Skip to main content
Breach Signal

Breach report

Telecom

SK Telecom

SK Telecom says malware breach lasted 3 years, impacted 27 million numbers

Malware hidden on SK Telecom servers for nearly three years exposed SIM authentication keys for about 27 million subscriber numbers, forcing South Korea's largest carrier to replace SIM cards nationwide and pay a record fine.

Reported by BleepingComputer

Records exposed

26.9M

About 27 million subscriber identities

Scale vs. largest on file

When
2025 (intrusion began 2022)
How they got in
Web shell and malware implanted on core network servers
Sector
Telecom

In April 2025, SK Telecom, South Korea's largest mobile carrier, detected malicious code on its systems and reported that subscriber SIM data had been leaked. The carrier said it identified the anomaly on the evening of April 18 and notified authorities within days. A joint government and private investigation later found that the attackers had first planted a web shell on company servers in June 2022, nearly three years before the intrusion was discovered.

Investigators reported finding 25 types of malware across 23 servers by May 2025, including variants of BPFDoor, a stealthy backdoor associated with espionage-focused hacking groups. Because SK Telecom had not been logging activity on some affected systems until December 2024, any data taken before then could not be traced. The attackers reached the home subscriber server, a central database that authenticates phones on the network.

The leaked data covered about 26.95 million subscriber identifiers, roughly half of South Korea's mobile market. It included IMSI numbers, which identify a SIM card on the network, and USIM authentication keys, the secrets used to verify that a SIM is genuine. Together these could in theory let criminals clone SIM cards and hijack phone numbers. Some server logs also held device IMEI numbers. The company said there was no confirmed case of damage from cloned SIMs.

The response was dramatic. SK Telecom offered free SIM replacements to all subscribers, leading to long lines outside stores and shortages of cards, and rolled out a service to block unauthorized SIM changes. SK Group chairman Chey Tae-won publicly apologized. Hundreds of thousands of customers switched carriers, and the government ordered the company to waive early termination fees. In August 2025, the Personal Information Protection Commission imposed a fine of about $97 million, the largest in the country's history for a data breach, citing weak separation between internet-facing and internal systems, unmonitored intrusion alerts, plaintext credentials and unencrypted authentication keys.

The breach is one of the most serious known compromises of telecom core infrastructure. Because SIM keys underpin identity verification for banking and government services in South Korea, it raised national security concerns and prompted scrutiny of other carriers. It also showed how long a well-hidden intruder can persist in an under-monitored network.

More from the wire

More in Telecom.

All 107 reports

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life’s most important information stays protected and accessible.