Menu Close

South Korean Police Dismantle Hacking Ring That Targeted BTS Member and Top Executives

Image Credentials: Image Title: South Korean Police Dismantle Hacking Ring That Targeted BTS Member and Top Executives. Source: (chatgpt.com) Date: May 2026. Attribution: This image was created using AI-generated imagery (chatgpt.com) by Open Chronicle and does not depict a real-world scene.

By Open Chronicle with agencies

South Korean police said Thursday they have dismantled a sophisticated cybercrime organization accused of targeting celebrities, business executives, and wealthy individuals through cloned SIM cards and fraudulent mobile phone accounts.

Among the reported targets was BTS member Jungkook, alongside dozens of corporate leaders and high-profile figures across South Korea.

The Seoul Metropolitan Police Agency’s cyber investigation unit confirmed that a Chinese national identified only as “A,” believed to be one of the leaders of the organization, will be referred to prosecutors on Friday while in custody on 18 charges linked to large-scale financial crimes.

Authorities said the group operated between May 2022 and April 2025, stealing personal and financial information from at least 271 victims. Investigators stated that the network primarily focused on individuals who were less likely to quickly detect suspicious activity, including people serving in the military, incarcerated individuals, and others temporarily disconnected from regular communication.

According to police, the criminal organization used two primary methods to compromise victims.

Initially, the hackers cloned victims’ SIM cards, creating so-called “twin SIMs” that allowed them to intercept text messages, authentication codes, and one-time passwords used for banking and cryptocurrency accounts.

After telecommunications companies strengthened protections against SIM cloning, investigators said the group adapted by exploiting vulnerabilities in online SIM activation systems, opening entirely new mobile accounts under victims’ identities.

Police described the operation as an unusually advanced form of cybercrime that bypassed multiple layers of identity verification systems, including digital certificates and i-PIN authentication methods.

Victims included 75 corporate figures, among them 70 chairmen, presidents, and chief executives, with 22 connected to South Korea’s 100 largest business groups.

Authorities also identified 11 politicians, legal professionals, and government officials among the targets, along with 12 entertainers and influencers, six athletes, 28 cryptocurrency investors, and several self-employed individuals.

Of the 271 victims identified during the investigation, 28 suffered actual or attempted financial losses.

Police estimate the organization caused total damages of approximately 73.4 billion won, equivalent to about $48.7 million, including around 25 billion won in attempted thefts.

Investigators said 13 victims were directly affected through SIM cloning, while another 258 were compromised through fraudulent SIM activations.

Among those who suffered confirmed financial losses were 10 corporate leaders or executives, three entertainers or influencers, and three cryptocurrency investors.

South Korean authorities worked closely with Thai police and Interpol during the investigation. Another alleged ringleader, identified only as “B,” was arrested in Bangkok last year and extradited to South Korea.

Police said “A” was initially detained in Thailand on immigration-related charges after being discovered at the same hideout. Following forensic analysis of seized evidence, investigators concluded that he was not a low-level participant but a central organizer behind the fraudulent SIM activation scheme.

He was later transferred back to South Korea in May.

Authorities said the nearly four-year investigation has now been concluded. South Korea also issued an Interpol purple notice to share details of the group’s methods with international law enforcement agencies and improve global prevention efforts against similar cybercrime operations.

Leave a Reply

Your email address will not be published. Required fields are marked *