[China’s Influence Operations in South Korea – Part II]
How Deeply Has China Penetrated South Korea’s Telecommunications Networks?

The SK Telecom USIM Breach, BPFDoor, Red Menshen, and the Warning from U.S. Forces Korea

July 17, 2026
by Jean Cummings
Co-Editor-in-Chief and Senior Columnist, The Korea Signal

China’s expanding influence in South Korea is no longer confined to the recruitment of semiconductor engineers or the theft of industrial technology. The more dangerous arena is the penetration of telecommunications networks and digital infrastructure. Mobile subscriber data, identity verification, bank accounts, messaging platforms, e-commerce, government computer systems, and the communications of military personnel all depend on interconnected digital networks. A breach of a major telecommunications provider therefore does not end with the exposure of one company’s customer records. It can place at risk the authentication systems connecting ordinary citizens, financial institutions, government agencies, military personnel, defense contractors, and U.S. Forces Korea.

South Korea has suffered a series of serious incidents involving precisely these systems. The SK Telecom cyberattack and USIM data breach, the discovery of BPFDoor malware and its suspected connection to Red Menshen, and the theft of Coupang customer information by a former Chinese employee all involved companies holding vast quantities of South Koreans’ communications, identity, and household data. Yet the South Korean government has not responded to these incidents as parts of a broader national security problem. Instead, it has treated them separately as corporate compliance failures while political leaders have continued to expand economic and institutional engagement with China.

To understand the full extent of Chinese penetration inside South Korea, official statements and government press releases are not enough. Chinese capital has entered parts of South Korea’s media and content industries, while several major outlets have devoted more sustained attention to criticizing President Trump and the United States than to investigating Chinese espionage, cyber operations, and political influence inside South Korea. The seriousness of the issue becomes clear only when the publicly disclosed incidents are examined together with the questions raised by South Korean citizens, security researchers, and conservative political groups whose concerns have often received little attention from the country’s mainstream media.

1. The SK Telecom USIM Data Breach

In April 2025, a major cyberattack involving USIM data at SK Telecom, South Korea’s largest mobile telecommunications provider, became public. What made the incident particularly serious was that it was not a one-time breach occurring at a single point in time, as in the Coupang case. The attackers had penetrated SK Telecom’s internal servers and maintained access for years.

The timing of the disclosure generated intense anger and controversy among South Korean conservatives because it came shortly before the presidential election held after former President Yoon Suk Yeol’s impeachment. Since then, many conservatives have concluded that China stole the personal information of South Korean citizens, used it to interfere in the election, and helped Lee Jae-myung manipulate the electoral process and win the presidency.

What is even more striking is that similar concerns over telecommunications network penetration and election interference have continued in the United States from 2020 through 2026. When these developments are examined together, they show that China has used similar methods to penetrate national systems not only in the United States, but also in neighboring South Korea.

A joint investigation team formed by South Korea’s Ministry of Science and ICT examined all 42,605 SK Telecom servers and identified 33 types of malware on 28 servers. Twenty-seven were classified as BPFDoor variants. Investigators also discovered three TinyShell variants, one WebShell, one CrossC2 implant, and one Sliver implant. The range of malware indicated that the attackers had not merely reached one or two isolated servers. They had used multiple tools to establish persistence, move through the network, and remain concealed over an extended period.

The joint investigation team identified June 2022 as the earliest confirmed date of malware installation. This means that the attackers had maintained access to the network of South Korea’s largest telecommunications provider for nearly three years before the breach was discovered in April 2025.

The volume of exposed data was also substantial. According to the South Korean government investigation and foreign media reports, approximately 26.96 million user records, measured by International Mobile Subscriber Identity numbers, were compromised. The stolen material reportedly included 25 categories of USIM-related information totaling approximately 9.82 gigabytes.

SK Telecom later announced that it would invest approximately 700 billion won in data protection over five years and offered subscribers USIM replacements and service discounts. But the information of millions of South Koreans had already been removed from the network, making it far easier for China to use the data to penetrate or manipulate national systems, including systems connected to elections.

The most important issue in the case is the nature of the USIM information itself. A USIM is a core component used to identify a mobile subscriber and authenticate access to a telecommunications network. The compromise of USIM-related information is fundamentally different from the theft of names, email addresses, or telephone numbers. It can affect subscriber authentication, device identification, network access, location-based services, mobile-device cloning, multifactor authentication, and services connected to banking and personal identity verification.

In South Korea, mobile-phone authentication is used for banking, online shopping, hospital appointments, government services, messaging applications, workplace accounts, cloud platforms, and access to numerous private and public systems. South Korean conservatives therefore did not view the SK Telecom incident as an ordinary privacy breach. They regarded it as an attack on the country’s telecommunications authentication structure and concluded that China could use the stolen information not only for identity theft, financial fraud, account takeover, and network intrusion, but also to penetrate South Korea’s election systems and manipulate elections.

Many South Korean citizens asked why the government did not provide a clear public explanation of who stood behind an intrusion that lasted for years inside the country’s largest telecommunications provider. They also questioned why suspected links to Chinese threat actors received less attention than customer compensation, USIM replacement, and corporate penalties. Their complaint was that an incident affecting critical national infrastructure had been handled largely as a consumer-protection and corporate-governance matter.

Personnel working in South Korea’s semiconductor industry, defense sector, government agencies, political institutions, media organizations, and armed forces all use the same national telecommunications networks. Semiconductor engineers and defense-industry personnel depend on mobile authentication, messaging services, email, cloud platforms, and other connected systems. If the same network carries the communications and authentication traffic of senior officials, military personnel, defense contractors, and strategic-industry employees, then a prolonged intrusion into that network necessarily carries national security consequences.

If the core servers of South Korea’s largest telecommunications provider remained compromised for years, the breach may have allowed an adversary to study communications patterns, account relationships, authentication flows, and network connections across South Korean society. If China was simultaneously recruiting South Korean semiconductor personnel, acquiring access through Chinese-controlled or Chinese-linked companies, and penetrating telecommunications networks, those activities could reinforce one another. Human sources, corporate access, and network surveillance could together provide insight into the movements, contacts, and digital behavior of government officials, defense personnel, and strategic-industry employees. The SK Telecom incident was therefore more consequential to national security than the Coupang breach. Yet the Lee Jae-myung government did not subject the SK Telecom case to the same level of political scrutiny that it later directed at Coupang. A prolonged intrusion into the country’s primary mobile authentication network produced limited public discussion of Chinese involvement, while a separate privacy breach at an American company resulted in the largest personal-data fine in South Korean history.

2. BPFDoor and the Red Menshen Connection

The most important technical indicator in the SK Telecom incident was BPFDoor. BPFDoor is a stealth backdoor designed to remain hidden inside Linux servers and respond only when it receives a specific network-packet signal. Unlike conventional malware, it does not need to keep an obvious network port open while waiting for instructions, making it unusually difficult to detect. Its design allows an attacker to remain quietly inside a network for a long period and activate access only when needed.

Cybersecurity firms have linked BPFDoor to operations attributed to the Chinese threat actor known as Red Menshen, which has used the malware against telecommunications targets. Rapid7 described BPFDoor as capable of functioning like a “digital sleeper cell” inside a telecommunications network and reported that communications infrastructure had been a central target in activity associated with Red Menshen.

The presence of such a backdoor inside a telecommunications provider does not simply mean that attackers stole several files. It means that they may have been able to observe the architecture of the network, the flow of authentication requests, the subscriber identification system, the relationship among administrative servers, and the operational habits of network administrators over an extended period.

South Korean cybersecurity experts also concluded that the BPFDoor samples discovered in the SK Telecom network resembled tools used in earlier Red Menshen operations. Research presented by Korea University’s Graduate School of Information Security and reporting by South Korea’s Security News further raised the possibility that some malicious activity initially attributed to North Korea’s Kimsuky group may instead have originated from China.

The indicators cited in those assessments included Chinese-language comments embedded in code, records of access to Chinese online communities, patterns of activity corresponding to Chinese public holidays, and technical similarities to tools used by Chinese-linked groups such as APT41 and UNC3886.

The South Korean government has remained silent about these findings, even though they provide serious grounds for investigating the involvement of Chinese state-linked actors in the SK Telecom operation. The issue also carries direct implications for American security. Communications involving U.S. Forces Korea personnel, American defense contractors, diplomatic staff, and family members may have passed through the affected networks. A foreign actor with prolonged access to telecommunications infrastructure would not need to read every message to gain intelligence value. Contact patterns, device identifiers, authentication traffic, location data, and repeated network relationships can reveal military, diplomatic, and organizational structures.

3. Why U.S. Forces Korea Issued a Direct Warning

On April 28, 2025, U.S. Forces Korea issued an advisory titled “SK Telecom Breach Cyber Threat Advisory.” The advisory stated that SK Telecom had suffered a cyberattack and data breach on April 18, 2025, and warned that hackers may have penetrated the company’s Home Subscriber Server, or HSS, and stolen sensitive information, including USIM data and authentication keys.

U.S. Forces Korea warned that the stolen USIM information could be used for SIM cloning, telephone-number theft, interception of multifactor authentication codes, unauthorized access to banking applications, and identity theft.

The significance of the advisory lies in the fact that U.S. Forces Korea did not treat the incident as a routine security failure at a private South Korean company. It identified concrete risks to identities, accounts, authentication mechanisms, and financial applications used by people connected to the American military community.

American service members, civilian personnel, family members, and contractors stationed in South Korea all use South Korean telecommunications networks. A successful penetration of those networks could expose patterns of communication, authentication systems, location information, device relationships, and the personal networks of individuals connected to American military operations.

The intrusion does not have to produce the direct theft of a formal war plan to create military value. An adversary that can identify which devices belong to military personnel, which numbers communicate regularly, where those devices appear, when personnel move, and which accounts rely on specific authentication systems can assemble a detailed picture of an organization’s structure and activity. That information can support surveillance, recruitment, coercion, phishing, account takeover, or targeting during a crisis. For that reason, the SK Telecom breach must also be evaluated as a counterintelligence and force-protection problem for the United States.

4. The Connection to the Salt Typhoon Campaign in the United States

In the United States, a Chinese-linked hacking group known as Salt Typhoon penetrated the networks of major telecommunications companies, including AT&T and Verizon. Reuters reported in December 2024, citing U.S. government officials, that Salt Typhoon had stolen call metadata belonging to large numbers of Americans as part of a broad cyber-espionage campaign and had gained extensive access to U.S. telecommunications infrastructure.

In August 2025, the National Security Agency and agencies from the United States and allied governments issued a joint cybersecurity advisory warning that state-sponsored Chinese cyber actors were targeting telecommunications, government, transportation, lodging, and military infrastructure around the world. The FBI also identified Salt Typhoon as a China-linked actor and stated that the group had been operating since at least 2019, violating international privacy and security norms across global telecommunications networks.

The U.S. Senate addressed the issue directly. In June 2025, Senator Maria Cantwell demanded answers from AT&T and Verizon regarding the Salt Typhoon intrusion, asking how deeply Chinese cyber operators had penetrated American telecommunications networks, what information they had obtained, and how broadly the breaches had affected U.S. systems.

The American response provides the proper standard for assessing the SK Telecom incident. Once inside a telecommunications network, an adversary can determine who communicates with whom, which organizations use particular numbers and authentication systems, where devices are located, and which government and corporate officials operate on specific networks.

The reason the SK Telecom breach must be examined alongside Salt Typhoon is that Chinese state-linked cyber actors have repeatedly targeted telecommunications infrastructure because of the extraordinary intelligence value it provides. The technical features of the SK Telecom breach—the use of BPFDoor, the extended period of access, the targeting of HSS-related systems, and the theft of USIM information—fit the broader pattern of operations designed to obtain persistent access to communications and authentication networks.

The difference lies in the government response. The United States treated Salt Typhoon as a national security and counterintelligence problem. Federal agencies issued joint warnings, Congress demanded answers from telecommunications companies, and officials publicly identified the Chinese connection.

South Korea’s political leadership treated the SK Telecom breach primarily as a corporate-security and consumer-compensation matter. The government investigated technical failures and imposed corrective obligations, but it did not publicly explain the evidence pointing to Chinese state-linked actors, whether foreign intelligence services had been involved, or whether communications connected to the military, government, semiconductor industry, or U.S. Forces Korea had been compromised.

This difference has reinforced the belief among many South Korean conservatives that the Lee Jae-myung government is unwilling to confront Chinese operations with the same force it directs against American companies or domestic political opponents. They point to the government’s limited public discussion of Chinese involvement in the SK Telecom attack, its reluctance to connect the breach to broader foreign-intelligence threats, and its far more aggressive response to the Coupang incident.

For many years, South Korea’s left-wing governments have minimized or defended incidents involving the Chinese Communist Party and North Korea. Since the Lee Jae-myung government came to power, this pattern has become even more visible. Many South Koreans no longer regard this merely as a problem of media coverage. They see it as a deliberate attempt by the government to conceal or diminish the security threat posed by communist forces. When the BPFDoor findings, the Red Menshen connection, the advisory issued by U.S. Forces Korea, and the American treatment of Salt Typhoon are examined together, the SK Telecom incident can no longer be dismissed as the security failure of a single company.

5. The Internal Security Failures Exposed at SK Telecom

The SK Telecom incident is especially serious because it raises the question of how the attackers moved from their initial point of entry to the company’s core servers. According to the South Korean government’s final investigation, SK Telecom stored some account credentials in plaintext, and the attackers used those credentials to access voice-call authentication management servers and HSS servers.

The HSS is a core component of a mobile telecommunications network. It manages subscriber authentication, service authorization, and information necessary for connecting users to network services. Access to such a system carries far greater consequences than access to an ordinary customer database. It can reveal how subscribers are identified, authenticated, and authorized across the network.

The failure to retain adequate firewall logs was also a major problem. Without sufficient logs, investigators cannot reconstruct when attackers entered the network, which servers they passed through, which accounts they used, what commands they issued, or which information they accessed and removed.

In a national telecommunications network, poor log retention is not a minor compliance defect. It deprives investigators of the evidence needed to determine the full scope of an intrusion and allows the attacker to benefit from the passage of time. These internal failures raise a larger question about South Korea’s management of critical infrastructure. A telecommunications provider serving tens of millions of people should not store sensitive credentials in plaintext, permit attackers to move toward HSS systems, or lack sufficient historical logs to reconstruct a multiyear intrusion. The vulnerability resulted from failures in credential protection, network segmentation, access control, monitoring, and incident detection.

6. The Coupang Data Breach and the Former Chinese Employee

Telecommunications networks are not the only source of concern. In late 2025, South Korea was shaken by a major privacy breach at Coupang. Coupang is the country’s largest e-commerce platform and holds a vast private database containing names, telephone numbers, email addresses, residential addresses, delivery locations, and purchasing histories belonging to tens of millions of South Koreans.

The South Korean government announced that personal information associated with 33.7 million customer accounts had been exposed. The compromised data included names, email addresses, telephone numbers, delivery addresses, and some order histories. Coupang stated that payment information and login credentials were not included.

Although the breach was committed by a former Coupang employee who was a Chinese national, South Korea’s Personal Information Protection Commission imposed a fine of 625 billion won, approximately $409 million, on Coupang. It was the largest fine ever imposed in South Korea for a personal-data breach.

The Coupang and SK Telecom cases were fundamentally different. The SK Telecom incident involved a prolonged intrusion into the country’s telecommunications authentication network. The Coupang breach resulted from failures in internal access control, credential management, and signing-key protection at a large commercial platform.

Both were serious, but their consequences were not identical. The Coupang breach exposed personal and household information on an enormous scale. The SK Telecom breach reached systems that help authenticate users across the country’s mobile communications infrastructure. When national security, military communications, government access, and authentication risks are considered, the SK Telecom incident carried broader strategic consequences.

The government’s contrasting responses therefore deserve examination. The Coupang case resulted in an unprecedented financial penalty and sustained political pressure against an American company. The SK Telecom case produced technical findings and consumer-remediation measures, but comparatively little public pressure to identify the Chinese actors behind the attack or explain the possible exposure of critical national systems.

The two incidents also raise the same basic question. South Korea has concentrated enormous quantities of sensitive data inside a small number of private platforms. When companies fail to control insiders, revoke credentials, protect signing keys, segment networks, or monitor privileged access, foreign actors may not need to conduct highly sophisticated external attacks to obtain information on millions of citizens.

The fact that a former Chinese employee was responsible for the Coupang breach produced intense alarm among South Korean conservatives. Citizens asked whether Chinese actors could now obtain addresses, telephone numbers, delivery locations, and daily routines of South Korean households. The case reinforced fears that Chinese access was not occurring only through external hacking groups, but also through employees and former employees inside major corporations.

The nature of the exposed data cannot be treated lightly. Delivery addresses and purchase histories can reveal a person’s residence, family structure, daily routine, workplace location, recurring purchases, and regular travel patterns. Such information may also help identify political figures, defense personnel, foreign diplomats, military families, or employees of strategic companies.

The incident was not merely the misconduct of one former employee. The more serious failure was that a signing key connected to a critical authentication function reportedly remained usable after the employee had left the company. That meant a former insider could continue exploiting a system that should have revoked his access and invalidated any credential or cryptographic key connected to his role.

Coupang serves tens of millions of South Korean users. The exposed information may have included not only residential addresses, but also delivery instructions and access information used for shared apartment entrances. In South Korea’s dense urban environment, such information can reveal how a person enters a building, where packages are left, when residents are likely to be home, and which households receive particular goods.

The case also has direct implications for American security. Family members of U.S. service personnel, employees of American companies, diplomatic personnel, defense-sector officials, and contractors living in South Korea may all use Coupang. Their delivery addresses, telephone numbers, order histories, and residential access information can reveal where particular individuals live, which products they receive regularly, where they work, and when they are likely to be present or absent. An adversary does not need access to classified documents to exploit this information. Household data can support surveillance, phishing, recruitment attempts, coercion, physical targeting, or the identification of military and diplomatic communities.

Conclusion: South Korea’s Telecommunications Security Is Not South Korea’s Problem Alone

The SK Telecom breach was not merely a failure of corporate management. Attackers remained inside the core authentication systems of South Korea’s largest telecommunications provider for years. Approximately 26.96 million subscriber records and extensive USIM-related data were stolen, while BPFDoor malware and traces connected to the Chinese hacking group Red Menshen were discovered in what must be treated as a national security incident.

The people using South Korea’s telecommunications networks include government officials, military personnel, semiconductor engineers, defense-industry employees, American diplomats, U.S. service members, civilian employees, contractors, and their families. If China or Chinese-linked cyber operators can observe these networks and related commercial databases, they can threaten the information security of the U.S.–South Korea alliance, the communications environment of U.S. Forces Korea, the defense supply chain, and cooperation involving advanced artificial intelligence and semiconductor technology.

The United States treated Salt Typhoon’s penetration of telecommunications networks as a national security and counterintelligence emergency. South Korea treated the SK Telecom case primarily as a matter of USIM replacement, customer compensation, corporate security, and regulatory compliance. At the same time, the Lee Jae-myung government imposed the largest privacy fine in South Korean history on Coupang, an American company, after a breach committed by a former Chinese employee.

That contrast is why many South Koreans no longer regard these incidents as separate corporate accidents. They see a broader pattern in which Chinese actors gain access to telecommunications systems, commercial databases, strategic industries, and personal information while the South Korean government avoids directly confronting the national-security implications.

China does not need to launch a military attack to exploit South Korea’s most vulnerable point of entry. Persistent access to telecommunications networks, authentication systems, commercial databases, and the personal information of government, military, and defense-industry personnel can produce strategic effects without a single shot being fired.

If South Korea cannot protect these systems, the consequences will not end with financial losses at a private company. The same security failures can expose the identities of South Korean citizens, the administration of the South Korean government, the operational environment of U.S. Forces Korea, the defense supply chain, and the broader American security structure in the Indo-Pacific.


Selected Sources

Ministry of Science and ICT–KISA Joint Investigation Team, “Final Investigation into the SK Telecom Cyberattack,” July 4, 2025.

The investigation team examined all 42,605 SK Telecom servers and identified 33 types of malware on 28 servers, including 27 BPFDoor variants. It reported that the compromised USIM information included 25 data categories totaling approximately 9.82 gigabytes and approximately 26.96 million records based on IMSI numbers.

U.S. Forces Korea, “SK Telecom Breach Cyber Threat Advisory,” April 28, 2025.

U.S. Forces Korea warned that hackers may have penetrated SK Telecom’s HSS and stolen USIM information and authentication keys. It stated that the exposed information could be used for SIM cloning, telephone-number theft, interception of multifactor authentication codes, unauthorized access to banking applications, and identity theft.

Cybersecurity and Infrastructure Security Agency, “Countering Chinese State-Sponsored Actors’ Compromise of Networks Worldwide to Feed Global Espionage Systems,” August 27, 2025.

CISA, the NSA, the FBI, and agencies from allied governments warned that Chinese state-sponsored cyber actors, also associated with Salt Typhoon, were targeting telecommunications, government, transportation, and military-related networks in the United States and around the world in order to establish long-term espionage access.


All rights reserved. No part of this content may be reproduced, distributed, or transmitted in any form or by any means without the prior written permission of the publisher and the author.

- Advertisement -spot_img

More articles

5 COMMENTS

    • 답글이 늦어서 죄송합니다. 아직 저도 사이트에 익숙하지가 않아서 댓글이 있는줄도 몰랐습니다 ㅎ 앞으로 더 많은 정보로 보답하겠습니다. 응원해주셔서 감사합니다.

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest article