logo

Korean telco failed at femtocell security, exposed customers to snooping and fraud

ID: 7ec96928-f45d-5905-be2e-8fff90abb2ab

STIX ID: report--7ec96928-f45d-5905-be2e-8fff90abb2ab

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2025-12-30

Date Updated: 2026-04-26

Author: Simon Sharwood

...
...

South Korea’s carrier Korea Telecom deployed thousands of poorly secured femtocells that shared a single certificate and had weak device security; attackers cloned these femtocells to intercept customers’ SMS/call data and perform micropayments fraud (reported $169,000 affecting 368 customers) while investigations uncovered multiple cloned devices, arrests, links to a prior BPFDoor data leak, and indications of possible large-scale surveillance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.