On May 13, 2026, it was reported that Jungkook, a member of the globally popular K-pop group BTS, was targeted in a massive cybercrime operation. This hacking attempt was linked to an international cybercrime ring focused on identity theft and attempted financial fraud. According to the authorities, the hacking operation was a coordinated effort by a Chinese cybercrime group that attempted to steal large amounts of money from prominent South Korean public figures, including Jungkook.

The primary figure behind the hacking ring was identified only as A, a Chinese national in his 40s. This individual was apprehended and extradited from Thailand to South Korea on May 12, following a thorough investigation by South Korea’s Ministry of Justice and National Police Agency. The investigation revealed that A operated a sophisticated hacking ring that was based in Bangkok, Thailand. Between August 2023 and April 2024, the group allegedly breached six government and public institution websites to obtain personal information from their victims. Using this stolen data, they were able to create fraudulent mobile phone accounts under the names of their victims. The hackers bypassed identity verification systems, which allowed them to gain unauthorized access to various financial accounts, including cryptocurrency platforms.

The full scale of the operation was shocking. Authorities estimate the attempted damages to be approximately 38 billion won, or about $27 million USD. The operation’s scope extended to high-profile individuals, including wealthy South Korean business executives and conglomerate leaders. Among the most alarming discoveries was the fact that Jungkook had been directly targeted shortly after beginning his mandatory military service. The hackers attempted to transfer around 8.4 billion won (approximately $6.1 million USD) in HYBE shares from accounts registered under Jungkook’s name.
Fortunately, financial institutions detected suspicious activity and froze the transactions before any financial loss occurred. Investigators have credited the swift actions of these institutions with preventing a potential disaster. Authorities also disclosed that the hackers had used similar tactics to target other high-profile individuals, including South Korean business leaders, further highlighting the breadth and complexity of the cybercrime ring.

The investigation into the criminal syndicate is ongoing, with South Korean authorities continuing to probe the financial networks of the hacking group and identify additional accomplices involved in the operation. The full scope of their actions is still under investigation, and further arrests and discoveries are expected.
This cybercrime attempt serves as a chilling reminder of the increasing sophistication of global cybercrime rings and the vulnerabilities individuals face in the digital age. The authorities’ quick response prevented what could have been a major financial scandal, but it also underscores the ongoing need for robust cybersecurity measures to protect sensitive personal information.