South Korea’s telecom companies have long boasted of running the world’s fastest, most sophisticated mobile networks. That distinction now carries a paradoxical risk: The density and ubiquity of the system have turned it into a hacker’s playground.
한국 통신사들은 세계에서 가장 빠르고 정교한 이동통신망을 운영한다는 점을 오랫동안 자랑해왔다. 그러나 그 명성이 이제는 역설적으로 위험을 부르고 있다. 촘촘하고 어디서나 연결된 시스템이 해커들의 놀이터로 전락했다.
The latest breach at KT, the country’s second-largest mobile carrier, underscores the fragility of digital security in a hyper-connected society. It also exposes a startling new vector of cybercrime. What corrodes public trust most, however, is the company’s response.
국내 2위 이동통신사인 KT에서 최근 발생한 보안 침해 사건은 초연결 사회의 디지털 보안이 얼마나 취약한지를 단적으로 보여준다. 동시에 사이버 범죄의 새로운 수법을 드러냈다. 그러나 무엇보다 국민 신뢰를 무너뜨린 것은 회사의 대응이었다.
Hackers appear to have deployed “ghost base stations,” miniature transmitters that mimic legitimate towers, hijacking user data to authorize fraudulent payments. Once largely the province of state intelligence agencies, the method has now trickled down into ordinary financial crime. As of Wednesday, KT acknowledged 278 victims and losses of about 177 million won ($127,200), concentrated in Gwangmyeong and Bucheon in Gyeonggi Province.
해커들은 ‘유령 기지국’이라 불리는 초소형 송신기를 설치해 정상 기지국을 흉내 내며 사용자 정보를 가로채 부정 결제를 승인한 것으로 보인다. 한때는 주로 국가 정보기관의 전유물이던 수법이 이제는 평범한 금융 범죄에도 활용되고 있다. KT는 수요일 기준 피해자가 278명, 피해액은 약 1억7,700만 원에 달한다고 인정했으며, 주로 경기도 광명과 부천 지역에서 집중적으로 발생했다.
Equally troubling is KT’s handling of the case. Police flagged the first suspicious transaction on Aug. 27, yet the company insisted its network was secure and dismissed the warnings as improbable. Only on Saturday did KT quietly post a notice online, leaving customers exposed for more than a week — a digital equivalent of leaving the vault open and hoping no one notices.
KT의 대응 방식 역시 심각했다. 경찰이 8월 27일 첫 의심 거래를 포착했지만, 회사는 자사 네트워크는 안전하다며 경고를 일축했다. 그러다 9월 첫 주 토요일에야 뒤늦게 온라인에 조용히 공지를 게재했다. 그 사이 고객들은 일주일 넘게 무방비 상태로 방치됐다. 이는 마치 금고 문을 활짝 열어둔 채 아무도 눈치채지 않기를 바라는 것이나 다름없다.
Such delay is more than a public-relations misstep; it reflects a culture where safeguarding corporate reputation outweighs protecting customers. In a country where mobile carriers function as the gatekeepers of banking, shopping and even public services, such behavior is indefensible.
이 같은 지연은 단순한 홍보 실수로 치부할 수 없다. 고객 보호보다 기업 이미지 지키기를 우선하는 문화의 단면이다. 이동통신사가 금융·쇼핑·공공서비스의 관문 역할을 하는 한국에서 이런 태도는 결코 용납될 수 없다.
The failure is not KT’s alone. South Korea has endured a string of high-profile cyberattacks this year: a massive data leak at SK Telecom in April, followed by breaches at Yes24, SGI Seoul Guarantee and Lotte Card. Each incident has been treated as isolated, with government and corporations alike offering piecemeal, reactive fixes — a patchwork approach to a systemic problem.
KT만의 실패도 아니다. 한국은 올해만도 굵직한 사이버 공격을 잇달아 겪었다. 4월 SK텔레콤의 대규모 정보 유출에 이어 예스24, SGI서울보증보험, 롯데카드에서도 보안 침해가 발생했다. 정부와 기업 모두 이를 개별 사건으로만 취급하며 땜질식·사후적 처방에 그쳤다. 이는 구조적 문제에 대한 임시방편적 대응에 불과하다
boast: 자랑하다
sophisticated: 정교한, 세련된
paradoxical: 역설적인
playground: 놀이터
society: 사회
trust: 신뢰
response: 대응, 반응
authorize: 승인하다
ordinary: 평범한
victim: 피해자
transaction: 거래
warning: 경고
notice: 공지
vault: 금고
culture: 문화
safeguard: 지키다, 보호하다
customer: 고객
failure: 실패
khnews@heraldcorp.com


