A Seoul court has handed down a 20-year prison sentence to a Chinese national who led an international hacking ring responsible for stealing or attempting to steal roughly 38 billion won, equivalent to approximately 25 to 28 million US dollars, from high-value targets across South Korea. Among the most striking targets was BTS member Jungkook, whose brokerage account was attacked while he was completing mandatory military service, with hackers attempting to transfer around 33,500 HYBE shares valued at approximately 8.4 billion won. The case has sent shockwaves through cybersecurity and entertainment circles alike, exposing how organized criminals weaponize identity data and telecom vulnerabilities to raid even the most prominent financial accounts.

Key Facts

  • A Seoul court sentenced a Chinese national to 20 years in prison for leading a hacking ring that stole or attempted to steal approximately 38 billion won (roughly USD 25 to 28 million) from wealthy South Korean targets, according to multiple court and media reports.
  • BTS member Jungkook was among the victims: attackers allegedly attempted to transfer approximately 33,500 HYBE shares, worth around 8.4 billion won, out of his securities account while he was serving in the South Korean military.
  • The ring breached government, telecom, and financial systems to harvest personal data, then fraudulently activated mobile lines in victims' names to take over brokerage accounts, according to South Korean authorities.
  • Assets were moved through layered accounts and cryptocurrency outlets, enabling rapid cross-border cashout designed to frustrate investigators, per reporting by the BBC and Anadolu Agency.
  • The sentencing, reported in May 2026, represents one of South Korea's most severe cybercrime punishments and underscores growing alarm about organized hacking rings targeting high-net-worth individuals.

How the Chinese Hacker Ring Operated

According to reporting by the BBC and Anadolu Agency, the operation was methodical and multi-layered. The group began by breaching websites operated by government agencies, telecoms, and financial institutions to harvest sensitive personal identification data. That stolen information then became the foundation for a chain of crimes that moved from the digital to the financial world with alarming speed.

With victim identity data in hand, the hackers fraudulently opened or reactivated mobile phone lines in those victims' names. This gave them effective control over phone numbers, allowing them to intercept one-time passwords and two-factor authentication codes sent by brokerages and banks. Once they controlled a victim's number, gaining access to their financial accounts was a straightforward next step.

SIM Takeover to Brokerage Raid: The Attack Chain

The technical chain of compromise followed a clear sequence. First, personal data was harvested through website intrusions. Second, fraudulent mobile activations handed the attackers SIM-level control. Third, that control was used to reset or bypass authentication on securities accounts at brokerages. Finally, shares and funds were rapidly moved through multiple layered accounts and converted through cryptocurrency outlets to obscure the trail and facilitate cross-border cashout.

This approach exploited a well-known weakness: many financial institutions still rely on SMS-based two-factor authentication, which becomes worthless once an attacker controls the phone number. The case is a textbook example of why security experts have long urged a move away from SMS-based verification toward hardware tokens or authenticator apps.

Jungkook's HYBE Shares Targeted During Military Service

The attempted theft targeting BTS star Jungkook drew particular attention. Authorities say the hackers tried to transfer approximately 33,500 HYBE shares, the entertainment company behind BTS, out of Jungkook's securities account. At the time of the attempted theft, the shares were valued at around 8.4 billion won. Jungkook was completing his mandatory South Korean military service when the attack occurred, a period during which close monitoring of personal financial accounts would naturally be more difficult.

The attackers reportedly targeted other wealthy individuals as well, selecting victims based on the value of assets held in their brokerage accounts. Jungkook's case became the most high-profile example, but investigators uncovered a broader list of targets whose accounts were accessed or compromised through the same SIM-takeover and account-hijacking methods.

Why High-Profile Celebrities Are Prime Targets

Celebrities like Jungkook hold substantial financial assets and often receive significant stock allocations from affiliated entertainment companies, making them attractive marks for financially motivated hackers. Their public profiles also make it easier for bad actors to gather background information useful in social engineering or identity theft. This pattern is not limited to South Korea. Across the globe, celebrity identities are being exploited in a range of financial crimes, from brokerage account raids to elaborate impersonation schemes. For context on how criminals exploit Korean celebrity identities in other ways, the Kim Seon Ho deepfake impersonation scam shows how digital fraud can be built entirely around a star's public image.

The Scale of the Operation and the Sentencing

The total scope of the criminal ring's activity reached approximately 38 billion won in stolen or attempted theft, a figure that reflects both the ambition and the organization behind the group. South Korean prosecutors pursued the case aggressively, and the 20-year sentence handed down by the Seoul court is regarded as one of the country's most severe cybercrime punishments.

The case involved international coordination, including extradition proceedings, and drew attention to the challenge of prosecuting cybercriminals who operate across borders. Investigators had to forensically trace sold shares, follow cryptocurrency transactions through multiple wallets and exchanges, and build a chain of evidence linking the hacking activity to specific individuals within the ring.

Broader Implications for Telecom and Brokerage Security

This case highlights a systemic vulnerability that affects financial systems worldwide. Telecom operators remain a weak link when criminals can fraudulently activate SIM cards using stolen identity data. Brokerages that rely on SMS-based authentication offer limited protection once that layer is compromised. Regulators in South Korea and elsewhere are expected to scrutinize these gaps more closely following the sentencing. The exploitation of celebrity identities in financial fraud is also a growing concern, as seen in broader reporting on celebrity impersonation scams costing victims billions globally.

How to Protect Yourself From Account Takeover Attacks

The tactics used in this case are not exclusive to South Korea or to celebrities. Anyone with significant assets in a brokerage account is potentially vulnerable to similar attack chains. The following steps can substantially reduce your risk.

  • Switch from SMS-based 2FA to hardware tokens or authenticator apps. SMS codes can be intercepted once a hacker controls your phone number.
  • Set a carrier PIN or account lock with your mobile provider. This adds a barrier against fraudulent SIM activations in your name.
  • Monitor your brokerage and bank accounts regularly for unauthorized transfers, logins from unfamiliar devices, or changes to contact details.
  • Alert your broker immediately if you lose mobile service unexpectedly, as this can be an early sign of a SIM takeover in progress.
  • Consider a credit freeze with major bureaus to limit the ability of criminals to open accounts using your identity.

If you believe you have been a victim of a similar scheme, you can report it to the FTC's fraud reporting portal or submit a complaint to the FBI's Internet Crime Complaint Center (IC3).

Conclusion

The 20-year sentence handed to the ringleader of this Chinese hacker group marks a significant moment in the global fight against cybercrime. The case against the Chinese hacker behind the BTS Jungkook securities hack demonstrates in concrete terms how identity theft, telecom exploitation, and financial fraud can be chained together to steal millions. It is a warning for individuals, brokerages, and telecom operators that SMS-based authentication is no longer sufficient protection for high-value accounts. If you hold significant assets in any brokerage or financial account, now is the time to audit your security settings, upgrade your two-factor authentication, and contact your mobile carrier to lock down your number. Staying informed about emerging cybercrime tactics is the first line of defense.

Frequently Asked Questions

What did the Chinese hacker do to BTS member Jungkook?

According to South Korean authorities, the hacking ring allegedly attempted to transfer approximately 33,500 HYBE shares, valued at around 8.4 billion won, out of Jungkook's securities account. The attack occurred while Jungkook was completing mandatory military service. The hackers reportedly used stolen identity data and fraudulent mobile activations to bypass account security.

How long was the Chinese hacker sentenced to prison?

A Seoul court sentenced the Chinese national who led the hacking ring to 20 years in prison. The sentence is considered one of the most severe cybercrime punishments handed down in South Korea. The ring was responsible for stealing or attempting to steal roughly 38 billion won, approximately 25 to 28 million US dollars, from multiple high-value targets.

How did the hackers gain access to brokerage accounts?

The ring first breached government, telecom, and financial websites to harvest personal identification data. They then used that data to fraudulently activate mobile phone lines in victims' names, giving them control over SMS-based two-factor authentication codes. With those codes, they could reset passwords and access brokerage accounts to move assets.

Why are celebrities targeted in securities and financial hacks?

Celebrities often hold substantial financial assets and may receive significant stock allocations from affiliated companies, making them high-value targets. Their public profiles also make it easier for criminals to gather personal details useful in identity theft or social engineering. Additionally, periods of reduced personal oversight, such as Jungkook's military service, can create windows of opportunity for attackers.

How can I protect my brokerage account from a SIM takeover attack?

The most effective steps include replacing SMS-based two-factor authentication with a hardware token or authenticator app, and setting a PIN or account lock with your mobile carrier to prevent unauthorized SIM changes. You should also monitor your accounts regularly and contact your broker immediately if you unexpectedly lose mobile service. Reporting suspicious activity to the FTC or FBI IC3 is also recommended.