CSIDB logo
Incident

SK Telecom

Incident posture

Attack window
Apr 2025
Location
South Korea
Status
Unknown
CIA posture
Available to members
Updated
2026-09-01 11:30

Linked entities

Victim
SK Telecom
Threat actors
0 actors
Sources
5 sources

Timeline

Occurred
Apr 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A major South Korean mobile operator suffered a significant cyberattack when hackers infiltrated internal systems and installed malware, which was detected shortly before midnight on a Saturday. The breach involved a USIM platform and exposed the personal information of millions of subscribers, with attackers having maintained undetected access since mid-2022, creating widespread risk of SIM cloning and identity theft. The company removed the malware, isolated affected equipment, reported the incident to the Korea Internet & Security Agency, and replaced SIM cards for all subscribers while offering discounted bills and free data. The incident triggered a record regulatory fine from the Personal Information Protection Commission and led to substantial financial losses, including a sharp decline in net profit, a rejected consumer agency compensation proposal, and ongoing legal challenges as the operator sought to limit total compensation costs.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

In April 2025, SK Telecom, South Korea's largest mobile operator, confirmed that its internal systems had been breached by a hacking attack with indications of a possible data leak involving USIM (Universal Subscriber Identity Module) cards. The company detected suspicious activity around 11 p.m. on Saturday, April 19, 2025, which revealed that hackers had infiltrated its internal systems and installed malware. Upon detection, SK Telecom immediately removed the malware, isolated affected equipment, and launched a full-scale investigation across its systems. The company reported the case to the Korea Internet & Security Agency (KISA) and stated that there were no confirmed cases of the leaked information being misused at that time. Following the incident, the Ministry of Science and ICT and KISA launched an investigation into the scope and cause of the data breach while forming an emergency response team. KISA experts were dispatched to the site to provide technical support aimed at identifying the cause and preventing further damage, and the ministry requested that SK Telecom preserve and submit relevant data related to the breach. As a precautionary measure, SK Telecom reinforced its defense against illegal USIM swaps and abnormal authentication attempts and offered a USIM protection service free of charge to customers upon request.

The breach proved to be far more extensive than initially confirmed. According to a subsequent Tokio Marine HCC International (TMHCCI) cyber incidents report covering 2025, the cybersecurity breach exposed the data of nearly 27 million users, creating widespread risk of SIM-cloning and identity theft. The report further revealed that attackers had maintained undetected access to SK Telecom's systems since June 2022, meaning the threat actors had remained inside the network for nearly three years before being discovered. Other reports cited in subsequent financial disclosures described the incident as a breach of SK Telecom's USIM platform that led to the exposure of the personal information of 23 million subscribers, with the precise number varying between sources. The incident drew the attention of South Korean regulators, as breaches involving USIM data raised concerns about the potential for SIM-swapping attacks, fraudulent authentication, and broader identity theft affecting nearly a quarter of South Korea's population. The scope of the exposure and the duration of the unauthorized access positioned the SK Telecom breach as one of the most significant cyber incidents of 2025 globally, alongside events affecting Marks & Spencer, Jaguar Land Rover, Amazon Web Services, and Oracle Corporation.

In the immediate aftermath, SK Telecom replaced the SIM cards of all subscribers and offered them discounted monthly bills along with 50GB of free data until the end of 2025. The company also stated it would strengthen its company-wide security system to prevent recurrence and implement measures to restore customer trust. Regulators pursued enforcement actions under South Korea's revised Personal Information Protection Act of 2023, with the Personal Information Protection Commission (PIPC) issuing SK Telecom with a record-breaking fine of approximately KRW134.8 billion (around $91-92.8 million) in August 2025. The PIPC fine exceeded the combined KRW100 billion ($67.75-68.88 million) that the agency had previously imposed on Google and Meta in 2022. In November, the PIPC ordered the company to pay 3,998 people who had joined the mediation process KRW300,000 ($206.63) each, with the total cost of that offer amounting to KRW1.2 billion ($826 million), alongside requirements to improve cybersecurity and protect internal data. SKT refused to accept the compensation plan out of concern that accepting it would open the door to a flood of claims from the 23 million affected customers, potentially driving total costs to approximately KRW7 trillion ($4.8 billion).

The financial impact on SK Telecom was severe. Full-year 2025 earnings showed a 73 percent drop in net profit to KRW375 billion ($260 million), down from KRW1.4 trillion the previous year, while operating income slid 41 percent to KRW1.07 trillion ($730 million) and revenue declined 4.7 percent to KRW17.1 trillion ($11.7 billion). CFO Park Jong-seok, who was installed last October along with new CEO Jung Jai-hun, attributed the collapse in earnings to the data leak, citing substantial costs from paying compensation and carrying out business restructuring. Customers fled in the second quarter of 2025, though they subsequently returned, with the company adding 230,000 5G subscribers in the fourth quarter to reach a total of 17.49 million, above the first-quarter level of 17.2 million. SKT spent KRW1.2 trillion ($812.3 million) on compensating users and reforming its data protection system, though the company did not pay a dividend for the fourth quarter. The operator also rejected a separate compensation proposal from the Korea Consumer Agency (KCA), which had offered KRW100,000 ($68.87) per victim through a mediation process involving approximately 50 people. SKT estimated that accepting the proposal would have led to total compensation costs of KRW2.3 trillion ($1.58 billion) due to considerable ripple effects on the broader customer base. The rejection of the KCA proposal automatically closed the mediation process, with participating victims retaining the option to file lawsuits.

In January 2026, SK Telecom filed a lawsuit with the Seoul Administrative Court challenging the KRW134.8 billion fine on the last day of the 90-day appeal period. The operator was expected to argue in court that it had already spent KRW1.2 trillion on compensating users and reforming its data protection system, that this spending should be taken into account when calculating the fine, and that users had not suffered any financial loss as a result of the data leak. The company stated it was seeking a detailed judicial review of whether the PIPC's penalty was appropriate. The dispute over compensation remained far from finalized as of early 2026, with both the PIPC arbitration outcome and the KCA mediation process either rejected or unresolved. Rival Korean operators benefited from SK Telecom's missteps, as LG Uplus reported a 5.7 percent uplift in revenue and 3.4 percent higher operating profit for the full year, with total MNO and wholesale wireless subscribers up 7.7 percent. Competitor KT Corp also suffered a customer data breach in 2025, though the consequences for SKT were described as more pronounced given the scale of the USIM exposure and the duration of the attackers' presence in the network.

Sources

Sources available to members: 5 sources.

CSIDB