박철성 기자 〈리서치센터 국장·칼럼니스트〉
■ 〈기획〉 대한민국 통신 보안 붕괴 리포트 〈1〉 SKT 해킹 사태, 과징금 1인당 5870원 그마저 불복 중!
■ 당신의 유심이 4년간 털리는 동안 국가는 무엇을 했나
조사 결과, 침입 시점은 2021년 8월까지 거슬러 올라간다.
그리고 2025년까지 아무도 몰랐다.
그 사이 가입자 기준 약 2300만 명이 털렸다.
해커는 SK텔레콤 관리망에 조용히 들어왔다. 흔적도 없이.
2021년 12월엔 가입자 관리 핵심 시스템(HSS)까지 파고들었다. 여전히 아무도 몰랐다. 2025년 4월 18일 오후 6시 9분. SKT 네트워크인프라센터가 트래픽 이상 징후를 처음 감지했다. 4년이 지난 뒤였다.
2300만 명의 유심 정보가 이미 빠져나간 다음이었다. 이 정보는 한 번 유출되면 회수되지 않는다. 그리고 대부분의 이용자는 그 사실조차 모른 채 계속 사용한다.
▲25년 5월 7일, 최태원 SK그룹 회장이 서울 중구 SK텔레콤 T타워 SUPEX홀에서 유심 해킹 사고 관련 대국민 사과를 하고 있다. 사고 발생 후 SKT는 1조2000억 원을 투입했지만 그 대부분은 수습 비용이었다.
■ 감독기관은 뭘 했나 — "몰랐다"가 말이 안 되는 이유
과학기술정보통신부가 있다. 한국인터넷진흥원(KISA)이 있다. 둘 다 통신망 보안을 감독하는 기관이다. 둘 다 4년 동안 몰랐다.
그냥 몰랐던 게 아니다. 처음부터 '못 보게 만든 구조'였다.
현행 정보통신망법상 통신사는 보안 점검 결과를 정부에 "자율 보고"한다. KISA가 SKT 내부 서버에 직접 접근해 점검할 수 있는 법적 권한은 사실상 없다. 침해 사고가 발생해야 비로소 현장 조사에 들어갈 수 있다. 들어오기 전엔 못 본다. 들어온 뒤엔 이미 늦다.
여기서 한 가지 더 짚어야 한다. SKT는 2022년 2월, 특정 서버에서 비정상 재부팅이 발생해 점검하는 과정에서 악성코드 감염 서버를 발견했다. 민관합동조사단 발표에 따르면 이 사실은 즉각적인 신고로 이어지지 않았다. 신고 의무 위반 여부는 법적 판단 영역이다. 그러나 그 시점 이후에도 감염은 계속됐다. 정부 조사는 그제야 시작됐다. 순서가 이미 틀려 있었다.
해커가 사용한 악성코드는 BPFDoor다. 서버에 숨어 탐지를 피하도록 설계된 리눅스 기반 백도어 프로그램이다. 보안 장비 눈에 잘 안 띈다는 게 핵심이다. 2021년 이미 보안업계에 알려진 코드다. 보안업계에서는 이 수법이 특정 중국계 APT 그룹과 연관된 것으로 추정해 왔다. 다만 공식적으로 특정된 바는 없다. 중동과 아시아 통신사를 수년간 공격해온 패턴이다. 2024년 7월과 12월. 한국 통신사들이 이미 같은 공격의 타깃이 됐다는 보고도 있었다.
민간 보안업계는 경고를 보냈다. 과기부와 KISA는 통신사에 대응 지침을 전달했다고 밝혔다. 그런데 SKT 서버엔 그 지침이 적용되지 않았다.
지침을 내린 것과 지침이 지켜졌는지 확인한 것은 다른 일이다. 감독기관은 전자만 했다.
따로 짚어야 할 게 있다. SKT 서버에서 발견된 취약점 'DirtyCow'. 2016년에 공개된 리눅스 보안 결함이다. 공개된 지 9년 된 취약점이었다. 그 취약점이 실제로 방치됐는지, 왜 탐지되지 않았는지는 설명이 필요하다. 아직 그 설명은 없다.
"사전 감시"를 한다는 기관들이 사실상 "사후 수습"만 하고 있었다.
▲SKT 대리점 유리창에 내걸린 사과문. "끝까지 책임을 다하겠다"는 문구 아래 유심 무상 교체와 유심보호서비스 안내가 적혀 있다. 사고 이후 2411만 명이 유심보호서비스에 가입했다.
■ 최종 조사 결과 — 숫자가 말한다
민관합동조사단이 최종 발표한 숫자를 보자.
피해 서버 28대. 발견된 악성코드 33종. BPFDoor 계열 변종 27개, 타이니쉘 3종, 웹쉘 1종, 오픈소스 악성코드 2종이다. 유출된 정보는 휴대전화 번호, IMSI(가입자 식별키), 유심 인증키(Ki·OPc) 등 25종. 가입자 수 기준 약 2300만 명, 중복 포함 유출 건수는 2695만 7749건이다. 유출 데이터 총량 9.82GB.
처음 SKT가 발표할 때는 악성코드 4종이었다. 조사할수록 33종으로 불어났다. 처음부터 제대로 파악조차 못 하고 있었다는 뜻이다.
사고 직후 SKT가 국민에게 한 첫 설명이 사실과 8배 이상 차이가 났다. 이걸 "정보 부족에 따른 초기 발표"로 봐줄 것인지. "축소 보고"로 볼 것인지. 독자 각자가 판단하면 된다.
■ 1347억 — 1인당 5870원
개인정보보호위원회는 지난해 8월 SKT에 과징금 1347억9100만 원을 부과했다. 위원회 스스로 "매우 중대한 위반행위"라고 규정했다. 개보위 출범 이래 역대 최대 과징금이다.
숫자를 나눠보자.
피해 가입자 2300만 명. 과징금 1347억 원. 1인당 5870원이다. 커피 한 잔 값도 안 된다.
SKT의 연간 영업이익은 1조 원대다. 1347억은 두 달도 안 되는 영업이익이다.
이 정도 처벌이라면 경영진 입장에서 냉정하게 따져볼 수 있다. 보안 투자를 수천억 쏟아붓는 것보다. 사고 나면 과징금 내는 게 더 싸게 먹힌다.
구조가 그렇게 돼 있다. 이 구조에서는 사고가 '리스크'가 아니라 '비용'이 된다.
■ SKT의 반응 — 불복, 그리고 법정
SKT는 과징금 처분에 불복했다. 지난 1월 19일 행정소송 소장을 법원에 제출했다. 소송대리인은 법무법인 김앤장이다.
SKT 측 논리는 세 가지다. 그리고 셋 다 핵심을 비껴간다.
첫째, 해킹 이후 보상과 정보보호 혁신에 1조2000억 원을 투입했다. 둘째, 실제 금융 피해는 발생하지 않았다. 셋째, 과징금 산정 기준이 과도하게 적용됐다.
하나씩 따져보자.
1조2000억 원 중 상당 부분은 유심 무상 교체, 요금 할인, 마케팅 비용이다. 피해를 막는 데 쓴 돈이 아니다. 이미 털린 뒤 수습하는 데 쓴 돈이다. 순서가 틀렸다.
"금융 피해가 없었다"는 논리는 더 위험하다. 유출된 IMSI는 복제폰 제작에 쓰인다. 2단계 인증 우회에 쓰인다. 향후 정교한 피싱 공격의 재료가 된다. 피해가 지금 안 나타났다는 게 피해가 없다는 증거가 아니다. 시한폭탄이 아직 터지지 않은 것뿐이다.
과징금 산정 기준 문제는 법정에서 가릴 일이다. 다만 이 소송의 본질을 직시해야 한다. 2300만 명의 개인정보를 4년간 방치한 기업이 국가와 다투는 그 장면 자체가 이미 답이다.
▲SKT 해킹 사태 직후 전국 휴대폰 판매점에 "해킹 대란" 현수막이 내걸렸다. SK에서 KT·LG U+ 이동 시 최대 70만 원 지원을 내세운 경쟁 마케팅이 쏟아졌다. 사고 공식 발표 후 2주 만에 25만 명이 SKT를 떠났다.
■ 이 나라엔 막을 구조가 없었다
감독기관은 4년 동안 몰랐다. 법 구조상 알 수 없게 설계돼 있었다. 알고 나서 때린 과징금은 1인당 5870원이었다. SKT는 그 처분에도 불복했다.
2300만 명의 개인정보가 털리는 동안. 이 나라의 통신 보안 감독 체계는 작동하지 않았다. 사후 처벌도 기업이 감수할 만한 수준이었다.
구조를 바꾸지 않으면 다음 사고는 이미 예고돼 있다.
법 개정. 과징금 상한 현실화. 감독기관의 실질적 점검 권한 확보. 이 세 가지가 없으면 SKT 사태는 유사 사례의 시작일 뿐이다.
▲SKT 유심 해킹 사태 전체 구조도. 2021년 8월 최초 침입부터 4년간의 감독 공백, 1인당 5870원의 과징금, 법무법인 김앤장을 앞세운 행정소송까지 한눈에 정리했다. / 인포그래픽=AI 생성
2300만 명이 털렸다.
그런데 시스템은 그대로다.
이미 한 번 일어났다.
그리고 아무것도 바뀌지 않았다.
다음 피해자는 아직 이름이 없을 뿐이다.
이 시스템에서는 누가 털릴지가 아니라 언제 털릴지가 문제다.
〈2편에서 계속 — 유심 교체 대란, SKT는 왜 준비가 없었나〉
pcseong@naver.com
아래는 위 기사를 구글 번역을 통해 영문으로 옮긴 전문입니다. 이해를 돕기 위한 참고용 번역으로, 일부 표현에는 원문의 뉘앙스와 차이가 있을 수 있습니다.
The following is a reference translation generated for reader convenience. Some nuances may differ from the original Korean text.
■ 〈Special Report〉 Korea’s Telecom Security Collapse 〈1〉
■ SKT Hack: $4.30 Per User — And Even That Is Being Challenged
■ What Was the State Doing While Your SIM Data Was Exposed for Four Years
By Park Cheol-seong, Veteran Journalist / <Director of the Research Center · Columnist>
The breach traces back to August 2021.
And no one knew until 2025.
In that time, approximately 23 million subscribers were exposed.
The attackers slipped quietly into SK Telecom’s internal network. There were no visible signs.
By December 2021, they had penetrated the Home Subscriber Server (HSS), the core system managing subscriber identities. Still, no one noticed. At 6:09 p.m. on April 18, 2025, SKT’s Network Infrastructure Center finally detected abnormal traffic. It had taken four years.
By then, SIM-related data for roughly 23 million users had already been extracted. This data, once leaked, cannot be retrieved. Most users continue using their devices without ever knowing.
▲ May 7, 2025. Chey Tae-won publicly apologizes at SK Telecom’s T Tower in Seoul. SKT later said it spent KRW 1.2 trillion on response measures — most of it post-incident damage control.
■ Where Were the Regulators — Why “We Didn’t Know” Doesn’t Hold
There is the Ministry of Science and ICT. There is Korea Internet & Security Agency. Both are responsible for overseeing telecom security. Both failed to detect the breach for four years.
This was not mere oversight. It was a structure that made detection unlikely from the start.
Under current law, telecom operators self-report security inspections. KISA has no effective authority to directly access internal servers without an incident. Before a breach, it cannot see. After a breach, it is already too late.
One detail matters.
In February 2022, SKT identified malware on a server while investigating abnormal reboots. According to the joint public-private investigation, this did not lead to an immediate report. Whether this constitutes a legal reporting violation remains a matter for judicial interpretation. What is clear is that the infection persisted. The official investigation began only afterward. The sequence was already broken.
The malware used was BPFDoor — a Linux-based backdoor designed to evade detection. It had been known in security circles since 2021. Industry analysts have linked similar techniques to Chinese-affiliated APT groups, though no official attribution has been made. The same attack patterns had already been reported targeting telecom operators across the Middle East and Asia. Korean telecom firms were flagged as potential targets in July and December 2024.
Private cybersecurity firms issued warnings. The ministry and KISA say they passed along response guidelines. But those guidelines were not implemented within SKT’s systems.
Issuing instructions and verifying compliance are not the same. Regulators did the former, not the latter.
Another issue remains unresolved.
A known Linux vulnerability, “DirtyCow,” disclosed in 2016, was identified on SKT servers. Nine years later, questions remain: Was it left unpatched? Why was it not detected? There are still no clear answers.
A system that claims to provide “proactive oversight” functioned, in reality, only after the damage was done.
■ Final Findings — The Numbers Speak
The joint investigation revealed:
28 compromised servers.
33 types of malware — including 27 BPFDoor variants, 3 TinyShell, 1 web shell, and 2 open-source strains.
25 categories of leaked data, including phone numbers, IMSI, and SIM authentication keys (Ki, OPc).
Affected users: approximately 23 million.
Total leaked records (including duplicates): 26,957,749.
Total data volume: 9.82GB.
SKT initially reported only four malware types. That number later rose to 33. The gap is significant.
The company’s first public explanation differed from the final findings by more than eightfold. Whether this reflects incomplete information or underreporting is left to public judgment.
■ KRW 134.7 Billion — About $4.30 Per User
The Personal Information Protection Commission imposed a fine of KRW 134.79 billion. It called the violation “very serious.” It is the largest penalty in the commission’s history.
Broken down:
23 million users.
KRW 134.7 billion total.
Approximately KRW 5,870 per person — about $4.30.
Less than the price of a cup of coffee.
SKT’s annual operating profit exceeds KRW 1 trillion. The fine equals less than two months of earnings.
From a purely economic standpoint, the calculation becomes straightforward: it can be cheaper to pay the penalty than to invest heavily in prevention.
That is the structure. In this system, a breach is no longer a risk. It becomes a cost.
■ SKT’s Response — Appeal and Lawsuit
SKT has challenged the fine in court. On January 19, it filed an administrative lawsuit, represented by Kim & Chang.
Its arguments are threefold. None directly address the core issue.
First, KRW 1.2 trillion invested in response and security improvements.
Second, no confirmed financial damage.
Third, excessive penalty calculation.
Much of the KRW 1.2 trillion went to SIM replacements, discounts, and customer retention — not prevention. The sequence was wrong.
“No financial damage” is a fragile claim. Leaked IMSI data can be used for SIM cloning, bypassing two-factor authentication, and enabling advanced phishing attacks. The absence of immediate damage does not mean there is no damage. It means the impact has yet to surface.
The penalty calculation will be decided in court. But the underlying image remains: a company that exposed 23 million users is now contesting the scale of its punishment. That image speaks for itself.
▲After the breach, telecom stores nationwide displayed banners referencing a “hacking crisis.” Competitors offered up to KRW 700,000 in incentives to switch carriers. Within two weeks, 250,000 users left SKT.
■ A System That Could Not Prevent It
For four years, regulators did not detect the breach. The system was not designed to detect it.
Afterward, the penalty amounted to KRW 5,870 per user. SKT is contesting even that.
While 23 million users were exposed, the national telecom security system failed to function. Post-incident penalties remain within a tolerable range for corporations.
Unless the structure changes, the next breach is already set.
Legal reform.
Higher penalty ceilings.
Real inspection authority.
Without these, this case is not an exception. It is a precedent.
23 million users were exposed.
The system remains unchanged.
It has already happened once.
Nothing has changed.
The next victim simply does not have a name yet.
In this system, the question is not who will be breached. It is when.
〈To be continued — Part 2: SIM Replacement Chaos and Why SKT Was Unprepared〉
pcseong@naver.com