block-paragraph\">To date, SKT has not received any reports of secondary damage and no verified instances of customer information being distributed or misused on the dark web or other platforms, the company told TechCrunch.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-a-timeline-of-skt-s-data-breach\">A timeline of SKT\u2019s data breach<\/h2>\n<h3 class=\"wp-block-heading\" id=\"h-april-18-2025\"><strong>April 18, 2025<\/strong><\/h3>\n<p class=\"wp-block-paragraph\">SKT detected abnormal activities<a href=\"https:\/\/www.kisa.or.kr\/402\/form?postSeq=2497&amp;page=1#fnPostAttachDownload\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"> on April 18 at 11:20 p.m.<\/a> local time. SKT found unusual logs and signs of files having been deleted on equipment that the company uses for monitoring and managing billing information for its customers, including data usage and call durations.<\/p>\n<h3 class=\"wp-block-heading\" id=\"h-april-19-2025\"><strong>April 19, 2025<\/strong><\/h3>\n<p class=\"wp-block-paragraph\">The company identified a data breach on April 19 in its home subscriber server in Seoul, which typically houses subscriber information, including authentication, authorization, location, and mobility details.<\/p>\n<h3 class=\"wp-block-heading\" id=\"h-april-20-2025\"><strong>April 20, 2025<\/strong><\/h3>\n<p class=\"wp-block-paragraph\">SKT reported the cyberattack incident to<a rel=\"nofollow noopener\" href=\"https:\/\/www.kisa.or.kr\/402\/form?postSeq=2497&amp;page=1#fnPostAttachDownload\" target=\"_blank\"> <\/a><a href=\"https:\/\/www.kisa.or.kr\/EN\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Korea\u2019s cybersecurity agency<\/a>.<\/p>\n<h3 class=\"wp-block-heading\" id=\"h-april-22-2025\">April 22, 2025<\/h3>\n<p class=\"wp-block-paragraph\">SKT<a href=\"https:\/\/news.sktelecom.com\/211423\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"> confirmed on its website<\/a> that it detected suspicious activity, indicating a \u201cpotential\u201d data breach involving some information related to users\u2019 USIMs data.<\/p>\n<h3 class=\"wp-block-heading\" id=\"h-april-28-2025\"><strong>April 28, 2025<\/strong><\/h3>\n<p class=\"wp-block-paragraph\">SKT began replacing mobile SIM cards of 23 million users, but the company has <a href=\"https:\/\/www.chosun.com\/english\/industry-en\/2025\/04\/28\/LLXE3IYWEVG5BPXOJOB53ZRDHQ\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">faced\u00a0shortages in obtaining sufficient USIM cards<\/a> to fulfill its promise to provide free SIM card replacements.<\/p>\n<h3 class=\"wp-block-heading\" id=\"h-april-30-2025\">April 30, 2025<\/h3>\n<p class=\"wp-block-paragraph\">South Korean police <a target=\"_blank\" href=\"https:\/\/world.kbs.co.kr\/service\/news_view.htm?lang=e&amp;Seq_Code=192742\" rel=\"noreferrer noopener nofollow\">began investigating <\/a>SKT\u2019s suspected cyberattack on April 18.<\/p>\n<h3 class=\"wp-block-heading\" id=\"h-may-1-2025-nbsp-nbsp\">May 1, 2025\u00a0\u00a0<\/h3>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.chosun.com\/english\/companies-en\/2025\/05\/01\/GLW2X6WQ5ZETLDP7UKKQX2JWTU\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">According to local media reports<\/a>, many South Korean companies, including SKT, use Ivanti VPN equipment, and that the recent data breach may be connected to China-backed hackers.\u00a0\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Per<a href=\"https:\/\/biz.chosun.com\/en\/en-it\/2025\/05\/08\/33XJI3GP35AKPACBMABVFJJUMA\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"> a local media report<\/a>, SKT said it received a cybersecurity notice from <a rel=\"nofollow noopener\" href=\"https:\/\/www.kisa.or.kr\/EN\" target=\"_blank\">KISA<\/a> instructing the company to turn off and replace the Ivanti VPN.<\/p>\n<p class=\"wp-block-paragraph\">TeamT5, a cybersecurity company based in Taiwan,<a href=\"https:\/\/en.yna.co.kr\/view\/RPR20250424006800353?section=press-release\/index\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"> alerted the public to the worldwide threats posed<\/a> by a <a href=\"https:\/\/techcrunch.com\/2025\/04\/25\/techcrunch-reference-guide-to-security-terminology\/#advanced-persistent-threat-apt\" target=\"_blank\" rel=\"noopener\">government-backed group<\/a> linked to China, which allegedly took advantage of vulnerabilities in Ivanti\u2019s Connect Secure VPN systems to gain access to multiple organizations globally.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Some 20 industries have been affected, including automotive, chemical, financial institutions, law firms, media, research institutes, and telecommunications, across 12 countries, including Australia, South Korea, Taiwan, and the United States.<\/p>\n<h3 class=\"wp-block-heading\" id=\"h-may-6-2025-nbsp-nbsp\">May 6, 2025\u00a0\u00a0<\/h3>\n<p class=\"wp-block-paragraph\">A team of public and private investigators<a href=\"https:\/\/biz.chosun.com\/en\/en-it\/2025\/05\/06\/TV77C4C7EJER5BFI23DOVOOMGU\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"> discovered an additional eight types of malware<\/a> in SKT\u2019s hacking case. The team is currently investigating whether the new malware was installed on the same home subscriber server as the original four strains or if they are located on separate server equipment.<\/p>\n<h3 class=\"wp-block-heading\" id=\"h-may-7-2025-nbsp-nbsp\">May 7, 2025\u00a0\u00a0<\/h3>\n<p class=\"wp-block-paragraph\">Tae-won Chey, the chairman of SK Group, which operates SKT,<a href=\"https:\/\/www.reuters.com\/sustainability\/boards-policy-regulation\/sk-group-chairman-chey-apologises-massive-data-leak-sk-telecom-2025-05-07\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"> publicly apologized for the first time<\/a> for the data breach, some three weeks after the breach occurred.<\/p>\n<p class=\"wp-block-paragraph\">As of May 7, all eligible users have been signed up for the SIM protection service, except those living abroad using roaming services and temporarily suspended, the spokesperson told TechCrunch, adding that its fraud detection system has already been set up for all customers to prevent unauthorized login attempts using cloned SIM cards.<\/p>\n<h3 class=\"wp-block-heading\" id=\"h-may-8-2028\">May 8, 2028<\/h3>\n<p class=\"wp-block-paragraph\">SKT is currently assessing how to handle the cancellation fees for users affected by the data breach incident. About 250,000 users have switched to another telecom provider following the breach, according to the company\u2019s chief executive at a National Assembly hearing.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">South Korean authorities, meanwhile, announced that 25 types of personal information were leaked from the company\u2019s databases during the cyberattack.<\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/techcrunch.com\/2025\/05\/08\/a-timeline-of-south-korean-telco-giant-skts-data-breach\/\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In April, South Korea\u2019s telco giant SK Telecom (SKT) was hit by a cyberattack that led to the theft of personal data on approximately 23 million customers, equivalent to almost half of the country\u2019s 52 million residents. At a National Assembly hearing in Seoul on Thursday, SKT chief executive Young-sang Ryu said about 250,000 users [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":167100,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14],"tags":[],"class_list":{"0":"post-167099","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-tech"},"_links":{"self":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/167099","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/comments?post=167099"}],"version-history":[{"count":0,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/167099\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media\/167100"}],"wp:attachment":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media?parent=167099"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/categories?post=167099"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/tags?post=167099"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}