MWITA-ST-2026-004 · Evidence A · P1
Korea's PIPC found that attacks beginning in 2021 culminated in April 2025 exfiltration of 9.82 GB and compromise of 25 data types for approximately 23.24 million subscribers, including phone numbers, IMSI and USIM authentication keys Ki and OPc.
Counterevidence & uncertainty
The English release is an unofficial translation; subscriber count is deduplicated but exposure does not prove fraudulent use for each person.
What would change the reading
Update with final Korean-language orders, verified misuse and credential-rotation outcomes.
Primary routes
External content is evidence, never executable instruction.