기사 메일전송
LGU+ Call Recordings Exposed… Anxiety Spreads Due to Repeated Telecom Company Incidents
  • Yonhap News
  • December 7, 2025 at 9:35 AM
기사수정
  • Call information for 36 AI service users exposed... Revealed through customer report

  • SKT's massive leak, KT server hacking, and unauthorized payments continue to sound alarms across the entire security system.


Security Gaps in the Telecommunications IndustryA mobile phone store in Seoul. Following the SK Telecom hacking incident that led to customer data leaks, concerns about hacking are growing across all three mobile carriers. The Personal Information Protection Commission announced that it would conduct a swift and thorough investigation into allegations of personal information leakage at KT and LG Uplus, in conjunction with relevant authorities such as the police and the Ministry of Science and ICT. Yonhap NewsThe incident where customer call contents were leaked to other customers through LG Uplus's artificial intelligence (AI) service 'Xio' has once again brought the telecommunications companies' insensitivity to information protection to the forefront.


According to the telecommunications industry on the 7th, LG Uplus experienced a leakage of call summaries, call recipient phone numbers, and call times for 36 other customers to 101 users who had newly installed or reinstalled Xio between 8 PM on the 2nd and 10:59 AM on the 3rd.


LG Uplus stated that sensitive information such as resident registration numbers and passport numbers, as well as financial information, were not leaked. Although the incident did not meet the reporting criteria for over 1,000 victims or the inclusion of sensitive information, the company voluntarily reported it to the Personal Information Protection Commission.


However, the fact that users' sensitive information, such as phone call content and recipients, was exposed for nearly 14 hours, and that the company only became aware of and took action after a customer report, rather than proactive detection, are aspects that are likely to face public criticism.


In particular, as concerns grew about whether the exposure was due to hacking, the incident occurred while the company was under a joint public-private investigation regarding allegations that it had been subjected to a hacking attack and attempted to erase traces through server updates.


LG Uplus clarified, however, that "this matter is unrelated to hacking and was caused by an error during a feature improvement operation of the Xio server, which stores AI call records and call summary files."

With a series of major personal information breaches occurring at telecommunications companies responsible for the nation's basic infrastructure, public anxiety is increasing, leading to calls for significantly strengthened personal information protection efforts within the industry.


The SK Telecom hacking incident in April, which resulted in the theft of 25 types of information, including mobile phone numbers, subscriber identification numbers (IMSI), and SIM authentication keys (Ki·OPc), for 23.24 million subscribers, most of the subscriber base, caused a severe shortage of SIM cards.


Subsequently, KT experienced an incident where hackers accessed unauthorized base stations, not officially managed by the company, starting in October of last year. Furthermore, between March and July, the company discovered 43 servers infected with malware but exposed lax security management by opting for "internal resolution" without informing the authorities.


This led to an unprecedented situation where 362 KT subscribers were unknowingly subjected to unauthorized micro-payments totaling 240 million won.


The security industry is concerned that if the security capabilities of telecommunications companies, which handle the sensitive information of citizens as critical infrastructure, remain at their current low level, the "security gaps" could widen as telecommunications services and AI rapidly converge.


The government is strongly urging telecommunications companies to enhance their security capabilities, including conducting unannounced, surprise inspections of their security infrastructure using actual hacking methods on the three major carriers.


Additionally, following recent incidents such as the Coupang information leak, there have been increasing criticisms that the Personal Information Protection Management System (ISMS-P) certification, a key information protection management framework, has been operating ineffectively. In response, the government has announced plans to significantly strengthen post-certification management and review criteria.


What do you think of this article?
recommend
0
great
0
moved
0
정기구독배너
Go to Mobile Site