Back
Back to Blog

The Real Cost of a Data Breach: Theft, Regulatory Fines, and Criminal Complaints

On this page

South Korea’s Personal Information Protection Commission, or PIPC, fined KT, one of the country’s largest telecommunications providers, ₩53.979 billion after finding that weaknesses in its femtocell security controls allowed an attacker to access the mobile network, expose subscriber information, and carry out approximately ₩240 million in unauthorized payments.

The same regulatory decision also addressed a separate malware incident at KT and a personal information leak involving LG U+, another major South Korean telecommunications provider. KT was referred for criminal investigation over alleged non-reporting, deleted logs, and false statements. LG U+ was referred to law enforcement after relevant servers were reinstalled or disposed of before investigators could establish the full scope of the leak.

KT Femtocell Breach Led to Subscriber Data Exposure and Payment Fraud

The primary KT incident involved femtocells, small base stations used to improve mobile coverage in homes, offices, underground areas, and other locations with weak signals.

View the full KT femtocell breach report in VenariX.

According to the regulator, the attacker extracted a certificate from a lost KT femtocell, installed it on a self-built device, and connected to KT’s mobile network. The attacker then caused customer devices to communicate through the unauthorized femtocell and intercepted information exchanged with KT’s internal systems.

The unauthorized access continued for approximately 11 months, from October 8, 2024, through September 5, 2025.

The regulator identified several control failures:

  • Femtocell certificates remained valid for 10 years.

  • KT did not restrict the IP addresses allowed to connect to the internal network.

  • Cell IDs were not adequately managed.

  • A path existed that bypassed the femtocell management server.

  • KT lacked effective monitoring for unauthorized or abnormal femtocell connections.

The breach affected 16,647 customers and exposed core mobile subscriber identifiers, including phone numbers, IMSI values, and IMEI values. The attacker also captured authentication messages used to approve mobile payments, which enabled roughly ₩240 million in fraudulent transactions across 368 victims.

PIPC responded with a ₩53.979 billion fine. The regulator also required KT to address weaknesses in its mobile network controls, reassess vulnerabilities across its telecommunications infrastructure, strengthen privacy oversight, and broaden the scope of its ISMS-P certification.

The Importance of Financial Loss Categories in Cybersecurity

The approximately ₩240 million in fraudulent payments represents the harm caused directly by the attacker. The ₩53.979 billion fine represents the cost of the company’s own control and governance failures.

That distinction is critical.

The fraud may still have occurred even in an environment with stronger controls. The regulatory penalty, however, arose from findings that KT had failed to adequately restrict, monitor, and govern access to its mobile network. If the regulator had found that appropriate safeguards were in place and that KT had met its legal obligations, the company could have avoided much of the financial exposure created by the enforcement action.

In other words, the largest financial consequence was the cost of failing to prevent, detect, and properly manage the incident, rather than the amount stolen.

This is why cyber losses should be categorized by source. Financial theft measures attacker-driven harm. Regulatory penalties measure the financial consequences of compliance and control failures. Legal expenses, recovery costs, lost revenue, and operational disruption each point to different weaknesses and different opportunities for risk reduction.

For security and risk leaders, that classification changes the question from “How much did the breach cost?” to “Which part of the cost was unavoidable, and which part could have been reduced through better controls, governance, and incident response?”

VenariX separates these categories so organizations can identify where cyber incidents are generating the greatest avoidable financial exposure.

The same regulatory decision addressed two other incidents involving KT and LG U+. In both cases, the regulator’s concern extended beyond the underlying compromise to how evidence was handled after the incident.

KT had identified a malware infection in March 2024 but did not report it to the government. Investigators later found that logs from 10 compromised servers had been deleted and that KT had initially provided inaccurate information about the records it retained.

LG U+ faced a separate investigation after employee and partner data appeared publicly. By the time the regulator began its review, operating systems had been reinstalled, and relevant servers had been disposed of, preventing investigators from determining how the data was accessed or whether additional information had been exposed.

KT was referred for criminal investigation over alleged non-reporting and obstruction. LG U+ was referred to law enforcement over the destruction of evidence before the investigation began.

These findings introduce another category of avoidable exposure. The initial compromise may be caused by an attacker, but the legal consequences that follow can be materially affected by decisions made during incident response.

Deleting logs, rebuilding systems before forensic collection, delaying notification, or providing incomplete information can:

  • Prevent the organization from establishing the scope of the incident.

  • Weaken its ability to demonstrate that appropriate controls were in place.

  • Delay containment and notification.

  • Increase regulatory scrutiny.

  • Create separate allegations of obstruction or non-compliance.

Evidence preservation is therefore not only a forensic requirement, but also part of legal, regulatory, and financial risk management.

Breaking Down the Cost of a Cyber Incident

The KT case shows why a single “total loss” figure provides limited value.

The fraud loss, regulatory fine, potential legal costs, investigation costs, and any operational or recovery expenses arose from different causes. They also point to different corrective actions:

  • Financial theft points to weaknesses that allowed the attacker to monetize access.

  • A regulatory fine points to failures in controls, governance, compliance, or oversight.

  • Legal costs may reflect litigation, investigations, or criminal proceedings.

  • Response and recovery costs show what the organization had to spend to contain and remediate the incident.

  • Operational disruption measures the effect on the business itself.

When these amounts are combined, the result may show the size of the impact, but not what created it. This is why VenariX records each disclosed financial consequence against the specific cyber incident that caused it and assigns the amount to a defined loss category.

Categorizing losses makes the data useful. It allows security and risk leaders to determine whether the highest costs are being driven by attacker activity, weak controls, poor incident handling, regulatory enforcement, or business interruption.

That distinction also changes where organizations invest. A company facing repeated financial theft may prioritize fraud prevention and identity controls. A company facing large regulatory penalties may need stronger governance, access control, evidence retention, and compliance oversight.

Closing

Cyber incident costs are often presented as a single figure. That approach hides the difference between losses caused by the attacker and losses created by the organization’s own controls, governance, and response decisions.

The KT case shows how a relatively smaller fraud loss can be followed by a far larger regulatory penalty. The related KT and LG U+ findings show that evidence handling and reporting decisions can create additional legal exposure even after the initial compromise has occurred.

VenariX separates those outcomes so organizations can identify where cyber incidents are producing the greatest financial exposure, and which costs may have been reduced through stronger controls, governance, and incident response.


Analyze cyber incidents by financial loss category, regulatory action, attack method, affected systems, and more in VenariX.

Explore VenariX →

VenariX

Every security decision,
backed by real data.

Start with a free plan or try Pro free for one week.