logo
[Editorial] Data breach, trust broken

[Editorial] Data breach, trust broken

Korea Herald24-04-2025
SK Telecom's hacking incident exposes cracks in South Korea's digital armor
In a hyper-connected nation where smartphones function as an extension of personal identity, the recent data breach at SK Telecom — a company with over 23 million subscribers — is more than another cybersecurity mishap. It is a stark wake-up call for consumers, regulators and telecom providers alike.
SK Telecom disclosed Tuesday that a hacking incident had resulted in the partial leakage of universal subscriber identity module data — critical for authenticating mobile users. The breach stemmed from a malicious code attack detected Saturday, which infiltrated parts of its Home Subscriber Server.
The company insisted that no resident registration numbers or bank account details were exposed, but that is scant consolation. USIM authentication keys, while not as overtly sensitive, can be weaponized in SIM swapping scams, identity theft and unauthorized access to financial services.
This is not an isolated event. LG Uplus suffered a breach in 2023, affecting 300,000 customers. KT saw even larger breaches, impacting 8.3 million users in 2012, followed by 12 million in 2014. South Korea's three telecom giants have all experienced large-scale data leaks. Public trust should be on the line. Yet the corporate playbook remains painfully predictable: a formal apology, vague promises to boost cybersecurity and then silence until the next breach.
What sets the SK Telecom breach apart is not just its scope but its systemic implications. Telecom companies increasingly resemble public utilities. Smartphones today are not mere gadgets; they are digital vaults housing everything from personal chats to biometric gateways to banking apps. The data they hold is not simply metadata — it is a mirror of identity.
SK Telecom acted by deleting the malicious code and offering a free USIM protection service. However, customers were only notified via text four days later. In the world of cybersecurity, where every hour can spell the difference between containment and catastrophe, that delay reflects a mindset dangerously out of sync with the digital age.
Assurances that no misuse has been reported offer little reassurance. Forensic analysis is ongoing, and the full impact of the breach remains murky. In the meantime, one uncomfortable question looms: Are South Korea's corporations doing enough to protect user data? The track record suggests not.
Regulators are now investigating and considering sanctions. South Korea's revised Personal Information Protection Act allows fines of up to 3 percent of related revenues. But past enforcement has lacked teeth. Kakao was fined a record 15.1 billion won ($10.5 million) last year — a sum that barely grazed its 7.87 trillion won in revenue. The three major telecoms posted combined operating profits of 3.5 trillion won in 2024; SK Telecom alone earned 1.82 trillion won.
Penalties are increasing. So are the breaches. It's clear that fines alone will not suffice. What's needed is structural change — from mandatory investment in cybersecurity to regular independent audits. More fundamentally, a cultural shift is overdue: companies must stop treating data as a monetizable asset and start seeing it as the core of user trust.
Speculation is already circulating about foreign actors, including North Korea, being behind recent breaches. Whether true or not, the growing sophistication of cyberattacks underscores a simple truth — the threat is global, but the defense starts at home.
South Korea has long prided itself on its digital prowess, from advanced mobile services to nationwide broadband infrastructure. Yet that ambition has not been matched by cybersecurity rigor. The cycle of breaches followed by boilerplate apologies must end. It is time for Korean corporations to treat data protection not as a compliance box to tick, but as a pillar of public trust. Consumers have handed over their digital lives. The least they deserve in return is robust protection.
Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

Google pushes again for map exports as Korea weighs security risks
Google pushes again for map exports as Korea weighs security risks

Korea Herald

time20 hours ago

  • Korea Herald

Google pushes again for map exports as Korea weighs security risks

US tech giant seeks approval to export mid-resolution map data, pledging masking measures, government cooperation US IT giant Google has expressed its willingness to purchase satellite images of South Korea with sensitive areas blurred out, in a move aimed at addressing national security concerns as the government deliberates on whether to allow the export of high-precision map data. In a blog post published Tuesday, Google emphasized its mission to 'organize the world's information and make it universally accessible and useful,' pointing to Google Maps as one of its flagship products designed to help users navigate and explore their surroundings efficiently. "More than 10 million international visitors travel to Korea each year, yet they face inconveniences the moment they arrive," Google said, referring to the fact that the IT giant's turn-by-turn navigation feature is not available here — a rare exception globally. Google said it has been in close dialogue with the Korean government to ensure the full functionality of its map services and aimed to clarify recent 'misunderstandings' surrounding its request to export map data. 'The map requested for export is not the 1:1,000-scale high-resolution map but rather the 1:5,000-scale national base map,' the company said, adding that the data had already passed the government's security review process. 'It is the same data used by most domestic mapping services, including that used by Google Maps through SK Telecom's T Map Mobility.' Google pushed back on the suggestion that a 1:25,000-scale map — which does not require separate export approval — could suffice for navigation, saying such data lacks the necessary detail to support accurate turn-by-turn directions. On the issue of satellite imagery, Google clarified that it does not rely on government-provided images but rather sources them from third-party commercial providers through open markets. 'Blurring sensitive sites directly on the original satellite imagery is the most effective method,' the company said, noting that even if images are blurred on Google Maps, the uncensored original images may still exist in the underlying data. 'We are working with the Korean government to find ways to obscure sensitive facilities in the original satellite imagery,' Google said, reiterating its commitment to cooperating with Seoul to make its services more accessible while respecting local security requirements. The Ministry of Land, Infrastructure and Transport is scheduled to convene a joint consultation panel on Friday to decide whether to approve Google's request to export the national base map. The decision was initially expected in May but was postponed due to ongoing US-Korea trade negotiations. Another delay is likely as the next bilateral summit approaches. It is not the first time Google has made such a request. In both 2011 and 2016, the Korean government denied similar petitions, citing the risk of leaking sensitive military information if map data were stored on overseas servers. Meanwhile, at the APEC Global Digital and AI Forum held in Incheon on Tuesday, Google Korea Country Director Kim Kyoung-hoon declined to comment when asked by local reporters about the ongoing map export controversy. Despite the Korean government reclassifying Cheong Wa Dae, the former presidential office, as a national security facility and suspending public access as of Friday, Google Maps continues to display the location and details of the compound. On Google Maps on Tuesday, major facilities such as the Cheong Wa Dae's main building, main gate, Yeongbingwan, the state guest house, and Sangchunjae, a presidential venue for unofficial meetings and dinners, are still visible. On the contrary, domestic mapping services like Naver Map and Kakao Map have blurred out most of the site's features, including its entrances and signage. Tmap has gone a step further by removing Sarangchae, a nearby tourist information center, from its maps entirely. Regarding the issue, a Google Korea official said, 'We will continue close discussions with the government and prepare concrete measures, including designating liaison personnel, establishing a direct hotline and implementing masking procedures, to address the issue promptly."

LG, SKT, Naver among five selected for Korea's sovereign AI push
LG, SKT, Naver among five selected for Korea's sovereign AI push

Korea Herald

time2 days ago

  • Korea Herald

LG, SKT, Naver among five selected for Korea's sovereign AI push

The Ministry of Science and ICT on Monday announced the final selection of five teams to lead South Korea's ambitious 'sovereign AI foundation model' project, aimed at building homegrown, high-performance artificial intelligence models. The selected teams are Naver Cloud, Upstage, SK Telecom, NC AI and LG AI Research. Each will be granted the titles of 'K-AI model' and 'K-AI company,' the ministry said. The final selection followed an evaluation process that assessed each consortium's technological capabilities, development experience, strategic clarity and the anticipated impact of their proposed models. The review also considered their commitment to open-source principles and broader industry contribution. 'All five teams have demonstrated exceptional capabilities in AI model development,' an ICT ministry official said. 'They share a clear commitment to the vision of sovereign AI and presented robust open-source strategies that will allow other businesses to adopt and commercialize their technologies.' Notably, the ministry commended the teams' ambitions to go beyond large language models and evolve into multimodal and omnimodel architectures, reflecting a bold, scalable vision aligned with global AI advancements. The sovereign AI project attracted proposals from 15 consortia, comprising domestic AI firms and research institutions. The initiative aims to develop AI models that achieve at least 95 percent of the performance of the most advanced international models released within the last six months. To support the development, the government will provide each selected team with access to jointly purchased and processed datasets worth 10 billion won ($7.2 million), beginning in September. Additionally, each team will receive 2.8 billion won in supplementary funding to build and refine domain-specific datasets tailored to their development goals. A separate pool of high-quality broadcasting and video learning data, valued at 20 billion won, will also be available. Upstage, which has expressed interest in bolstering its global talent pool, will receive matching support from the government to cover personnel and research expenses for international researchers it seeks to recruit. SK Telecom and Naver Cloud have been selected as graphics processing unit infrastructure providers for the project. They will lease GPU resources from the second half of this year through early 2026, with GPU support allocated to Upstage, NC AI and LG AI Research. The ministry plans to sign formal agreements with the five groups early this month and to begin comprehensive support ― ranging from GPU and data access to global talent acquisition ― to fast-track the development of globally competitive AI foundation models. A first-round evaluation will be conducted in December, narrowing the pool from five teams to four. Successive assessments will be conducted every six months, with only two left remaining by 2027. 'The bold initiative marks the beginning of Korea's journey toward building AI for all,' said ICT Minister Bae Kyung-hoon. 'The government will stand firmly behind our AI companies and institutions as they scale new heights and shape a robust sovereign AI ecosystem.'

New threats, new protection: Korea rethinks cyber insurance as attacks surge
New threats, new protection: Korea rethinks cyber insurance as attacks surge

Korea Herald

time29-07-2025

  • Korea Herald

New threats, new protection: Korea rethinks cyber insurance as attacks surge

Hanwha, Samsung move to fill coverage gap as corporate breaches fuel demand A string of high-profile cyber incidents, from SK Telecom's data breach to a ransomware attack on Seoul Guarantee Insurance, has raised alarm over digital vulnerabilities and spurred Korean insurers to ramp up cyber coverage. Leading the response is Hanwha General Insurance, which in November launched its Cyber Risk Management Center, the first dedicated cyber risk division established by a Korean insurer. As part of its strategy, Hanwha formed a three-way partnership with global cybersecurity firm Theori and leading Korean law firm Shin & Kim, which operates a team specializing in digital and IT-related legal issues. Samsung Fire & Marine has also stepped up, establishing a cyber risk team last year and launching a policy in May tailored to small- and mid-sized firms — those with under 100 billion won ($72 million) in revenue and fewer than 3 million data subjects. Despite rising threats, Korea's cyber insurance market remains underdeveloped. A 2024 report by Munich Re estimated Korean cyber premiums at just $50 million, only 0.3 percent of the global total and placing it among the smallest in Asia. Domestically, cyber insurance accounts for just 1 percent of Korea's non-health accident insurance market. Awareness is also low. A 2024 Korea Internet & Security Agency survey showed only 14.5 percent of companies were aware of cyber insurance, while just 2.7 percent had purchased a policy. Yet threats are mounting. Reported incidents in Korea more than doubled from 630 in 2020 to 1,277 in 2023, then rose another 48 percent to 1,887 in 2024. In just the first half of 2025, major breaches hit SK Telecom, GS Retail, Olive Young, SGI and Yes24, exposing gaps in corporate defenses across sectors. Globally, cyber risk tops the list of business concerns. Allianz has named it the biggest threat for four years running, while Travelers also found it was US executives' top concern. In Korea, many companies still downplay cyber risks, viewing insurance as a supplementary response measure rather than an essential preventive safeguard. A KISA survey reflected worsening awareness. In 2024, only half of 6,500 companies had a data security budget, down from 68 percent in 2022. Of those, just 0.6 percent spent over 100 million won, while 75 percent spent less than 5 million. The only mandatory policy is liability insurance for data breaches, required of firms with over 1 billion won in revenue and more than 10,000 data subjects. As of last year, only 10 percent of eligible firms — about 7,800 — were enrolled. Even among the insured, coverage is often inadequate. SK Telecom, whose USIM breach affected 23 million subscribers, was covered for just 3 billion won, including the 1 billion won legal minimum. With USIM replacement alone estimated at 170 billion won, most of the burden remains uninsured. Regulators are starting to take notice. At a parliamentary hearing on the SKT breach, Rebuilding Korea Party lawmaker Lee Hai-min said, 'The 1 billion won coverage under personal data compensation insurance falls far too short to meaningfully compensate consumers in large-scale hacking cases,' calling for higher limits and stronger mandates to drive preventive investment. 'Cyber risks are mostly intangible and hard to quantify, and firms tend to avoid costs tied to abstract risks. On the other end, insurers face challenges in underwriting due to their interconnectedness and large-scale losses," stated Kwon Soon-il of the Korea Insurance Research Institute, urging policy incentives such as tax benefits and premium subsidies, along with clearer terms and broader coverage for broader adoption. The insurance industry is seeing growing demand. 'Until now, most firms only subscribed to basic liability policies, but the SK Telecom and SGI breaches have prompted many to reassess their coverage,' said an industry official. Newer comprehensive policies are particularly gaining attention for their flexibility. They allow companies to tailor plans, such as adding emergency response coverage or avoiding overlaps with existing policies, the official added. At Hanwha General, cyber insurance revenue surged 200 percent between November and June. Meanwhile, Munich Re expects the global cyber insurance market to grow 37 percent to $21 billion by 2027. In Korea, it's projected to rise 80 percent to $90 million — still modest, but showing clear momentum.

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store