

The SK Telecom USIM Breach, BPFDoor, Red Menshen, and the Warning from U.S. Forces Korea
July 17, 2026by Jean CummingsCo-Editor-in-Chief and Senior Columnist, The Korea Signal
China’s expanding influence in South Korea is no longer confined to the recruitment of semiconductor engineers or the theft of industrial technology. The more dangerous arena is the penetration of telecommunications networks and digital infrastructure. Mobile subscriber data, identity verification, bank accounts, messaging platforms, e-commerce, government computer systems, and the communications of military personnel all depend on interconnected digital networks. A breach of a major telecommunications provider therefore does not end with the exposure of one company’s customer records. It can place at risk the authentication systems connecting ordinary citizens, financial institutions, government agencies, military personnel, defense contractors, and U.S. Forces Korea.
South Korea has suffered a series of serious incidents involving precisely these systems. The SK Telecom cyberattack and USIM data breach, the discovery of BPFDoor malware and its suspected connection to Red Menshen, and the theft of Coupang customer information by a former Chinese employee all involved companies holding vast quantities of South Koreans’ communications, identity, and household data. Yet the South Korean government has not responded to these incidents as parts of a broader national security problem. Instead, it has treated them separately as corporate compliance failures while political leaders have continued to expand economic and institutional engagement with China.
To understand the full extent of Chinese penetration inside South Korea, official statements and government press releases are not enough. Chinese capital has entered parts of South Korea’s media and content industries, while several major outlets have devoted more sustained attention to criticizing President Trump and the United States than to investigating Chinese espionage, cyber operations, and political influence inside South Korea. The seriousness of the issue becomes clear only when the publicly disclosed incidents are examined together with the questions raised by South Korean citizens, security researchers, and conservative political groups whose concerns have often received little attention from the country’s mainstream media.
1. The SK Telecom USIM Data Breach
In April 2025, a major cyberattack involving USIM data at SK Telecom, South Korea’s largest mobile telecommunications provider, became public. What made the incident particularly serious was that it was not a one-time breach occurring at a single point in time, as in the Coupang case. The attackers had penetrated SK Telecom’s internal servers and maintained access for years.
The timing of the disclosure generated intense anger and controversy among South Korean conservatives because it came shortly before the presidential election held after former President Yoon Suk Yeol’s impeachment. Since then, many conservatives have concluded that China stole the personal information of South Korean citizens, used it to interfere in the election, and helped Lee Jae-myung manipulate the electoral process and win the presidency.
What is even more striking is that similar concerns over telecommunications network penetration and election interference have continued in the United States from 2020 through 2026. When these developments are examined together, they show that China has used similar methods to penetrate national systems not only in the United States, but also in neighboring South Korea.
A joint investigation team formed by South Korea’s Ministry of Science and ICT examined all 42,605 SK Telecom servers and identified 33 types of malware on 28 servers. Twenty-seven were classified as BPFDoor variants. Investigators also discovered three TinyShell variants, one WebShell, one CrossC2 implant, and one Sliver implant. The range of malware indicated that the attackers had not merely reached one or two isolated servers. They had used multiple tools to establish persistence, move through the network, and remain concealed over an extended period.
The joint investigation team identified June 2022 as the earliest confirmed date of malware installation. This means that the attackers had maintained access to the network of South Korea’s largest telecommunications provider for nearly three years before the breach was discovered in April 2025.
The volume of exposed data was also substantial. According to the South Korean government investigation and foreign media reports, approximately 26.96 million user records, measured by International Mobile Subscriber Identity numbers, were compromised. The stolen material reportedly included 25 categories of USIM-related information totaling approximately 9.82 gigabytes.
SK Telecom later announced that it would invest approximately 700 billion won in data protection over five years and offered subscribers USIM replacements and service discounts. But the information of millions of South Koreans had already been removed from the network, making it far easier for China to use the data to penetrate or manipulate national systems, including systems connected to elections.
The most important issue in the case is the nature of the USIM information itself. A USIM is a core component used to identify a mobile subscriber and authenticate access to a telecommunications network. The compromise of USIM-related information is fundamentally different from the theft of names, email addresses, or telephone numbers. It can affect subscriber authentication, device identification, network access, location-based services, mobile-device cloning, multifactor authentication, and services connected to banking and personal identity verification.
In South Korea, mobile-phone authentication is used for banking, online shopping, hospital appointments, government services, messaging applications, workplace accounts, cloud platforms, and access to numerous private and public systems. South Korean conservatives therefore did not view the SK Telecom incident as an ordinary privacy breach. They regarded it as an attack on the country’s telecommunications authentication structure and concluded that China could use the stolen information not only for identity theft, financial fraud, account takeover, and network intrusion, but also to penetrate South Korea’s election systems and manipulate elections.
Many South Korean citizens asked why the government did not provide a clear public explanation of who stood behind an intrusion that lasted for years inside the country’s largest telecommunications provider. They also questioned why suspected links to Chinese threat actors received less attention than customer compensation, USIM replacement, and corporate penalties. Their complaint was that an incident affecting critical national infrastructure had been handled largely as a consumer-protection and corporate-governance matter.
Personnel working in South Korea’s semiconductor industry, defense sector, government agencies, political institutions, media organizations, and armed forces all use the same national telecommunications networks. Semiconductor engineers and defense-industry personnel depend on mobile authentication, messaging services, email, cloud platforms, and other connected systems. If the same network carries the communications and authentication traffic of senior officials, military personnel, defense contractors, and strategic-industry employees, then a prolonged intrusion into that network necessarily carries national security consequences.
If the core servers of South Korea’s largest telecommunications provider remained compromised for years, the breach may have allowed an adversary to study communications patterns, account relationships, authentication flows, and network connections across South Korean society. If China was simultaneously recruiting South Korean semiconductor personnel, acquiring access through Chinese-controlled or Chinese-linked companies, and penetrating telecommunications networks, those activities could reinforce one another. Human sources, corporate access, and network surveillance could together provide insight into the movements, contacts, and digital behavior of government officials, defense personnel, and strategic-industry employees. The SK Telecom incident was therefore more consequential to national security than the Coupang breach. Yet the Lee Jae-myung government did not subject the SK Telecom case to the same level of political scrutiny that it later directed at Coupang. A prolonged intrusion into the country’s primary mobile authentication network produced limited public discussion of Chinese involvement, while a separate privacy breach at an American company resulted in the largest personal-data fine in South Korean history.
You are unauthorized to view this page. Please log in to read this page in full.
이 페이지를 보실 권한이 없습니다. 이 글 전문과 한글 버전을 읽으시려면 로그인을 먼저 해주십시오.
Please renew your membership or subscribe a membership if you didn't yet. Thank you.
멤버십을 갱신하시거나, 만약 구독하지 않으셨다면 구독을 먼저 해주시기 바랍니다. 감사합니다.
정기구독 신청하기 ← click here to subscribe. 여기를 클릭해서 구독해 주세요.




이 게시물을 접해보고
깜짝 놀랐 습니다
한국인도 모르는
한국의 상황을 정확히
파악하고 있다는 사실이
윤대환
앞으로 열심히 기사를 탐독하고
여기서 보게된 진실을 한국 사회에 전파하고 싶습니다
👍👍👍
👍👍👍