Rotten Company

Korean privacy regulator fined SK Telecom after mass USIM-data breach

Company: SK Telecom Co., Ltd.

Summary

South Korea’s Personal Information Protection Commission found SK Telecom had inadequate security and breach notification after a hacker penetrated its systems and exfiltrated subscriber data in April 2025. It assessed 23,244,649 affected people and imposed a KRW 134.791 billion administrative fine in August 2025. The company reportedly challenged the penalty in court in 2026, so the sanction is recorded as unresolved. Direct regulator source: https://pipc.go.kr/np/cop/bbs/selectBoardArticle.do?bbsId=BS074&mCode=C020010000&nttId=11453 ; reporting on challenge: https://www.boannews.com/news/articleView.html?idxno=141569