The alleged leader of an international hacking ring that targeted wealthy South Koreans—including BTS member Jungkook—has been sentenced to 20 years in prison after a Seoul court found him guilty of fraud and violations of South Korea’s Information Network Act.
The Seoul Central District Court handed down the sentence on August 20 to the Chinese national, identified by his surname Jeon, over a cybercrime operation that investigators said targeted high-net-worth individuals and used stolen personal information to gain access to financial assets.
According to Yonhap News Agency, the group was linked to the theft of more than ₩38 billion (about US$27 million) in assets. The targets included business executives, entertainers, influencers and cryptocurrency investors.
Jungkook’s ₩8.4-billion HYBE shares were targeted
Jungkook was reportedly among the victims selected by the criminal organization.
Investigators found that hackers attempted to take approximately ₩8.4 billion worth of HYBE shares associated with the BTS star.
However, Jungkook did not ultimately suffer the reported financial loss. His agency detected the suspicious activity and quickly implemented protective measures, including suspending transactions, preventing the attempted theft from becoming an actual loss.
The incident nevertheless revealed how far the group had penetrated victims’ personal and financial information.
How the hacking operation allegedly worked
Investigators said the organization operated from overseas, including Thailand, and collected personal, financial and authentication information from victims.
The group allegedly used stolen information to activate mobile phone lines in the victims’ names. Those unauthorized phone numbers could then be used to obtain authentication codes and gain access to financial accounts and other services.
According to Seoul Economic Daily, investigators uncovered evidence that the organization had accumulated sensitive information—including identification details, account information, phone numbers and financial data—from hundreds of people. The group allegedly used that information to identify wealthy targets and exploit weaknesses in authentication systems.
The operation reportedly targeted 258 people whose personal information had been obtained, with a smaller group selected based on their wealth and ability to respond quickly to suspicious activity.
Among those specifically targeted were corporate chairmen and executives, celebrities, athletes, influencers and cryptocurrency investors.
Court calls crime a threat to the financial system
The Seoul Central District Court described the scheme as particularly serious because victims were allegedly stripped of assets without having done anything to expose themselves to conventional fraud.
The court said the offenders deliberately searched for wealthy individuals and took advantage of them while they were effectively defenseless.
The judge also criticized Jeon’s lack of genuine remorse. The defendant reportedly claimed that another person was the actual mastermind, but investigators were unable to verify the existence of that alleged superior.
The court ultimately concluded that the circumstances did not demonstrate sincere reflection over the crimes.
From Thailand to a Seoul courtroom
The case also involved international law enforcement cooperation.
South Korean authorities worked with Interpol and Thai police to locate Jeon, who was reportedly staying in Thailand. He was arrested there in May 2025 before being repatriated to South Korea in August 2025.
He was subsequently indicted while in custody in September 2025.
The international investigation underscores the increasingly cross-border nature of sophisticated financial cybercrime, where stolen identities, mobile authentication and online financial accounts can be exploited across multiple jurisdictions.
Jungkook case highlights growing risks for celebrities and high-net-worth individuals
The case has drawn particular attention because Jungkook was one of the high-profile individuals targeted.
But investigators said the operation was not simply aimed at celebrities. Its broader strategy was reportedly to identify people with substantial assets and then exploit weaknesses in their digital identities and authentication systems.
The victims included eight company chairmen, CEOs or presidents, one executive, three entertainers or influencers and three cryptocurrency investors, according to Korean reports.
The case therefore extends beyond the BTS connection, exposing a wider cybercrime network allegedly built around identity theft, unauthorized mobile activation and financial-account compromise.
For Jungkook, the immediate financial damage was prevented. But the attempted theft of billions of won worth of assets demonstrates the scale of the threat facing public figures whose financial information can make them attractive targets for organized cybercriminals.
The 20-year prison sentence now marks a major development in the case, although it is only the first-instance ruling and may still be subject to further legal proceedings.

Leave a Reply