EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/2025-sk-telecom-breach
065/430

File EL-0366CriticalOngoingData Breach / Data Exfiltration

SK Telecom Data Breach

Also filed as SK Telecom Massive Customer Data Leak · South Korea Telecom Breach 2025

One of the largest telecom breaches in South Korea's history. Hackers stole personal information of approximately 27 million SK Telecom customers.

  • #telecom
  • #pii
  • #customer-data
  • #south-korea
  • #massive-breach
Notoriety9/10
Event
20 Apr 2025
Disclosed
28 Apr 2025
Target
SK Telecom
Scale
27.0M people
Status
Ongoing

01Summary

In late April 2025, SK Telecom discovered unauthorized access to internal systems containing customer data. The breach exposed names, dates of birth, phone numbers, addresses, and partial resident registration numbers for roughly 27 million customers (nearly half of South Korea's population). The company confirmed the data was exfiltrated and later appeared on underground forums.

02Background

SK Telecom is South Korea's largest mobile network operator. Telecom companies hold highly detailed and long-lasting personal data, making them prime targets for identity theft and fraud.

03Key revelations

  1. 01Scale of telecom customer data held by major operators.
  2. 02Challenges in protecting national-scale personal datasets.

04Technical analysis

The attackers exploited a vulnerability in an internal system or used compromised credentials. Exact method was not fully disclosed due to ongoing investigation, but reports suggest a supply-chain or contractor-related vector.

Attack vector
Unauthorized access to internal customer database
Attack method
Data exfiltration
Initial access
Unknown (under investigation)
Exfiltration
Bulk data extraction

05Threat actor

Unknown threat actor(s) targeting high-value national telecom datasets.

Attribution sources

  • SK Telecom statements
  • Korean authorities
  • BleepingComputer

06Victims and impact

Countries affected

  • South Korea

07Data exposed

Data types

  • PII
  • Names
  • Dates of Birth
  • Phone Numbers
  • Addresses
  • Partial Resident Registration Numbers

08Financial damage

Massive risk of identity theft and phishing across South Korea; regulatory fines expected.

09Timeline

  1. 2025-04-20Breach occurred.
  2. 2025-04-25SK Telecom internally discovers the incident.
  3. 2025-04-28Public disclosure.

10Reaction and fallout

Public reaction

Nationwide outrage and increased fear of identity theft and scams.

Political impact

Triggered emergency parliamentary hearings and stronger data protection demands in South Korea.

11Legal

Ongoing regulatory investigation by Korea Communications Commission and Personal Information Protection Commission.

Civil lawsuits

  • Multiple class-action style complaints expected

12Aftermath

Policy changes

  • Stronger requirements for telecom data security and breach notification.

Security improvements

  • Accelerated internal system hardening and access control reviews.

13Significance and legacy

Significance

One of the largest single-company customer data breaches in South Korea's history.

Legacy

Pushed South Korea toward stricter telecom cybersecurity regulations.

14Disclosure and media

Authentication
Official company disclosure and forum samples

Publishing organisations

  • BleepingComputer
  • Yonhap News
  • Korea Herald

15Field notes

  1. 01The breach affected nearly half of South Korea's entire population.

16Resolution

Data already widely circulated; SK Telecom offering credit monitoring and identity protection services to affected customers.

17Sources

Official documents

  • SK Telecom Official Notice

References

  1. [1]SK Telecom statements
  2. [2]BleepingComputer reports
  3. [3]Korean government announcements
Fact sheetEL-0366

Dates

Event
20 Apr 2025
Started
20 Apr 2025
Discovered
25 Apr 2025
Disclosed
28 Apr 2025
Ongoing
Yes

Target

Organisation
SK Telecom Co., Ltd.
Type
Telecommunications Company
Sector
Telecommunications
Country
South Korea

Actor

Motivation
Financial gain through sale of massive telecom customer dataset.
Attribution
Low
Status
Active
Arrested
No
Convicted
No

Data

People
27,000,000
Records
27,000,000
Sensitivity
Critical
Published
Yes
Sold (dark web)
Yes

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.