Yazılar

South Korea Fines SK Telecom Over Massive Data Breach Affecting Millions

South Korean authorities on Friday penalised SK Telecom, the country’s largest mobile operator, for its failure to prevent a massive data leak involving nearly 27 million pieces of user data, blaming the company for negligence and failure to meet regulatory standards.

Government Findings and Penalties

The Ministry of Science and ICT found that SK Telecom did not adequately protect USIM (universal subscriber identity module) data and violated cybersecurity regulations. The ministry’s investigation followed SK Telecom’s disclosure in April that it had been the target of a malware attack, leading to the breach.

As a result, SK Telecom faces:

  • A fine of up to 30 million won (~$22,000)

  • A requirement to implement quarterly security audits

  • Mandates for the CEO to directly oversee data governance

  • Increased investment and staffing in cybersecurity

The ministry called the situation a “wake-up call” for the nation’s broader digital infrastructure and urged stronger protections across the telecom sector.

Company Response and Compensation Measures

Following the announcement, SK Telecom said it would invest 700 billion won (~$513 million) over the next five years to bolster data protection. The company also offered:

  • A 50% discount on August subscription fees for its 24 million customers

  • Free USIM replacements to all affected users at 2,600+ retail stores

  • A public apology from CEO Ryu Young-sang, who said the company takes full responsibility for the incident

To reflect the financial impact, SK Telecom has cut its 2025 revenue forecast by 800 billion won, citing approximately 500 billion won in costs linked to the customer compensation package.

Broader Fallout and Public Concern

The breach has caused widespread alarm among SK Telecom’s 23 million active users, many of whom fear the potential theft of personal and financial information. As of late June, around 9.39 million users had replaced their USIM cards in response.

SK Group Chairman Chey Tae-won also apologised last month, vowing to take responsibility and restore public trust.

South Korea’s handling of the incident is likely to influence future regulatory scrutiny and standards in the country’s telecom and tech sectors, as data privacy becomes an increasingly critical issue in both corporate accountability and public confidence.

SK Group Chairman Chey Apologizes for Major SK Telecom Data Breach, Pledges Security Overhaul

SK Group Chairman Chey Tae-won issued a public apology on Wednesday following a significant data breach at SK Telecom, South Korea’s largest mobile carrier, which has sparked alarm among its 23 million users over potential theft of personal and financial information.

The breach, detected on April 18, was attributed to a malware attack, and has led to widespread concern and customer action. Thousands have visited SK Telecom outlets to replace their USIM (Universal Subscriber Identity Module) cards, which the company is offering free of charge.

Chey, speaking for the first time since the breach became public, said, I believe we need to look at this as a matter of national defence, not just (data) security.” He acknowledged a need for a more comprehensive and strategic approach to cybersecurity, noting that the company previously treated such threats as a standard IT issue handled internally.

In response to the breach, SK Telecom has launched a USIM Protection Service, which it says provides equivalent protection to replacing the USIM card. Chey confirmed he enrolled in the service but had not yet replaced his own card.

The chairman also pledged a full-scale security review involving external cybersecurity experts to prevent similar incidents in the future and restore public trust in the company’s data protection capabilities.