Connect with us

NEWS

BTS Jungkook Hack: $25.5M Cybercrime Kingpin Extradited From Thailand

Published

on

South Korea brought home the second mastermind of a hacking syndicate that drained roughly $25.5 million from the country’s wealthiest accounts, the Ministry of Justice confirmed this week. The 40-year-old Chinese national arrived at Incheon International Airport from Bangkok on Wednesday, May 13, 2026, ending an extradition file that ran through three Interpol-backed operations and months of Thai court hearings. He is the second ringleader from the same syndicate to be marched through Incheon in nine months.

BTS member Jungkook sat near the top of a target list that ranged from famous entertainers to conglomerate chairmen and venture-company CEOs. Hackers used his stolen identity to open unauthorised brokerage accounts in January 2024 in an attempt to lift 8.4 billion won worth of HYBE shares before BigHit Music froze the trade. He had just begun mandatory military service.

An 11-Month Treaty File Closes At Incheon

The handover capped a chase that began long before the perp walk. The ministry requested the suspect’s provisional arrest from Thai authorities in May last year, followed by a formal extradition request in August. Korea waited through three months of Thai court processing before formally requesting transfer.

Korean prosecutors and investigators were dispatched to Thailand in July 2025 to coordinate with officials from the Thai Prosecutor General’s Office and the Thai National Police. Authorities from both countries also conducted frequent video conferences from October to December 2025. The final ministerial sign-off came this week, per the Justice Ministry’s account in the Korea Times extradition briefing.

A joint operation in Thailand in May 2025 led to the arrest of a 36-year-old Chinese accomplice along with 16 other members of the group. Authorities also secured custody of the latest suspect at the same location. The 40-year-old then stayed on a provisional detention hold while Seoul worked through nine more months of paperwork.

The first ringleader, a 36-year-old Chinese national, was extradited to Korea, indicted and detained in August last year. Identified as Jeon, he is now facing 11 charges, with court proceedings ongoing in Seoul.

How $25.5 Million Slipped Out of Korea’s Elite Accounts

From August 2023 to April 2024, the syndicate allegedly siphoned off more than 38 billion won ($25.5 million) by using illegally obtained personal data to gain access to victims’ bank and cryptocurrency accounts, according to the Ministry of Justice’s statement to the Korea Herald. Another attempt to steal 25 billion won (~ $16.8 million) from 10 people was thwarted only by financial intervention in the eleventh hour.

The breach trail started inside government infrastructure. The hacking group meticulously breached six government and public agency websites to gain resident registration numbers and authentication credentials of 258 high-profile targets.

The target list was not random. Investigators say the group covertly looked into the account balances of as many as 258 people, ranging from famous entertainers to conglomerate chairmen and venture-company CEOs, with 258 high-net-worth Koreans in the crosshairs.

  • $25.5M lifted from victim accounts between August 2023 and April 2025
  • $16.8M second-wave attempt blocked at the eleventh hour
  • 258 high-net-worth Koreans on the target list
  • 89 victims whose names were used to register cloned SIM cards
  • 6 government and public agency websites breached
  • 18 members of the syndicate now in custody

The Budget Carrier Backdoor That Broke Two-Factor Authentication

The crew did not crack a single financial firewall. They walked through the front door using cloned identities.

The hacker ring made use of a loophole in South Korea’s budget mobile carrier system and exploited the mechanism of remote SIM card activation, which helped them bypass in-person verification and enabled them to register phones in the names of 89 victims. That gap let the syndicate intercept every SMS-based one-time password the banks pushed.

Korea’s MVNO market is built for prepaid SIM activation customers can complete entirely online. Larger telcos still require in-person ID checks at retail stores. The syndicate picked the path of least resistance and ran it across 89 cloned identities.

These cloned identities allowed them to even cross the two-factor authentication required to drain accounts. Brokerage logins, crypto exchange withdrawals, and password resets routed straight to attacker handsets.

“This technique compromises SMS-based MFA by transferring the target’s phone number to the attacker,” says Matthew Gardiner, Product Marketing Manager at Proofpoint, in the firm’s SIM swapping threat reference. Bitsight’s threat research team places telecommunications among the most-targeted industries for SIM-swap fraud, noting in its State of the Underground report that compromising telecom infrastructure or personnel lets attackers reassign phone numbers and bypass multi-factor authentication, per the firm’s SIM swapping breakdown.

Why Jungkook Made the Perfect Mark

Jungkook checked every box the syndicate looked for. Wealthy. Recognizable. Out of the loop.

Jungkook was reported to have had his securities account identity stolen in January 2024, shortly after entering the military, with 33,500 shares of HYBE stock worth approximately 8.4 billion won taken. The group transferred 33,500 HYBE shares into accounts they controlled.

The hacker took away shares from the singer’s account and sold a portion to a third party. Jeon allegedly sold about 100 million won (approx. 73,000 USD) worth of stocks under Jungkook’s name to a third party, and Jungkook later recovered the funds through a civil lawsuit in March 2024.

Investigators also found that Jeon used the names of a top-30 chaebol leader, a venture company CEO, and others to commit further crimes. Both names remain redacted in court filings. “The suspect admits to some of the allegations while denying others,” police said during a press briefing after his August 2025 detention hearing.

The hackers were also particularly looking for known figures who are currently serving in the military or incarcerated, to take advantage of their absence. The Seoul Metropolitan Police Agency framed the case’s stakes during a briefing reported by Yonhap News Agency.

“As this case has very large social repercussions, we will conduct a strict investigation with not a shred of doubt.”

SIM Cloning Is Outpacing Carrier Defenses Worldwide

The Jungkook case lands inside a global spike. In 2024, the FBI’s Internet Crime Complaint Center (IC3) received 982 complaints related specifically to SIM swapping attacks, with total reported losses exceeding $26 million, according to VikingCloud’s IC3 data analysis. While this represents a slight dip from the peak of $68 million in 2021, experts say attackers are becoming more selective, targeting victims with higher-value digital assets like cryptocurrency and brokerage accounts.

In a separate US case, attackers used SIM swaps to steal $400 million in cryptocurrency from 50 victims, including one company.

Federal cybersecurity agencies have moved against the underlying weakness. CISA put it plainly: “Do not use SMS as a second factor for authentication.” Organizations must also remain compliant with evolving regulations, such as the FCC’s new rules designed to combat SIM swapping.

Group-IB’s 2026 SIM swap evolution analysis frames the wider shift bluntly. The High-Tech Crime Trends Report 2026 reveals how this shift has industrialized cybercrime, exposed the limits of perimeter-based defenses, and elevated identity and trust as the new primary attack surfaces.

Korea’s case shows the wall buckles when the gate is automated. Cheap MVNO portals built for convenience let the syndicate impersonate 89 people without ever speaking to a human.

Inside the 18-Member Syndicate Now in Custody

With both leaders and the other 16 members now under governmental custody, the Ministry of Justice has confirmed the end to this specific transnational fraud. The Seoul Metropolitan Police plan to apply for an arrest warrant for the 40-year-old after an intensive investigation.

Korea JoongAng Daily reported the ring was headed by two individuals attending the same university, who orchestrated the acts from their bases in China and Thailand. A judge at the Seoul Central District Court issued the original arrest warrant on Jeon on charges of violating the Information and Communications Network Act and the Act on the Aggravated Punishment of Specific Economic Crimes, and his trial will keep Korea-Thailand cooperation in play through at least 2026.

Jungkook avoided personal loss. The next 257 names on the list mostly did not. Whether Korean prosecutors can recover the won that already crossed into crypto wallets, and whether MVNO regulators close the SIM activation loophole before the next syndicate spins up, are the only questions still open.

Logan Pierce is a writer and web publisher with over seven years of experience covering consumer technology. He has published work on independent tech blogs and freelance bylines covering Android devices, privacy focused software, and budget gadgets. Logan founded Oton Technology to publish clear, no nonsense tech news and reviews based on real hands on testing. He has personally tested and reviewed dozens of mid range and budget Android phones, written extensively about app privacy, and built and managed multiple WordPress publications over the past decade. Logan holds a bachelor's degree in English and studied digital marketing at a certificate level.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending