01Summary
In late April 2025, SK Telecom discovered unauthorized access to internal systems containing customer data. The breach exposed names, dates of birth, phone numbers, addresses, and partial resident registration numbers for roughly 27 million customers (nearly half of South Korea's population). The company confirmed the data was exfiltrated and later appeared on underground forums.
02Background
SK Telecom is South Korea's largest mobile network operator. Telecom companies hold highly detailed and long-lasting personal data, making them prime targets for identity theft and fraud.
03Key revelations
- 01Scale of telecom customer data held by major operators.
- 02Challenges in protecting national-scale personal datasets.
04Technical analysis
The attackers exploited a vulnerability in an internal system or used compromised credentials. Exact method was not fully disclosed due to ongoing investigation, but reports suggest a supply-chain or contractor-related vector.
- Attack vector
- Unauthorized access to internal customer database
- Attack method
- Data exfiltration
- Initial access
- Unknown (under investigation)
- Exfiltration
- Bulk data extraction
05Threat actor
Unknown threat actor(s) targeting high-value national telecom datasets.
Attribution sources
- SK Telecom statements
- Korean authorities
- BleepingComputer
06Victims and impact
Countries affected
- South Korea
07Data exposed
Data types
- PII
- Names
- Dates of Birth
- Phone Numbers
- Addresses
- Partial Resident Registration Numbers
08Financial damage
Massive risk of identity theft and phishing across South Korea; regulatory fines expected.
09Timeline
- 2025-04-20Breach occurred.
- 2025-04-25SK Telecom internally discovers the incident.
- 2025-04-28Public disclosure.
10Reaction and fallout
Public reaction
Nationwide outrage and increased fear of identity theft and scams.
Political impact
Triggered emergency parliamentary hearings and stronger data protection demands in South Korea.
11Legal
Ongoing regulatory investigation by Korea Communications Commission and Personal Information Protection Commission.
Civil lawsuits
- Multiple class-action style complaints expected
12Aftermath
Policy changes
- Stronger requirements for telecom data security and breach notification.
Security improvements
- Accelerated internal system hardening and access control reviews.
13Significance and legacy
Significance
One of the largest single-company customer data breaches in South Korea's history.
Legacy
Pushed South Korea toward stricter telecom cybersecurity regulations.
14Disclosure and media
- Authentication
- Official company disclosure and forum samples
Publishing organisations
- BleepingComputer
- Yonhap News
- Korea Herald
15Field notes
- 01The breach affected nearly half of South Korea's entire population.
16Resolution
Data already widely circulated; SK Telecom offering credit monitoring and identity protection services to affected customers.
17Sources
Official documents
- SK Telecom Official Notice
References
- [1]SK Telecom statements
- [2]BleepingComputer reports
- [3]Korean government announcements









