광고
경제
〈기획〉 대한민국 통신 보안 붕괴 리포트 〈2〉 2300만 털렸다… 그리고 각자 싸우라고 했다
이기는 사람만 보상받는다 — 9월 법정이 가른다
박철성 기자
필자의 다른기사 보기 인쇄하기 메일로 보내기 글자 크게 글자 작게
기사입력: 2026/04/28 [08:57]
트위터 페이스북 카카오톡

박철성 기자 〈리서치센터 국장·칼럼니스트〉

■ 〈기획〉 대한민국 통신 보안 붕괴 리포트 〈2〉 2300만 털렸다… 그리고 각자 싸우라고 했다

■ 이기는 사람만 보상받는다 — 9월 법정이 가른다

 

1편에서 물었다.

 

왜 4년 동안 아무도 몰랐냐고. 이번엔 다른 질문이다. 털린 뒤, 2300만 명은 어떻게 됐나.

 

과징금 1인당 5870원. SKT는 그마저 불복했다.

 

2026년 9월. 법정이 열린다.

 

▲유영상 SK텔레콤 대표가 유심 해킹 사태 관련 기자회견에서 고개를 숙여 사과하고 있다. 사과는 했다. 배상은 법정으로 넘겼다.

 

■ 유심 교체 대란 — 준비가 없었다

 

2025년 4월 22일. SKT가 해킹 사실을 공식 발표했다.

 

그날부터 전국 수천 개 대리점 앞에 줄이 섰다. 수백 명씩. 문을 열기 전부터. 유심을 바꾸러 온 사람들이었다.

 

그런데 유심이 턱없이 부족했다. 대리점마다 하루 수십 개. 수백만 명이 기다렸다.

 

2300만 명 규모의 통신사였다. 국민 절반의 유심 정보가 털렸다. 그런데 재고 준비는 없었다.

 

해외 체류 고객은 더 복잡했다. 당시 해외 로밍 고객은 유심보호서비스 적용에서 제외됐고, 국내처럼 즉시 교체하기도 어려웠다.

 

SKT는 5월 14일이 돼서야 유심보호서비스 2.0을 도입했다. 로밍 요금제와 병행 사용이 가능하도록. 사고 발생 후 26일이 지난 뒤였다.

 

유심 교체를 완료한 고객은 사고 발표 약 2주 후 기준 107만 명이었다. 2300만 명 중 107만 명. 전체의 4.6%였다.

 

대규모 교체 수요에 대한 대비는 부족해 보였다. 왜 부족했는지. 그 질문에 SKT는 아직 답하지 않았다.

 

■ 숫자로 본 실적 붕괴 — 사고가 '비용'이라고 했다

 

1편에서 이렇게 썼다.

 

"이 구조에서는 사고가 '리스크'가 아니라 '비용'이 된다."

 

그 비용이 얼마였는지 이제 숫자로 나왔다.

 

SKT 2025년 2분기 영업이익. 전년 동기 대비 37.1% 급감. 3383억 원. 3분기엔 더 빠졌다. 과징금과 고객 감사 패키지 비용이 한꺼번에 반영됐다. 영업이익 484억 원. 전년 동기 대비 90.9% 급감이다. SKT가 공식 공시한 수치다.

 

연간으로 보면 SKT 2025년 영업이익은 1조732억 원. 전년 대비 41% 급감이다.

 

가입자는 떠났다. 사고 공식 발표 후 2주 만에 25만 명이 이탈했다. 위약금 면제 기간이 끝나는 7월 14일까지 번호이동 순감은 72만 명에 달했다.

 

1조2000억 원을 쏟아부었다. 유심 무상 교체, 요금 할인, 마케팅 비용, 보안 투자. 그런데 영업이익은 41% 빠졌다. 가입자는 72만 명 떠났다. 과징금 1347억은 법정에서 다투는 중이다.

 

보안에 미리 투자했다면 어땠을까. 그 질문은 이미 늦었다.

 

■ 조정안 거부 — 최대 2조3000억의 부담

 

한국소비자원 소비자분쟁조정위원회가 조정안을 내놨다. 피해자 1인당 10만 원 상당을 지급하라.

 

SKT는 거부했다.

 

조정안을 수용할 경우 전체 피해자 2300만 명에게 소급 적용될 가능성이 있었다. 최대 2조3000억 원 규모로 확대될 수 있는 부담이었다. 이 같은 부담 가능성도 영향을 미친 것으로 보인다.

 

개인정보분쟁조정위원회도 별도로 권고안을 냈다. 1인당 30만 원 배상. SKT는 이것도 수용하지 않았다.

 

소비자원 측은 "SKT가 자체적으로 진행한 통신요금 할인을 반영한 것"이라며 "기업이 감수할 수 있는 수준에서 합리적으로 도출된 조정안"이라고 밝혔다. SKT는 그래도 거부했다.

 

조정안이 불성립으로 종결된 순간, 2300만 명은 결과적으로 개별 대응으로 흩어졌다.

 

■ 9175명만 싸우고 있다

 

서울중앙지방법원에 1차 손해배상 청구 소송이 제기됐다. 원고는 9175명이다. 1인당 50만 원, 총 46억 원을 청구하고 있다.

 

2300만 명 중 9175명이다. 0.04%다.

 

나머지 대다수에게 소송은 현실적으로 높은 장벽이다. 소장을 써야 하고, 변호사를 찾아야 하고, 시간과 비용을 감수해야 한다.

 

이 구조에서는 시간이 기업 편으로 작용한다. 결과적으로 버틸수록 유리한 구조다.

 

■ 미국이었으면 달랐다

 

미국엔 집단소송제도(Class Action)가 있다. 피해자 한 명이 소를 제기하면 원칙적으로 집단 전체가 소송 대상에 포함되는 구조다. 개별적으로 소장을 쓸 필요가 없다. 기업은 피해자 전원을 상대해야 한다.

 

집단소송이 가능한 구조에서는 대규모 배상 리스크가 발생할 수 있다. 기업이 보안 투자 압박을 더 크게 느끼는 이유가 여기 있다.

 

한국엔 개인정보·소비자 피해 분야에 그 제도가 없다. 피해자가 한 명 한 명 직접 나서야 한다. 현행 구조는 기업에 유리하게 작동하는 측면이 있다. SKT가 조정안을 거부할 수 있었던 배경이 여기 있다.

 

■ 집단소송법 — 국회는 지금 어디 있나

 

집단소송법 도입 논의가 없었던 게 아니다. 수년째 국회를 맴돌고 있다. SKT 사태 이후 소급 적용 논의까지 꺼냈다. 소비자원도 도입 필요성에 공감하는 입장을 밝혔다.

 

그런데 법은 아직 없다.

 

그 사이 SKT 사태가 터졌다. KT 해킹 사태도 터졌다. LG유플러스 개인정보 유출도 터졌다. 사고는 연속으로 났는데 법은 제자리다.

 

피해자만 늘어나고 있다.

 

■ 9월 법정 — 무엇을 가르나

 

2026년 9월. SKT가 개인정보보호위원회(개보위)를 상대로 제기한 행정소송 첫 변론이 열린다. 소장은 서울행정법원에 접수됐다. 소송대리인은 법무법인 김앤장이다.

 

쟁점은 세 가지다.

 

첫째.

외부 해킹에서 기업 책임 범위는 어디까지인가. SKT 측은 해킹이 외부 범죄 행위인 만큼 100% 차단은 현실적으로 불가능하다는 입장이다. 개보위는 과징금 처분에서 기초적인 보안 조치조차 미 이행했다고 적시했다.

 

둘째.

과징금 산정 기준이 비례 원칙을 위반했는가. SKT 측은 부당이득이 없는 상황에서 제재적 성격으로만 산정한 것은 과도하다고 주장한다.

 

셋째.

유출된 IMSI가 개인정보에 해당하는가. 법조계 일각에서는 다른 정보와 결합해야 특정 개인을 식별할 수 있다는 점에서 법리 다툼이 예상된다고 본다.

 

표면적으로는 SKT 대 개보위 싸움이다. 그런데 본질은 다르다. 해킹 피해에서 기업이 어디까지 책임지는가를 가르는 재판이다. 통신사, 금융사, 플랫폼. 대규모 개인정보를 보유한 모든 기업이 이 재판을 지켜보고 있다. 판결이 나오면 이 나라 보안 투자의 기준선이 바뀐다.

 

그래서 SKT도 물러설 수 없다. 그래서 국가도 물러설 수 없다.

 

참고할 판례가 있다. 2012년 KT 해킹 사태. 870만 명 유출. 피해자 342명이 소송을 냈다. 패소했다. 당시 법원은 기업의 보안 조치가 현저히 미흡했다고 보기 어렵다고 판단했다. 대법원은 2018년 그 판단을 확정했다.

 

SKT는 그 판례를 알고 있다. 법무법인 김앤장도 알고 있다.

 

▲SKT 유심 해킹 사태 2편 전체 구조도. 유심 교체 대란부터 조정안 거부, 9175명 소송, 9월 법정까지 한눈에 정리했다. / 인포그래픽=AI 생성

 

■ 2300만 명은 누가 지키나

 

SKT가 잘못했다는 건 국가기관이 이미 확인했다. 그런데 피해자는 스스로 증명해야 한다. 소장을 써야 한다. 변호사를 찾아야 한다. 법원에 줄을 서야 한다.

 

가해자는 법인이다. 자본이 있다. 변호인단이 있다. 시간을 끌 여력이 있다. 피해자는 개인이다. 2300만 명이지만 혼자다.

 

감독기관은 4년을 몰랐다. 과징금은 1인당 5870원이었다. 조정안은 거부당했다. 집단소송법은 없다. 행정소송은 진행 중이다.

 

2300만 명이 털렸다.

그런데 이기는 사람만 보상받는다.

포기하면 아무것도 없다.

구조가 바뀌지 않는 한, 기업은 크게 다치지 않는다.

대한민국, 다음 사고에서도 결과는 같다.

pcseong@naver.com

 

아래는 위 기사를 구글 번역을 통해 영문으로 옮긴 전문입니다. 이해를 돕기 위한 참고용 번역으로, 일부 표현에는 원문의 뉘앙스와 차이가 있을 수 있습니다.

The following is a reference translation generated for reader convenience. Some nuances may differ from the original Korean text.

 

■ [SERIES] Korea's Telecom Security Collapse Report 〈2〉 23 Million Were Hacked… Then Told to Fight Alone

■ Only the Winners Get Compensated — September's Courtroom Will Decide

 

By Park Cheol-seong, Veteran Journalist / <Director of the Research Center · Columnist>

 

Part One asked the question. How did no one know for four years? This time, the question is different. After 23 million people were hacked — what happened next?

 

A fine of 5,870 won per victim. SKT appealed even that.

 

September 2026. The courtroom opens.

▲     ©호주브레이크뉴스

▲SK Telecom CEO Yoo Young-sang bows deeply at a press conference to apologize for the USIM hacking incident. The apology was made. The compensation was handed to the courts.

 

■ The USIM Replacement Crisis — There Was No Preparation

 

April 22, 2025. SK Telecom officially announced the hacking incident.

 

Lines formed outside thousands of carrier stores across the country that same day. Hundreds of people. Before the doors even opened. They had come to replace their USIMs.

 

But USIMs were in critically short supply. A few dozen per store per day. Hundreds of thousands waited.

 

This was a carrier with 23 million subscribers. Half the nation's USIM data had been compromised. Yet there was no stock prepared.

 

Overseas customers faced an even more complicated situation. At the time, roaming customers were excluded from USIM protection service coverage and could not replace their USIMs as easily as those in Korea.

 

SKT only introduced USIM Protection Service 2.0 on May 14 — enabling use alongside roaming plans. That was 26 days after the incident was announced.

 

The number of customers who had completed USIM replacements stood at 1.07 million as of approximately two weeks after the announcement. Out of 23 million. That is 4.6%.

 

The preparation for large-scale replacement demand appeared insufficient. Why it was insufficient. That question remains unanswered by SKT.

 

■ The Collapse in Numbers — "Accidents Become Costs"

 

Part One stated this.

 

"In this structure, accidents become not a 'risk' but a 'cost.'"

 

Now the numbers show exactly what that cost was.

 

SKT's Q2 2025 operating profit. Down 37.1% year-on-year. 338.3 billion won. Q3 dropped further. The fine and customer appreciation package costs hit simultaneously. Operating profit: 48.4 billion won. Down 90.9% year-on-year. These are SKT's officially disclosed figures.

 

For the full year, SKT's 2025 operating profit was 1.0732 trillion won. Down 41% from the previous year.

 

Subscribers left. Within two weeks of the official announcement, 250,000 had gone. By July 14, when the penalty-free cancellation period ended, net subscriber loss reached 720,000.

 

1.2 trillion won was poured in. Free USIM replacements, billing discounts, marketing costs, security investment. Yet operating profit fell 41%. 720,000 subscribers left. The 134.7 billion won fine is still being contested in court.

 

What if the security investment had come first? That question is already too late.

 

■ Rejecting the Settlement — A Burden of Up to 2.3 Trillion Won

 

The Korea Consumer Agency's Consumer Dispute Mediation Committee issued a settlement proposal. Pay each victim the equivalent of 100,000 won.

 

SKT refused.

 

If the settlement had been accepted, it could have been applied retroactively to all 23 million affected subscribers. The potential burden could have expanded to a maximum of 2.3 trillion won. This level of financial exposure appears to have been a factor in the decision.

 

The Personal Information Dispute Mediation Committee separately issued its own recommendation. 300,000 won per victim. SKT declined this as well.

 

The Korea Consumer Agency stated that the proposal "reflected SKT's own billing discounts" and had been "reasonably derived at a level the company could bear." SKT refused regardless.

 

The moment the mediation collapsed, 23 million people were effectively left to fight on their own.

 

■ Only 9,175 Are Fighting

 

A first-round damages lawsuit has been filed at the Seoul Central District Court. There are 9,175 plaintiffs. Each is claiming 500,000 won — a total claim of 4.6 billion won.

 

9,175 out of 23 million. That is 0.04%.

 

For the vast majority, filing a lawsuit is a formidable barrier. They must draft legal documents, retain an attorney, and bear the cost and time involved.

 

In this structure, time works in the company's favor. The longer it holds out, the more advantageous the position becomes.

 

■ It Would Have Been Different in America

 

The United States has a class action system. When one victim files a suit, the entire affected group is in principle included as plaintiffs. No individual filing required. The company must face all victims at once.

 

In a system where class actions are possible, the risk of large-scale damages can arise. That is why companies face far greater pressure to invest in security.

 

Korea has no such system in the area of personal data and consumer harm. Each victim must come forward individually. The current structure operates in ways that favor companies. That is the backdrop against which SKT was able to refuse the settlement.

 

■ The Class Action Bill — Where Is the National Assembly Now?

 

The debate over introducing a class action bill is nothing new. It has been circulating in the National Assembly for years. After the SKT incident, discussion even arose about retroactive application. The Korea Consumer Agency expressed support for the idea.

 

But the law still does not exist.

 

In the meantime, the SKT incident happened. The KT hacking incident happened. The LG Uplus personal data breach happened. Incidents keep occurring. The law stays where it is.

 

The number of victims keeps growing.

 

■ September's Courtroom — What Will It Decide?

 

September 2026. The first hearing in the administrative lawsuit filed by SKT against the Personal Information Protection Commission (PIPC) is scheduled to open. The filing was made at the Seoul Administrative Court. SKT's legal representative is Kim & Chang.

 

Three issues are at stake.

 

First. How far does corporate liability extend in an external hacking incident? SKT's position is that 100% prevention of external criminal attacks is realistically impossible. The PIPC, in its fine ruling, explicitly noted that even basic security measures had not been implemented.

 

Second. Did the fine's calculation violate the principle of proportionality? SKT argues that applying a punitive-only standard in the absence of any illicit gain is excessive.

 

Third. Does the leaked IMSI qualify as personal information? Some in the legal community anticipate a legal dispute over whether a specific individual can be identified without combining IMSI with other data.

 

On the surface, this is a fight between SKT and the PIPC. But the substance is different. This trial determines how far corporate liability extends in hacking cases. Every telecom company, financial institution, and platform — every entity holding large volumes of personal data — is watching. When the verdict comes, the benchmark for security investment in this country will shift.

 

That is why SKT cannot back down. That is why the government cannot back down either.

 

There is a relevant precedent. The 2012 KT hacking case. 8.7 million records leaked. 342 victims filed suit. They lost. The court found it difficult to conclude that KT's security measures had been significantly inadequate. The Supreme Court confirmed that ruling in 2018.

 

SKT knows that precedent. Kim & Chang knows it too.

▲     ©호주브레이크뉴스

▲Full structure of the SKT USIM hacking series Part 2 — from the replacement crisis to the settlement rejection, the 9,175-person lawsuit, and the September courtroom. / Infographic=AI Generated

 

■ Who Protects 23 Million People?

 

Government agencies have already confirmed that SKT was at fault. Yet victims must prove their case themselves. They must draft legal filings. Find attorneys. Stand in line at courthouses.

 

The perpetrator is a corporation. It has capital. It has a legal team. It has the resources to delay. The victims are individuals. 23 million of them — yet each one stands alone.

 

The regulators didn't know for four years. The fine came to 5,870 won per person. The settlement was rejected. There is no class action law. The administrative lawsuit is ongoing.

 

23 million people were hacked.

Yet only those who fight — and win — get compensated.

Give up, and there is nothing.

As long as the structure doesn't change, companies won't be seriously hurt.

Korea — the outcome will be the same in the next incident too.

pcseong@naver.com

 

ⓒ 호주브레이크뉴스. 무단전재 및 재배포 금지
트위터 페이스북 카카오톡
  • 도배방지 이미지

광고
PHOTO
1/17
최근 인기기사