Data breach
SK Telecom
- Records
- 15,025
- Breach date
- 19 April 2025Estimated
- Added
- 20 March 2026
What was exposed
1 type of data
- Email addresses15,025
About this breach
SK Telecom, South Korea's largest mobile carrier, suffered a malware intrusion that led to the theft of SIM card-related data covering roughly 27 million subscribers. According to South Korea's Ministry of Science and ICT, attackers exfiltrated 9.82 GB of data, about 26.96 million IMSI records, from the carrier's Home Subscriber Server system. The investigation team has indexed 15,025 rows from this breach, with email addresses present in an undetermined quantity, and estimates the attack occurred on April 19, 2025. No hacking group has publicly claimed responsibility in available reporting. The intrusion itself went undetected for years: investigators traced the first infection back to 2022, with the privacy regulator later citing infiltration as early as August 2021.
June 15, 2022: A joint public-private investigation later found the initial infection occurred on this date, when malware was installed in SK Telecom's Integrated Customer Authentication System.
April 18, 2025: The Ministry of Science and ICT's final report dates the data exfiltration to this night, when an unusually large outbound transfer was detected; SK Telecom's own notice described the discovery as occurring around 11 p.m. on April 19.
April 20, 2025: SK Telecom reported the incident to the Korea Internet & Security Agency at 4:46 p.m., missing the 24-hour statutory reporting window.
April 23, 2025: The Ministry of Science and ICT formed a public-private joint investigation team.
May 8, 2025: The Personal Information Protection Committee confirmed 25 types of data were leaked and ordered notification of roughly 25.64 million subscribers.
August 28, 2025: The privacy regulator fined SK Telecom 134.8 billion won, about $97 million, a record penalty in South Korea.
What Information Was Compromised?
Our analysis found the following data types in this breach: email. SK Telecom's breach notice and subsequent government findings describe far more. The company confirmed that USIM-related information was suspected to have leaked, including phone numbers, IMSI identifiers, and SIM authentication keys stored in its Home Subscriber Server. The Personal Information Protection Committee later confirmed 25 categories of leaked data.
South Korea's final government investigation found that two infected servers temporarily stored IMEI numbers and personal details such as names, birth dates, phone numbers, and email addresses in plain text, and one server stored call detail records. Firewall logs showed no evidence those records were exfiltrated during certain periods, but investigators could not rule out leakage during gaps in the logs.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The most serious risk involves SIM cloning. With leaked IMSI numbers and authentication keys, attackers can potentially activate burner phones to intercept a victim's calls and text messages. That could allow criminals to receive one-time passwords and access mobile banking or stock trading apps, authorize micropayments, or take over social media accounts. SK Telecom has said its security systems make such misuse unlikely, and the government investigation noted firewall logs showing no evidence of some exfiltration, but no one can guarantee the data will never be abused. Stolen names, phone numbers, and email addresses can also fuel convincing phishing messages.
What Is SK Telecom Doing in Response?
The company removed the malware, isolated suspect equipment, and blocked unauthorized SIM changes and abnormal authentication attempts. It offered free USIM replacements, automatic enrollment in its SIM protection service, and upgrades to its fraud detection system, and it pledged a 700 billion won investment in security improvements. The Ministry of Science and ICT also determined that subscribers can invoke the early-termination penalty waiver in SK Telecom's terms because the company failed its duty of care. Regulators found the company stored server passwords in plain text, left the USIM authentication key unencrypted, and notified customers late.
What Should You Do If You Were Affected?
If you were an SK Telecom subscriber in 2025, request the free SIM replacement and confirm you are enrolled in the SIM protection service. Watch for unusual behavior on your phone line, such as calls or texts you did not send, and treat unexpected messages asking for codes or credentials as suspicious. Monitor bank and payment accounts for activity you did not authorize. If you want to leave the carrier, the regulator's determination means the early-termination penalty waiver may apply.
In the news
- Security Affairs: Millions of SK Telecom customers potentially at risksecurityaffairs.com (opens in a new tab)
- Security Affairs: SK Telecom breach began in 2022securityaffairs.com (opens in a new tab)
- Ministry of Science and ICT: Final investigation resultsmsit.go.kr (opens in a new tab)
- Donga.com: SK Telecom hacked, exposing data of 23 million subscribersdonga.com (opens in a new tab)
- Reuters: South Korea agency fines SK Telecom $97 million
