my timesThe Korea Times

ED SKT chief's insincere apology

Listen

National security undermined: SKT hit for data breach

SK Group Chairman Chey Tae-won apologizes for the recent SK Telecom data breach during a press conference at SK Group headquarters in Seoul, Wednesday. Yonhap

SK Group Chairman Chey Tae-won apologizes for the recent SK Telecom data breach during a press conference at SK Group headquarters in Seoul, Wednesday. Yonhap

The recent data breach at SK Telecom, Korea’s largest telecommunications provider, has triggered a crisis not only of corporate accountability but also of national security. The incident, involving the leak of universal subscriber identity module (USIM) information affecting untold numbers of subscribers, has revealed troubling deficiencies in the company’s response, leadership and overall preparedness. In failing to treat the matter with the urgency and transparency it demands, SKT and its chairman, Chey Tae-won, have compromised public trust and exposed the dangerous gap between Korea’s digital advancement and its cybersecurity readiness.

Chey’s belated and inadequate apology did little to quell the growing public outrage. Only after considerable pressure did he acknowledge that the breach extended beyond a simple data leak, admitting it bore implications for national defense and security. However, his vague promises to “expand investment” in data protection and to establish an “information protection innovation committee” fell far short of what the situation demanded. At a time when clarity and decisive leadership were most needed, SKT offered platitudes rather than action.

The stakes are enormous. With over 25 million subscribers, SKT forms the backbone of Korea’s telecommunications infrastructure. Any compromise of its systems carries far-reaching consequences, from economic disruption to national vulnerability. Initial internal investigations uncovered four types of malware. Yet external experts soon discovered eight more, raising serious doubts about SKT’s capacity to identify, let alone contain, the breach. Despite the ongoing probe, the company has yet to determine the precise source or method of the attack — a glaring and unacceptable shortfall for a tech giant of its stature.

In the absence of timely solutions or even basic crisis management, public anxiety has soared. More than 250,000 customers have already defected to rival carriers, driven not only by concerns over their personal data but by SKT’s inability to provide even rudimentary services such as USIM replacement. The exodus reflects a catastrophic collapse of consumer trust — once the cornerstone of the SK brand — and signals that SKT now faces its most severe reputational crisis since its inception.

Compounding this failure is the company’s apparent unwillingness to address the question of compensation or restitution for affected users. This omission further illustrates the disconnect between the leadership's understanding of its obligations and the experience of its customers, many of whom continue to suffer due to delays and service outages.

More broadly, this incident casts a harsh spotlight on Korea’s inadequate investments in cybersecurity. As the nation rapidly digitizes, integrating artificial intelligence and 5G networks into daily life, cyber threats are growing in both frequency and sophistication. According to the Korea Internet & Security Agency, cyberattacks on domestic enterprises nearly tripled from 640 cases in 2021 to 1,887 last year. This nearly exponential trajectory is alarming. The SKT breach must serve as a wake-up call — not just for telecom companies, but for regulators, lawmakers and all critical infrastructure providers.

In this context, urgent legislative and institutional reforms are necessary. Minimum standards for data protection must be mandated and rigorously enforced. Certification systems should be strengthened, and punitive measures imposed on firms that fail to safeguard sensitive information. Only through such systemic changes can Korea begin to close the widening gap between digital capability and digital security.

Chey and SK Telecom have failed their customers — and, by extension, the nation — at a time when vigilance should have been paramount. Their sluggish, insufficient response has turned a preventable breach into a national crisis. It is now up to the government, civil society and forward-thinking corporate leaders to ensure that such negligence is never repeated.

Trust, once lost, is difficult to regain. SKT would do well to remember that recovery will not be measured by words, but by tangible, sustained action.