KoreaTechToday - Korea's Leading Tech and Startup Media Platform
  • Topics
    • Naver
    • Kakao
    • Nexon
    • Netmarble
    • NCsoft
    • Samsung
    • Hyundai
    • SKT
    • LG
    • KT
    • Retail
    • Startup
    • Blockchain
    • government
  • Lists
KoreaTechToday - Korea's Leading Tech and Startup Media Platform
  • Topics
    • Naver
    • Kakao
    • Nexon
    • Netmarble
    • NCsoft
    • Samsung
    • Hyundai
    • SKT
    • LG
    • KT
    • Retail
    • Startup
    • Blockchain
    • government
  • Lists
KoreaTechToday - Korea's Leading Tech and Startup Media Platform
No Result
View All Result
Home Topics LG

LG Uplus Bows to Pressure, Will Report Hacking Signs to Cybersecurity Watchdog

Dae-Hyun by Dae-Hyun
PUBLISHED: October 21, 2025 UPDATED: October 22, 2025
in LG, South Korea, Tech Industry
0
LG Uplus Bows to Pressure, Will Report Hacking Signs to Cybersecurity Watchdog

The company’s delayed response to hacking allegations exposes broader issues in how Korean firms interpret and apply disclosure requirements under cybersecurity law.



After facing mounting criticism from lawmakers and regulators, LG Uplus CEO Hong Beom-shik has pledged to report suspected hacking activity to the Korea Internet & Security Agency (KISA). 

During a parliamentary audit on October 21 by the National Assembly’s Science, Technology, Information, Broadcasting, and Communications Committee, Hong said the company had initially believed that reporting was only required after confirming an actual breach. However, facing rising confusion and criticism, he said the telecom provider would “actively consider” submitting an official report to the national cybersecurity agency.

This represents a clear reversal from LG Uplus’ earlier stance, when it denied any evidence of hacking despite growing concerns over leaked internal data.

Legal Obligations Under the Cyber Law

Under South Korea’s Information and Communications Network Act, any information and communications service provider must report to KISA within 24 hours of detecting possible signs of intrusion.

LG Uplus’ initial refusal to report the incident—on grounds that no customer data had been compromised—prompted criticism from lawmakers and cybersecurity observers, who accused the company of failing to meet both the legal requirement and the spirit of proactive cybersecurity governance.

The company’s argument that “no customer information was leaked” was seen as insufficient under the law, which also covers internal systems and operational data.

Hacking Allegations and Data Exposure

The controversy intensified after an August report by the U.S.-based cybersecurity magazine Phrack, which claimed that two anonymous white-hat hackers had discovered around 8 GB of leaked data connected to LG Uplus.

According to the report, the exposed data allegedly included:

  • Details from 8,938 servers,
  • Information on 42,526 user accounts, and
  • Records of 167 employees.

KISA reportedly detected suspicious access patterns as early as July and advised LG Uplus to submit a breach report. However, the company declined, citing a lack of confirmed intrusion. The Ministry of Science and ICT later launched an on-site inspection that remains ongoing.

Security Gaps and Weak Authentication

During the National Assembly hearing, Rep. Lee Hae-min of the Rebuilding Korea Party revealed that LG Uplus’ internal systems suffered from eight major vulnerabilities in its Account Privilege and Access Management (APPM) system.

These flaws included:

  • A loophole allowing bypass of two-factor authentication using a simple numeric code;
  • A backdoor providing access to administrator pages without additional verification; 
  • Plain-text passwords and unencrypted keys stored directly in the source code.

Rep. Lee criticized the findings, saying, “Leaving passwords unencrypted in source code is like writing a safe’s combination on a sticky note and putting it on the door.” He added that even a single one of these vulnerabilities could allow remote hijacking of administrator privileges, threatening the company’s internal network security.

Allegations of Evidence Tampering

Adding to the controversy, lawmakers accused LG Uplus of erasing potential digital evidence. The company allegedly updated its server operating system the day after the Ministry of Science and ICT requested copies of its internal investigation results.

Rep. Lee claimed that LG Uplus had reinstalled the server image before submitting it to authorities—raising doubts over whether original traces of the intrusion were preserved for forensic review. The lawmaker demanded a thorough investigation, questioning whether the updated server image accurately reflected the system’s state before the alleged tampering.

Company’s Defense and Next Steps

In response, CEO Hong emphasized that no confirmed intrusion had been found so far. However, he pledged to cooperate with the ongoing investigations and to “actively respond according to the procedures” set by both the National Assembly and the Ministry of Science and ICT.

An LG Uplus official later clarified that Hong’s remarks were intended to ease public concerns and ensure transparency, adding that the company would align with regulatory protocols as the investigations progress.

Still, cybersecurity experts argue that the incident underscores a systemic problem: companies prioritizing image management over rapid disclosure. Delayed reporting not only risks regulatory breaches but also undermines public confidence in digital infrastructure.

Broader Implications for Corporate Cyber Accountability

The LG Uplus case exposes deeper issues in South Korea’s corporate cybersecurity culture. Despite the country’s advanced digital economy, experts point to recurring weaknesses in incident disclosure, employee cyber hygiene, and risk communication.

The controversy also arrives amid increasing cyber threats from North Korean hacking groups, such as Kimsuky, which Phrack suggested may have been linked to the incident.

For South Korea’s telecommunications industry—considered critical national infrastructure—this episode serves as a wake-up call. Companies are now expected to move beyond reactive crisis management and adopt: Real-time threat monitoring and external audits, Encrypted authentication protocols for internal systems, and Transparent reporting frameworks aligned with regulatory timelines.

 

 

Tags: Data LeakinvestigationLG UplusSouth Korea

Related Posts

South Korea Tightens Cyber Defenses After Detecting Government Hacking Attempt
Government

South Korea Tightens Cyber Defenses After Detecting Government Hacking Attempt

October 21, 2025
When Data Fails Trust: A Deep Dive into South Korea’s Escalating Breach Crisis
Editorial Feature

When Data Fails Trust: A Deep Dive into South Korea’s Escalating Breach Crisis

October 17, 2025
South Korea Prepares Fourth Launch of Homegrown Nuri Rocket
Government

South Korea Prepares Fourth Launch of Homegrown Nuri Rocket

October 1, 2025
South Korea, BlackRock Team Up to Build Hyperscale AI Data Center Hub
Data Center

South Korea, BlackRock Team Up to Build Hyperscale AI Data Center Hub

October 1, 2025
LG Chem Launches Autonomous Smart Lab for Battery Material Research
AI

LG Chem Launches Autonomous Smart Lab for Battery Material Research

September 29, 2025
LG and SK Join Forces on AI Data Center Cooling and Energy Solutions
AI

LG and SK Join Forces on AI Data Center Cooling and Energy Solutions

September 25, 2025
No Result
View All Result

Most Popular

  • Ride-Hailing Rivalry: Kakao and Uber Bet on Membership Services in Korea

    0 shares
    Share 0 Tweet 0
  • Kakao Mobility Faces $10.5 Million Fine for Limiting Competitors’ Access to Taxi Platform

    0 shares
    Share 0 Tweet 0
  • Korea’s Navigation Battle Heats Up: Naver and Kakao vs. Google maps

    0 shares
    Share 0 Tweet 0
  • 5 Best Korean to English Translation Apps

    0 shares
    Share 0 Tweet 0
  • Naver Maps Launches Guide in English, Chinese, and Japanese to Enhance Travel Experience for Tourists

    0 shares
    Share 0 Tweet 0
  • Naver Unveils Asia’s Largest Data Center, GAK Sejong, for Tech Innovation

    0 shares
    Share 0 Tweet 0
  • KakaoTalk to Adopt Instagram-Style Feed in Major 2025 Redesign

    0 shares
    Share 0 Tweet 0
  • South Korea’s $2.26 Billion Vision: A Robotic Revolution by 2030

    0 shares
    Share 0 Tweet 0
  • Naver Video Streaming Service V Live to Go Global

    0 shares
    Share 0 Tweet 0
  • Kakao Mobility Takes k.ride Global with Expansion to 12 Countries

    0 shares
    Share 0 Tweet 0

PRODUCTS

[ads_amazon]

TOPICS

  • Naver
  • Kakao
  • Nexon
  • Netmarble
  • NCsoft
  • Samsung
  • Hyundai

FREE NEWSLETTER

FOLLOW US

  • About Us
  • Cookie policy
  • home
  • homepage
  • mainhome
  • Our Services
  • Privacy Policy
  • Terms of Use

Copyright © 2024 KoreaTechToday | About Us | Terms of Use |Privacy Policy |Cookie Policy| Contact : [email protected] |

No Result
View All Result
  • Topics
    • Naver
    • Kakao
    • Nexon
    • Netmarble
    • NCsoft
    • Samsung
    • Hyundai
    • SKT
    • LG
    • KT
    • Retail
    • Startup
    • Blockchain
    • government
  • Lists

Copyright © 2024 KoreaTechToday | About Us | Terms of Use |Privacy Policy |Cookie Policy| Contact : [email protected] |