top of page
fnlogo.png

South Korean Police Refer Eight People to Prosecutors in Gmarket Payment Fraud and Money Laundering Case

  • 4 hours ago
  • 5 min read

South Korean police have referred eight people to prosecutors in connection with a payment fraud case involving Gmarket customer accounts, alleging that the individuals helped launder criminal proceeds by providing bank accounts used to receive and move funds generated through unauthorised transactions. Investigators have yet to identify the hacker believed to have organised the original scheme and are continuing to trace the movement of the proceeds.


South Korean Police Refer Eight People to Prosecutors in Gmarket Payment Fraud and Money Laundering Case

The case relates to unauthorised payments made through Gmarket accounts on November 28 and 29, 2025. Online gift certificates and other products were purchased after gaining access to customers' accounts without their authorisation. At the time, approximately 60 Gmarket customers were initially identified as having suffered losses ranging from 30,000 won to 200,000 won each. Police subsequently received reports from 45 victims, with the total reported losses reaching approximately 9.6 million won.


The investigation later expanded beyond the unauthorised payments themselves after police began tracing the financial flows generated by the fraud. Investigators identified a group of individuals suspected of helping move the proceeds by making their bank accounts available to others. Eight people, including an individual identified as "A", were referred to prosecutors without detention in late May on suspicion of violating South Korea's Act on Real Name Financial Transactions and Confidentiality.


According to investigators, the individuals admitted providing access to their accounts after being asked by acquaintances. Although they claimed they had simply lent their accounts, police suspect that the accounts were subsequently used as part of the process for moving or concealing money generated by the fraudulent payments.


The use of third-party bank accounts is a common feature of financial fraud schemes because it can create distance between the person responsible for the original offence and the eventual movement of the proceeds. Funds obtained through fraudulent activity can first be transferred into an account belonging to another individual before being moved elsewhere, making it more difficult for investigators to immediately identify the person controlling the money.


Such accounts can also make fraudulent transactions appear to originate from individuals who have no obvious connection to the underlying offence. This creates additional challenges for financial institutions because an account holder may not necessarily be the person who initiated the fraudulent activity or ultimately benefited from it.


The Gmarket investigation demonstrates the importance of following financial flows after a cybercrime has taken place. Identifying unauthorised purchases may establish the initial offence, but tracing where the resulting funds were transferred can help investigators uncover the wider network behind the operation.


Police reportedly identified indications that two additional people may have participated in the criminal activity. However, investigators determined that both individuals had left South Korea, preventing the immediate continuation of proceedings against them. The investigation into those individuals was suspended and they were placed on a wanted list.


The person believed to have led the hacking operation has also not yet been identified. Investigators are continuing to examine the movement of the criminal proceeds and the associated bank accounts in an attempt to establish the identity of the suspected ringleader.


The difficulty in identifying the alleged organiser highlights one of the principal challenges associated with cyber-enabled financial crime. A criminal operation can involve several layers of participants, with one individual responsible for gaining access to customer accounts, others providing bank accounts and additional participants potentially receiving or transferring the funds.


This separation of functions can make it difficult to determine who ultimately controls a scheme. Individuals whose accounts are used to move money may have limited knowledge of the wider operation, while the people directing the fraud can attempt to remain several steps removed from the transactions.


The case also illustrates how cybercrime and money laundering increasingly overlap. The initial offence involved unauthorised access to customer accounts and fraudulent purchases, but the subsequent movement of the resulting funds created a separate financial crime dimension.


For banks and payment providers, identifying the movement of fraudulent proceeds therefore requires monitoring not only for suspicious transactions but also for account behaviour that may indicate the use of an account as a money mule. Accounts that suddenly receive funds inconsistent with the customer's normal activity, followed by rapid transfers or withdrawals, can present important warning signs.


The use of personal accounts belonging to individuals with no apparent commercial reason to receive particular payments can also warrant scrutiny. Where several unrelated accounts are linked through common transaction patterns, financial institutions may be able to identify relationships that are not immediately apparent from individual transactions.


The Gmarket case demonstrates why transaction monitoring systems need to consider patterns rather than isolated payments. A single transfer into a personal account may have a perfectly legitimate explanation. Repeated transfers followed by rapid movement of funds to other accounts, particularly when the activity is inconsistent with the customer's profile, may present a very different risk.


The involvement of online gift certificates is also noteworthy. Digital or easily transferable products can be attractive to fraudsters because they may be purchased quickly and, depending on the circumstances, transferred or converted into value without the same characteristics as conventional retail purchases.


For online marketplaces, this creates a particular security challenge. Platforms need to protect customer accounts against unauthorised access while also monitoring unusual purchasing activity that could indicate compromised credentials or coordinated fraud.


The incident also underlines the broader risks associated with account credentials being reused across different online services. Where criminals obtain usernames and passwords from other sources, they may attempt to use those credentials to access accounts on e-commerce platforms and make fraudulent purchases.


From a compliance perspective, the case demonstrates that cybercrime investigations increasingly require cooperation between technology companies, financial institutions and law enforcement authorities. The initial evidence may originate from an online marketplace, while the most useful information for identifying the perpetrators can subsequently come from banking records and transaction histories.


Cyprus Company Formation

The fact that investigators have continued following the money even after identifying individuals who allegedly provided their accounts demonstrates the importance of tracing proceeds beyond the first recipient. A money laundering network can involve several layers of transfers, and stopping at the first account may leave the principal organiser unidentified.


The case also highlights the risks faced by individuals who allow others to use their bank accounts. Even where an account holder claims not to have known the full purpose of the transactions, providing account access can expose the individual to legal and financial consequences if the account is used to receive or transfer criminal proceeds.


For financial institutions, this reinforces the importance of customer education alongside formal transaction monitoring. Customers should understand that allowing another person to use their account can create significant risks, particularly where they are offered money or another benefit in return.


The investigation remains ongoing, and the person believed to have organised the hacking operation has not yet been identified. The authorities are continuing to analyse account movements and criminal proceeds in an effort to establish the full structure of the operation.


The case ultimately demonstrates how a relatively modest payment fraud can develop into a broader money laundering investigation. Although the reported losses amounted to approximately 9.6 million won, the investigation uncovered a network involving multiple bank accounts and individuals allegedly involved in moving the proceeds.


It also reinforces the growing connection between online fraud, cybercrime and financial crime. Criminals can exploit compromised customer accounts to generate illicit funds, while third parties and financial infrastructure can subsequently be used to move those proceeds and obscure their origin.


As authorities continue searching for the suspected hacker and the individuals who left South Korea, the investigation will likely focus heavily on the financial trail. Establishing where the money went, who controlled the accounts and how the transactions were coordinated could ultimately prove crucial to identifying the individuals responsible for organising the wider scheme.


The case serves as a reminder that financial crime controls must evolve alongside cybercrime. Protecting customers from unauthorised payments is only one part of the challenge; identifying and disrupting the financial networks used to process the resulting proceeds is equally important. Effective cooperation between online platforms, banks and law enforcement agencies will remain essential as fraudsters increasingly combine digital account compromises with traditional money laundering techniques.

By fLEXI tEAM

Comments


bottom of page