![]() |
Photo courtesy of Yonhap News |
[Alpha Biz= Kim Jisun] The National Intelligence Service (NIS) has revealed that it confirmed the decryption of SMS messages on certain KT smartphones in September, which it deemed a significant threat to national cybersecurity.
Following this discovery, the NIS officially notified KT and the Ministry of Science and ICT.According to materials submitted to Representative Choi Min-hee of the National Assembly's Science, Technology, Broadcasting, and Communications Committee on the 13th, the NIS received reports indicating that "SMS encryption could be compromised on certain KT smartphone models" and subsequently verified the facts.
As a result, it was found that SMS communications were not protected by end-to-end encryption, leading to vulnerabilities where messages could be decrypted on intermediary servers.Telecommunications companies are required to implement end-to-end encryption to ensure that the contents cannot be decrypted by intermediary servers, in accordance with recommendations from the International Organization for Standardization (ISO) and the Korea Telecommunications Technology Association (TTA). However, the NIS's verification indicated that this protective measure had been undermined on certain KT devices.
The NIS did not disclose specific models, circumstances, or whether actual information leaks occurred as a result of the decryption.In response, a joint government-private investigation team established to examine the KT hacking incident is further investigating whether the issue is limited to specific smartphones or if it could be replicated across KT’s entire subscriber network, based on the NIS's notification.
Previously, KT was implicated in a hacking incident involving small payment fraud, where hackers were confirmed to have stolen SMS and ARS authentication information from victims. The investigation team has technically verified the possibility that hackers manipulated illegal relay stations (femtocells) to decrypt SMS and ARS signals transmitted to KT’s core network, intercepting them in plaintext for authentication and payment fraud.The investigation team is currently conducting a thorough analysis to determine whether external attackers could access not only authentication information but also general call and SMS data.
Alphabiz Reporter Kim Jisun(stockmk2020@alphabiz.co.kr)















































