my timesThe Korea Times

Carriers under fire for mismanaging data

Listen

By Kim Yoo-chul

There is an old saying about fixing the barn after the horse has bolted. This is a fitting description for telecommunications companies that are scrambling to strengthen protection of their computer networks and databases following a massive data breach at KT.

Police arrested two computer hackers and are investigating seven others after they broke into KT’s network and stole the personal details of 8.7 million of the company’s mobile phone users.

The incident could have huge ramifications for KT, which was unaware for five months that its network had been penetrated by cybercriminals before belatedly calling the police.

The compromised data includes names, mobile phone numbers, contract terms and resident registration codes, the Korean equivalent of social security numbers. Police suspect the data was leaked to telemarketers with the suspects pocketing at least 1 billion won (about $880,000).

The incident also raised questions whether data are protected any better at SK Telecom and LG Uplus, the country’s other two wireless carriers.

SK Telecom says the personal information of each its customers is managed by unique Internet protocol addresses that make it hard for cyber criminals to penetrate.

``We are running our cyber security center 24 hours a day, 365 days a year, to block any apparent hacking attempts and to detect internal viruses. If excessive data collection of personal information is detected, we will be able to stop it right away,’’ said an SK Telecom official.

To strengthen privacy protection, the company will no longer require customers to present their registration forms on paper. ``We will strengthen our monitoring of telemarketing firms and hire more security staff,’’ said the official.

LG Uplus, the smallest of the three carriers, insists that its current security system is good enough.

It applies what company officials describe as ``complex algorithm codes’’ to protect information. A 64-digit authorization system is required for log-in and the codes are automatically changed from time to time.

``We limit access to searches for personal information to a maximum of 150 cases a day,’’ said a Uplus spokesman.

Meanwhile, the Korea Communication Commissions (KCC), the nation’s converged regulator for telecommunications and broadcasting, says it will investigate KT ``thoroughly’’ to determine whether the company has been lax in protecting customer data.

``The KCC is investigating whether KT has broken the law or missed requirements in any way. If we find evidences to prove KT’s mismanagement of its customer policy, then we will fine KT,’’ said Kim Kwang-soo, an official from KCC’s customer policy bureau.

Kim said the KCC ordered SK Telecom and LG Uplus as well as KT to strengthen their security measures in an organized meeting with senior executives, and added the local telecom companies pledged to simply follow the requests of the government agency.

KT has been swift to issue an apology over the incident and has vowed to improve its security measures. But the firm is facing massive class action suits from victims of the data leak.

``News of the data leak is truly hurting investor sentiment. For KT, the recent scandal looks enough to threaten the company’s fundamentals,’’ said a fund manager from a U.S.-based investment bank in Seoul by telephone, asking not to be identified.