The Register Home Page

back to article SK Telecom walloped with $97M fine after schoolkid security blunders let attackers run riot

South Korea's privacy watchdog has slapped SK Telecom with a record ₩134.5 billion ($97 million) fine after finding that the mobile giant left its network wide open to hackers through a catalog of bungles. The case stems from a breach disclosed in April, when SK Telecom admitted that hackers had swiped the universal subscriber …

  1. Andy E
    FAIL

    Did anyone get fired?

    Given the criminal negligence, someone must have been fired.

    1. Andy Non
      Coat

      Re: Did anyone get fired?

      They probably cleaned up... by firing the office janitor.

    2. Anonymous Coward
      Anonymous Coward

      Re: Did anyone get fired?

      ... a record ₩134.5 billion ($97 million) fine ...

      A slap on the wrist, a pittance. ie: nothing but a bad joke.

      27M subscribers?

      In a country with a population of ~ 50M?

      If my math is correct, over 50% of the population was affected.

      The fine ends up being $3.59 / subscriber.

      Ridiculous.

      The CEO and the whole board of directors are still laughing.

      The fine should have been no less than $100* per subscriber and the company put under administration until the sum is paid in full.

      With interests and from the end of year dividends.

      ... must have been fired.

      Not only fired: prosecuted for a criminal offence.

      .

      * I am assuming the author means US currency.

      1. AdamWill

        Re: Did anyone get fired?

        Yup, I was thinking the same. To put it another way: SK Telecom's annual revenue for 2024 was 17.9406 trillion won - $12.6bn . Its operating income (profit, more or less) was 1.8234 trillion won - $1.28bn . A $97m fine is less than 10% of its profit for one year and less than 1% on its revenue for one year. That's pathetic. It's barely noticeable. For comparison, it's like a fine of $970 for a person who earns $126,000 per year. Slightly annoying? Sure. Appropriate punishment for compromising the security of half the nation? No.

      2. Excused Boots Silver badge

        Re: Did anyone get fired?

        Fines are irrelevant, fine them, what, say $1 billion, who ultimately pays it? Does it come out of the remuneration of the C-suite or is it paid by increased fees on customers, the very, very people who have had their data basically handed out to all comers?

        No, there needs to be actual prison time for executives who allow this to happen. Now I know, I absolutely know that this is difficult; ’to convict someone of a criminal offence, you have to prove beyond reasonable doubt.....’.

        But it can’t be beyond possibility. Of course the alternative is a massive disgruntled mob armed with pitchforks and blazing torches turning up at the company HQ or the CEO’s house!

    3. PRR Silver badge

      Re: Did anyone get fired?

      > Given the criminal negligence, someone must have been fired.

      Who do you think the government works for? Even more so than the US, in South Korea the government is a pawn of the major banks and factories. There was probably a "tisk-tisk" editorial in an opposition newpaper, SKT asked the government to slap its hand to "punish" them. They probably write it right off their nominal taxes.

  2. anthonyhegedus Silver badge

    Fuck around and find out

    Replace senior management: it's the only answer. Jail them for criminal negligence, seize all their personal assets (houses, cars, etc) to pay the fine - oh and make the fine MUCH larger. It needs to be not just a lesson to the parasitic idiots in charge, but a lesson to all telcos throughout the world: if you don't take security a hell of a lot more seriously than you already do, expect heavy repercussions.

    Regulators need to have a lot more power.

    Still, in this country (UK), we hear of scammers getting new phones delivered to their addresses with someone else's SIM, using someone else's account. Whether it's clever social engineering, or just an insde job, it's down to the telcos to beef up all areas of security.

    Just ONE breach of ONE customer's account can ruin that customer. Upper management need to know that if that happens to their customer, they'll be ruined too. It's the only way they'll take it seriously,

    1. Missing Semicolon Silver badge

      Re: Fuck around and find out

      I give you - TalkTalk! Which is only now going down because they are rubbish, not because they leaked the entire customer database.

  3. Anonymous Coward
    Anonymous Coward

    Worst IT of the year awards

    The Register should have worst-of annual awards.

    Worst IT of the Year -- 3 categories: large, medium and small organizations

    2025 nominee: SK Telekom, S. Korea, large organization

    Actually, maybe name the award for SK Telekom. "The 2025 SK Telekom award for worst IT in the world goes to... SK Telekom."

    What would the physical award look like? A 3D poop emoji?

    Also...

    Worst Programming Flaw of the Year -- given to programmers and their orgs (not a bug of the year award)

    This wouldn't necessarily be the most severe vulnerbility but the most avoidable coding vulnerability. It shouldn't include extremely difficult-to-exploit zero-days. Just the SK Telekoms of coding.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like