Skip to main content
Back to overview
Medium

SK Telecom Suffers Cyberattack, Exposing USIM Data of 23 Million Customers

April 2025 Data Breaches: 4 Million SSNs Leaked, 23M+ in Settlements Stay up to date with Pomerium news and announcements.

Key points

  • Over 23 million customers affected.
  • Sensitive USIM card data exposed.
  • Breach detected on April 18, 2025.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Ransomware

Malware, Social, Hacking, Error activity

03

Potential impact

Service Disruption

Confidentiality, Availability

Published
Apr 18, 2025
Updated
Jul 22, 2026
Confidence
Medium
Evidence
1 source

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Malware, Social, Hacking, Error activity

The feed marks multiple actor roles. Treat this as a review signal rather than a final attribution.

  • Source type: possible insider or internal misuse
  • Source type: supplier or third-party involvement

Business impact

Potential operational disruption
Impact area
Confidentiality, Availability
Likely asset
User or customer data, Server or cloud data store

Mentioned entities

SktelecomData DisclosureSK Telecom Suffers CyberattackMillion Customers AprilMillion SSNs LeakedSettlements StayPomeriumYouCompiledSource

Quick context

Questions about this signal

What happened in this signal?

April 2025 Data Breaches: 4 Million SSNs Leaked, 23M+ in Settlements Stay up to date with Pomerium news and announcements. You have successfully joined our subscriber list. Cyber attacks didn’t slow down this past April 2025, recording sizable breaches and settlements—one data breach compromised the personal identifiable data of 4 million individuals. The cause behind many of these breaches was undisclosed, however, there is a recurring theme of insufficient access controls, third-party vulnerabilities, and delayed breach detection—all weaknesses that zero-trust security measures could have addressed. Compiled on May 1, the following list of data breach headlines published during the month of April contains details behind the cause of the breach (if available). Source articles have been organized by cause of breach (compromised credentials, insider threat, malware, third party data breach, ransomware, social engineering, system vulnerability, and undisclosed) with articles organized in reverse chronological order. Security Breaches Reported in April 2025 Alternate Solutions Health Network Notifies Patients About May 2024 Email Breach | HIPAA Journal Email accounts have been compromised at four HIPAA-regulated organizations: Alternate Solutions Health Network in Ohio; Park Royal Hospital in Florida; 90 Degree Benefits in Minnesota; and the Charleston Fire Department in West Virginia. Almost 107,000 individuals have been affected. Data Breach at Onsite Mammography Impacts 350,000 | SecurityWeek Massachusetts medical services provider Onsite Mammography is notifying over 350,000 people that their personal and health information was compromised in a data breach. The incident was discovered in October 2024 and involved unauthorized access to an employee’s email account, the firm reveals in a notification letter mailed to the impacted individuals.Some of the emails in the compromised account’s inbox, Onsite says, exposed both personally identifiable information (PII) and protected health information (PHI). 33,529 more Texans' data breached by now-fired state workers | The Texas Tribune Texas Health and Human Services Commission late Wednesday began notifying another 33,529 recipients of state benefits that their private information had been improperly accessed. Three months ago, the state notified 61,104 Texans that their personal information may have been improperly accessed by state employees. A total of nine state employees had accessed individuals’ accounts without a stated business reason. SK Telecom shares plunge after data breach due to cyberattack | Reuters SK Telecom shares fell as much as 8.5% on Monday to hit their lowest level since August last year, after South Korea's biggest mobile carrier disclosed it suffered a leak of customer data earlier this month caused by a cyberattack. The company said in a statement it would take full responsibility for any harm caused as a result of the breach that was detected on April 18. It described the incident as a large-scale leak of data due to malware, without providing more details. Marks & Spencer breach linked to Scattered Spider ransomware attack | Bleeping Computer Ongoing outages at British retail giant Marks & Spencer are caused by a ransomware attack believed to be conducted by threat actors known as "Scattered Spider" BleepingComputer has learned from multiple sources. M&S confirmed it suffered a cyberattack that caused widespread disruption, including to its contactless payment system and online ordering. The threat actors are believed to have first breached M&S as early as February, when they reportedly stole the Windows domain's NTDS.dit file. Hitachi Vantara takes servers offline after Akira ransomware attack | Bleeping Computer Hitachi Vantara, a subsidiary of Japanese multinational conglomerate Hitachi, was forced to take servers offline over the weekend to contain an Akira ransomware attack. While the company's cloud services are not impacted, Hitachi Vantara systems and Hitachi Vantara Manufacturing were disrupted as part of the containment effort. Additionally, while Hitachi Vantara's remote and support operations are down, customers with self-hosted environments can still access their data as usual. Ransomware Attack on Frederick Health Medical Group Affects 934,000 Patients | HIPAA Journal Frederick Health Medical Group is facing several potential class action lawsuits over a recent data breach that affected more than 900,000 patients. Frederick Health Medical Group, a Maryland-based healthcare group, announced on January 27, 2025, that it had fallen victim to a ransomware attack and had called in cybersecurity experts to investigate the incident. Two Ransomware Hacks Affect 1.1 Million Patients | BankInfoSecurity Two separate ransomware hacks of a Maryland medical group and a California hospital resulted in data thefts affecting more than 1.1 million patients, according to recent reports to regulators. Cybercriminals claim to have leaked 480 gigabytes of data from one of the attacks. Frederick Health in a report filed on March 28 to the U.S. The Department of Health and Human Services said 934,326 people were affected by its hacking incident early this year. California-based Dameron Hospital reported the breach affected nearly 211,000 people.

When was this signal reported?

Shadow Tier lists Apr 18, 2025 as the signal date.

Which organization is connected to this signal?

Sktelecom is the organization connected to this public signal.

Explore Sktelecom
Which attack pattern is relevant?

This signal is connected to current ransomware incidents based on its reported incident context.

Explore current ransomware incidents
Which impact area is relevant?

This signal is connected to cyber service disruption intelligence based on its reported consequences.

Explore cyber service disruption intelligence