logo

SKT, the first abnormal recognition was on the 18th... Violated regulations by reporting hacking within 24 hours

SK Telecom [017670] was aware of the hacking attack earlier than the day before, when they recognized the theft of customer information on the 19th, and it was found that they violated the regulation requiring reporting within 24 hours of incident awareness.

 

According to data submitted by K Telecom to the National Assembly's Science, Technology, Information, Broadcasting, and Communications Committee on the 24th, the company first became aware on the 18th at 6:09 PM that internal system data had unintentionally moved.

 

On the same day at 11:20 PM, we internally confirmed the discovery of malicious code and a hacking attack, and on the following day, the 19th at 1:40 AM, we began analyzing which data had been exfiltrated.

SK Telecom, after analyzing what kind of data was leaked, confirmed around 11:40 PM on the same day, 22 hours later, that some information related to user SIM cards had been leaked due to malicious code by hackers.

SK Telecom is suspected of delaying reporting after discovering a hacking attack and reporting it to the Korea Internet & Security Agency (KISA).

The report from SK Telecom to KISA was made at 4:46 PM on the 20th, which is 45 hours after the initial awareness of the incident at 6:00 PM on the 18th.

Even based on the time of 11:20 PM on the 18th, which was considered a hacking attack, the report was made just over a day later.

The Information and Communications Network Act stipulates that providers of information and communication services must report to the Minister of Science and ICT or KISA within 24 hours of becoming aware of a security breach, including details such as the date and time of the incident, causes, and extent of damage.

KISA also announced that SK Telecom violated the regulation requiring reporting of hacking attacks within 24 hours to Minister Choi's office.

Regarding this, SK Telecom explained, "Considering the seriousness of the issue, the delay in reporting the cyber intrusion incident was due to a more thorough investigation of the minimal causes and damages necessary for reporting, and there was no intentional delay."

Meanwhile, SK Telecom is providing a SIM card protection service to prepare for situations where hackers create cloned phones using leaked SIM card information to cause financial damage. It has been identified that users who have not subscribed to this service are also exposed to security vulnerabilities, raising concerns.

SK Telecom explained that for users who have not applied for the SIM card protection service, if their mobile phone remains turned on, the device control may not be seized by hackers, but if the phone is turned off or switched to airplane mode, this may not be the case.

If the mobile phone turns off or switches to airplane mode, there is a possibility that hackers could hijack access rights through the SIM card information.

However, those who have applied for the SIM card protection service are not exposed to these risks.

SK Telecom stated, "Even if the mobile phone is turned off, we are doing our best to block illegal SIM card device changes through the abnormal authentication attempt blocking system (FDS)."

Commissioner Choi said, "Since the SK Telecom hacking incident occurred, consumer concerns have been increasing. We will prepare measures at the national assembly level to prevent the spread of damage caused by security breaches and to prevent recurrence."

 

===========================================

 

It's really frustrating that our country's largest telecommunications company is behaving like this...

 

This is why my security gets compromised, I use my phone normally, then I get activation texts and money gets taken... that's how it goes.

 

It seems that legislation should be introduced to ensure that both telecommunications companies and bank banking programs can be compensated if legal issues arise.

1
0
Comments 13
  • Profile Image
    팝콘
    아.. 나도 sk인데 별일 없겠죠?..ㅠ.ㅠ
    돈도 많이 없기는 한데.. 폰 정지되면 황당할 듯...
    • Profile Image
      뉴페이스
      Author
      아.. 정말 통신사1위 그룹이 참 어설프네요..
      정말 한심합니다... 유심바꾸는 것도 줄서야 되고...
  • Profile Image
    안레몬
    SK 몇년을 쓰고 있는데 황당하네요. 해킹 공격이라니ㅜㅜ 별일없겠지요. 
    • Profile Image
      뉴페이스
      Author
      정말 이번에 하는 처사가 더 많은 이탈자를 만들 것 같네요..
      고개만 숙이면 뭐하나요.. 대처가 이래서야..
  • 쩡♡
    sk인데 이일로 무료로 보호 가입
    해준다던데 가입 해야겠어요
    
    • Profile Image
      뉴페이스
      Author
      유심보호서비스인가 무료가입을 하긴 했는데..
      이걸로는 아무것도 안된다는 말들이 많네요...
  • Profile Image
    땡땡이
    저도 sk인데 ㅠㅠ
    별생각 없었는데 이런ㅠㅠ
    • Profile Image
      뉴페이스
      Author
      피해사례가 있다고 기사들이 뜨긴하는데 이게 정확한
      기사가 아닐수도 있다고 하네요...
  • 굿맨
    이 글 읽고 정말 놀랐어요! 😳 SK텔레콤이 해킹 공격을 당한 건 큰 이슈인데, 사고 인지 시점이 늦었다니… 고객 정보 보호를 위해 더 철저한 관리가 필요할 것 같아요. 🔒 앞으로는 이런 일이 없기를! 
  • Profile Image
    깐데또까
    저도 sk인데.. 해킹공격이라니
     무료로 보호가입 해준다니 해야겠어요
       
    • Profile Image
      뉴페이스
      Author
      유심보호서비스 궁여지책이지만 급하게라도
      무료가입해야죠..뭐..ㅠ.ㅠ
  • Profile Image
    앱톰
    저도 통신사 여기인데 참 답답하더라구요..
    털린건 지네들이 털리고 유심은 줄서서 직접바꾸라 그러고 ㅋㅋ
    • Profile Image
      뉴페이스
      Author
      맞아요 정말 이걸 대처라하고 하고 있네요
      1위기업이 정말 한심하네요