Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
LG유플러스 (LG Uplus)

LG유플러스 (LG Uplus) Vendor Cyber Rating & Cyber Score

lguplus.com

Simply. U+


L A.I CyberSecurity Scoring

L
Company Information
Website:https://www.lguplus.com
Employees number:2,740
Number of followers:160,795
NAICS:517
Industry Type:Telecommunications
Homepage:lguplus.com
L Risk Score (AI oriented)
Between 0 and 549
logo
LTelecommunications
Updated:
06/08/2026
363/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
L Global Score (TPRM)
xxxx
logo
LTelecommunications
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

L
LCritical
Current Score
363C (CRITICAL)
01000
4 incidents
-189 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
553Before Incident
Breach
06 Aug 2026L
LG Uplus and SK Telecom: Korean Telecoms Lose Breach Immunity: Regulator Voids Subscriber Liability Waivers

South Korea Forces Telecom Giants to Remove Unfair Liability Clauses After Major Data Breaches

364After Incident
CRITICAL-189
SK-LG-1786027269
South Korea Forces Telecom Giants to Remove Unfair Liability Clauses After Major Data Breaches South Korea’s Korea Fair Trade Commission (KFTC) has ordered the country’s three dominant mobile carriers SK Telecom, KT, and LG Uplus to remove four categories of unfair clauses from their standard customer contracts. The ruling, issued on Thursday, targets provisions that previously shielded carriers from legal responsibility in cases of data breaches or negligence, marking a significant shift in consumer protections for the nation’s 55 million mobile subscribers. ### Key Findings and Contract Changes The KFTC’s review identified four types of clauses that violated Korea’s Terms and Conditions Act, which prohibits standard-form contracts from unreasonably limiting a business’s liability: 1. Blanket Data-Breach Immunity – All three carriers had clauses absolving themselves of liability for breaches, particularly those involving wireless LAN systems or private telephone exchanges. The KFTC ruled that carriers cannot contractually transfer security risks to subscribers and must now be held liable in proportion to their negligence. 2. Credential Security Shifted to Users – One carrier’s contract held subscribers fully responsible for unauthorized account use while capping the carrier’s liability to cases of gross negligence. The KFTC rejected this, affirming that carriers bear the burden of proving they were not at fault under Korea’s data protection laws. 3. All-or-Nothing Fault Elimination – Carriers previously included clauses stating that if a service disruption was partly caused by subscriber conduct, the carrier bore zero liability. The KFTC ruled that damages must be apportioned based on each party’s degree of fault, preventing carriers from evading responsibility entirely. 4. Silence as Consent to Contract Changes – One carrier’s contract deemed subscriber inaction as acceptance of amendments. The KFTC voided this practice unless carriers provide clear, prominent notice that silence within a reasonable period constitutes agreement. ### Regulatory Pressure in the Wake of Major Breaches The ruling arrives amid heightened scrutiny of South Korea’s telecom sector, following a series of high-profile security failures: - SK Telecom’s USIM Breach – In April 2025, malware in SK Telecom’s network exfiltrated USIM authentication data for 26.96 million subscribers (nearly half the population). Investigators found the company stored 26.1 million USIM keys unencrypted, used plaintext admin credentials, and ignored security patches dating back to 2016. The Personal Information Protection Commission (PIPC) fined SK Telecom ₩134.8 billion ($94 million) the largest telecom privacy penalty in Korean history while the Consumer Dispute Settlement Commission later ruled the carrier could owe up to ₩2.3 trillion ($1.61 billion) in per-user compensation. - KT’s Evidence Deletion – KT faced allegations of deleting server evidence during an investigation into a separate breach. - LG Uplus’s Server Wiping – LG Uplus was accused of wiping servers before regulators could examine them. The KFTC’s action adds a consumer contract dimension to these enforcement efforts, removing the legal loopholes carriers could previously exploit to avoid liability. ### Market Impact and Broader Enforcement Trends South Korea’s telecom market is highly concentrated, with SK Telecom, KT, and LG Uplus serving nearly all 55 million subscribers. The KFTC noted that the lack of competitive alternatives left consumers with no choice but to accept the carriers’ unfair terms. The ruling ensures that future breaches will no longer be shielded by contractual waivers, providing subscribers with clearer legal recourse for damages. The decision aligns with a broader crackdown on unfair standard-form contracts. In 2024, the KFTC handled 168 such cases 50% more than in 2023 targeting sectors from webtoons to e-commerce. However, the telecom ruling carries the highest stakes, given the industry’s scale and the sensitivity of the data involved. ### Global Contrast: US Lacks Equivalent Protections The KFTC’s action highlights a regulatory gap in the U.S., where mobile carriers routinely include limitation-of-liability clauses in contracts. While the FCC’s 2023 breach notification rules require disclosure, no federal regulator has compelled carriers to remove such waivers. State laws vary, but no systematic review akin to Korea’s has been conducted at the national level. ### Future Implications South Korea’s amended Personal Information Protection Act, set to take effect on September 11, 2026, will raise the maximum administrative fine for serious violations from 3% to 10% of a company’s annual revenue. While the new penalties won’t apply retroactively to past breaches, they will govern future incidents, increasing pressure on carriers to bolster security measures. The KFTC’s ruling is prospective, meaning it applies to future breaches and contract disputes. However, ongoing compensation claims from the 2025 SK Telecom breach will proceed through separate regulatory and civil channels. For subscribers, the changes remove a major legal barrier, making it easier to hold carriers accountable for negligence.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Financial Loss: ₩134.8 billion ($94 million) fine, potential ₩2.3 trillion ($1.61 billion) in per-user compensationData Compromised: USIM authentication data, personally identifiable informationSystems Affected: SK Telecom’s network, wireless LAN systems, private telephone exchangesOperational Impact: Regulatory scrutiny, legal actions, contract revisionsBrand Reputation Impact: Significant reputational damage to SK Telecom, KT, and LG UplusLegal Liabilities: Increased liability for negligence, removal of unfair contract clausesIdentity Theft Risk: High (USIM data and PII exposed)
DATA BREACH
Type Of Data Compromised: USIM authentication data, personally identifiable informationNumber Of Records Exposed: 26.96 millionSensitivity Of Data: High (USIM keys, PII)Data Exfiltration: YesData Encryption: No (unencrypted USIM keys)Personally Identifiable Information: Yes
JULY 2026
551Before Incident
JUNE 2026
547Before Incident
MAY 2026
539Before Incident
APRIL 2026
539Before Incident
MARCH 2026
535Before Incident
FEBRUARY 2026
530Before Incident
JANUARY 2026
526Before Incident
DECEMBER 2025
521Before Incident
NOVEMBER 2025
516Before Incident
OCTOBER 2025
511Before Incident
SEPTEMBER 2025
506Before Incident
AUGUST 2025
576Before Incident
Breach
01 Aug 2025L
LG Uplus

Possible Data Breach at LG Uplus

496After Incident
HIGH-80
LG-0262902102325
LG Uplus, a major South Korean mobile carrier, reported a possible data breach after a U.S. cybersecurity outlet, Phrack, claimed a hacking group infiltrated its internal network. The breach allegedly involved the compromise of 8,938 servers, 42,256 accounts, and 167 employees' data. While LG Uplus initially denied any evidence of a breach following an internal inspection in August, the company later filed a proactive report to the Korea Internet and Security Agency (KISA) to address public concerns and potential misunderstandings. The incident was disclosed after the company’s president, Hong Bum-shik, mentioned it during a parliamentary audit, emphasizing the need for transparency despite the lack of confirmed data exfiltration. The breach, if validated, could expose sensitive internal employee data and customer account information, raising significant operational and reputational risks.
INCIDENT DETAILS -
TYPE
Data Breach (unconfirmed)Network Intrusion
IMPACT
8,938 servers (claimed)Brand Reputation Impact: Potential reputational damage due to public disclosure of suspected breach
DATA BREACH
42,256 accounts (claimed)167 employees (claimed)Data Exfiltration: Claimed by Phrack (unverified by LG Uplus)
JULY 2025
636Before Incident
Breach
01 Jul 2025L
LG Uplus

Suspected Data Breach at LG Uplus

573After Incident
CRITICAL-63
LG-4862648103025
LG Uplus, a major South Korean telecommunications provider, reported a suspected data breach to the national cybersecurity agency (KISA) after potential compromise signs were detected in July. While the company initially denied a breach in August, an unverified report by Phrack magazine claimed hackers—allegedly linked to China or North Korea—stole data from nearly 9,000 LG Uplus servers. The incident remains under investigation, with no confirmed details on the scope, source, or whether customer/employee data was exposed. However, the breach follows a pattern of escalating cyberattacks targeting South Korea’s telecom sector, raising concerns about national digital infrastructure resilience and the sector’s vulnerability to state-sponsored or sophisticated threat actors.The breach coincides with similar incidents at SK Telecom and KT Telecom, suggesting a coordinated campaign against critical communications networks. If confirmed, the compromise could undermine public trust in telecom security, disrupt services, or expose sensitive subscriber data—potentially affecting millions of users. The lack of transparency and delayed disclosure further exacerbate risks, highlighting systemic gaps in South Korea’s cybersecurity framework. Authorities have not ruled out financial, reputational, or operational damage, though the full impact remains unclear pending investigation results.
INCIDENT DETAILS -
TYPE
Data BreachCyberattack
IMPACT
Unverified: Data from nearly 9,000 serversUnverified: ~9,000 serversBrand Reputation Impact: Potential reputational damage due to suspected breach and ongoing investigations
DATA BREACH
Unverified: Alleged theft from ~9,000 servers
OCTOBER 2024
767Before Incident
Breach
08 Oct 2024L
KT Corporation and LG U+: South Korea fines telco giant KT $39 million for customer data breach

KT Corporation Fined $39 Million for 11-Month Data Breach in South Korea

611After Incident
CRITICAL-156
LG-KT-1785457450
KT Corporation Fined $39 Million for 11-Month Data Breach in South Korea South Korea’s Personal Information Protection Commission (PIPC) has imposed a KRW 53.979 billion ($39 million) fine on telecommunications giant KT Corporation for severe data protection failures that led to an 11-month-long network compromise between October 8, 2024, and September 5, 2025. The breach came to light on September 10, 2025, after customers reported fraudulent micropayments. KT initially disclosed that 5,500 users were affected, but the PIPC’s investigation revealed the exposure of 16,647 subscribers’ personal data, resulting in KRW 240 million ($167,400) in fraudulent mobile payments for at least 368 victims. ### How the Breach Occurred The attack stemmed from a compromised femtocell a small cellular base station used to extend network coverage. Attackers obtained a valid authentication certificate from the lost device and installed it on a rogue femtocell, tricking nearby devices into connecting. This allowed them to intercept mobile traffic, including phone numbers, IMSI, and IMEI identifiers, and later capture SMS and ARS authentication codes used for micropayments. The PIPC found KT’s security measures severely lacking: - Femtocell certificates remained valid for 10 years without renewal. - Connections were not restricted by source IP addresses. - A bypass route allowed attackers to evade the femtocell management server. ### Additional Security Failures The investigation also uncovered a separate malware infection in March 2024, affecting 38 KT servers. The malware, BPFDoor a stealthy Linux/Solaris backdoor linked to the China-nexus Red Menshen group enabled attackers to monitor network traffic covertly using Berkeley Packet Filter (BPF) technology. Despite detecting the infection, KT failed to report it and later deleted logs from compromised servers, hindering the PIPC’s ability to assess the full scope of the breach. ### Regulatory Response In addition to the fine, the PIPC ordered KT to: - Strengthen femtocell and network security controls. - Improve governance over personal data protection. - Ensure its Chief Privacy Officer has meaningful oversight. - Expand ISMS-P certification to cover mobile network systems. The Commission also announced plans to push for legislative changes, including stricter penalties for companies that conceal or destroy evidence during investigations. The case follows a similar incident at LG U+, where logs were wiped before authorities could fully assess the breach.
INCIDENT DETAILS -
TYPE
Data BreachNetwork CompromiseMalware Infection
MOTIVATION
Financial GainData Exfiltration
IMPACT
Financial Loss: KRW 53.979 billion ($39 million) fine + KRW 240 million ($167,400) in fraudulent paymentsData Compromised: Personal data of 16,647 subscribers, including phone numbers, IMSI, IMEI identifiers, SMS/ARS authentication codesFemtocell network38 KT serversOperational Impact: Network traffic interception, fraudulent micropayments, regulatory scrutinyCustomer Complaints: Reported fraudulent micropaymentsBrand Reputation Impact: Severe (public disclosure, regulatory fine, customer distrust)Legal Liabilities: PIPC fine, potential future legal actionsIdentity Theft Risk: High (exposure of PII and authentication codes)Payment Information Risk: High (fraudulent micropayments)
DATA BREACH
Phone numbersIMSIIMEI identifiersSMS/ARS authentication codesNumber Of Records Exposed: 16,647Sensitivity Of Data: High (personally identifiable information, authentication codes)Data Exfiltration: Yes (fraudulent micropayments indicate data was used)Personally Identifiable Information: Yes (phone numbers, IMSI, IMEI, authentication codes)

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for L ?
?
What was L's A.I Rankiteo Cyber Score in July 2026 ?
?
What was L's A.I Rankiteo Cyber Score in June 2026 ?
?
What was L's A.I Rankiteo Cyber Score in May 2026 ?
?
What was L's A.I Rankiteo Cyber Score in April 2026 ?
?
What was L's A.I Rankiteo Cyber Score in March 2026 ?
?
What was L's A.I Rankiteo Cyber Score in February 2026 ?
?
What was L's A.I Rankiteo Cyber Score in January 2026 ?
?
What was L's A.I Rankiteo Cyber Score in December 2025 ?
?
What was L's A.I Rankiteo Cyber Score in November 2025 ?
?
What was L's A.I Rankiteo Cyber Score in October 2025 ?
?
What was L's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on L's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with L ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view L's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?