Financial Integrity Monitor

South Korea KR

Domains (D1–D6)
4
Sources
13
Role actions
8
Horizon <90d
1
Jurisdiction profile
Largely CompliantTier ARisk: IncreasingMixed

AML/CFT governed by the Act on Reporting and Use of Certain Financial Transaction Information (amended 2021 to cover VASPs) and the 2023 Virtual Asset User Protection Act, with KoFIU as FIU and FSC/FSS as prudential and VASP supervisors.

MoreA won-backed stablecoin framework (Digital Asset Basic Act) is stalled amid FSC-Bank of Korea disagreement over bank-only vs. tech-firm issuance, leaving a regulatory gap in a market larger than domestic equities trading.

Key deficiencies
  • Beneficial ownership, PEP and correspondent-banking measures remain unresolved since the original mutual evaluation
  • Low level of sanctions actually applied by supervisory authorities for AML/CFT breaches despite adequate legal powers
  • No centralized public beneficial ownership registry; UBO identification remains CDD/FI-held rather than centrally verifiable
  • Repeated internal-control failures at licensed VASPs (unreported counterparty transactions, CDD/STR lapses, operational error at scale)
  • Stablecoin and non-bank digital-asset issuance left in regulatory limbo pending stalled legislation
Recent developments (18m)
  • FSC suspended Dunamu/Upbit new-customer virtual-asset transfers for three months (Mar-Jun 2025) over unreported-VASP transactions, CDD and STR violations
  • FATF October 2024/2025 follow-up re-rated Korea's Recommendation 8 to largely compliant, leaving 13 compliant / 20 largely compliant / 7 partially compliant
  • Upbit suffered a ~$30-36m Solana-based exploit (Nov 27, 2025), one day after unveiling Naver's $10.3bn acquisition of parent Dunamu
  • Bithumb erroneously transferred ~$40bn in 'ghost bitcoin' to 695 users (Feb 2026), triggering an FSC industry-wide task force
  • US, Japan and South Korea issued a joint statement (Aug 2025) pledging intensified action against DPRK overseas IT-worker networks
  • FSC/FIU proposed bulk cross-border VASP transaction reporting (transactions >KRW 10m) to close cross-border intelligence gaps (Mar 2025 proposal)
  • Digital Asset Basic Act (won-stablecoin bill) stalled in the National Assembly into 2026 amid FSC-BOK dispute over issuer eligibility
  • Bank of Korea publicly urged limiting stablecoin issuance to licensed banks, citing money-laundering and stability risk (Feb 2026)
Weekly brief

Lead signal

Lead Signal

Read full brief

Lead Signal

South Korea's cycle is dominated by a two-front crisis at Bithumb that has become the clearest illustration yet of a persistent AML/KYC and operational-control gap across the country's largest virtual-asset service providers. Regulators found approximately 6.65 million alleged AML violations at the exchange, comprising 3.55 million identity-verification failures and 3.04 million transaction-blocking failures, and imposed a six-month partial business suspension that a Korean court subsequently overturned on appeal, leaving the status of an associated $24.6 million fine unresolved. Separately, a $40 billion 'ghost bitcoin' mis-crediting incident in February 2026 prompted the Financial Supervisory Service to commit to deploying AI-based real-time trading-surveillance tools, introducing punitive fines for IT incidents, and increasing executive security accountability. Read together, these two episodes point to a structural rather than episodic weakness: Korea's largest exchanges have now been sanctioned within an eighteen-month window, evidencing systemic gaps in KYC and transaction-monitoring controls rather than isolated compliance failures, even as the court's reversal of the Bithumb suspension introduces genuine near-term uncertainty about how enforcement outcomes will actually resolve.

Other Developments

Sanctions-adjacent domestic mechanism strengthens. The amended Terrorist Financing Act, effective 22 January 2026, criminalises transacting with persons on the Financial Services Commission's prohibited list without prior approval, exposing violators to up to three years' imprisonment or a KRW30 million fine. This functions as a domestic targeted-financial-sanctions-adjacent mechanism sitting alongside Korea's core AML architecture, tightening the designation-enforcement toolkit available to authorities.

Governance reform leaves beneficial-ownership gap unresolved. The 2026 Commercial Act amendments, promulgated 6 March 2026, represent the most consequential overhaul of Korean corporate governance since the post-Asian-financial-crisis reforms of 1998-1999, introducing a 3% voting cap and mandatory treasury-share cancellation. The reform, however, leaves entirely unaddressed the absence of any disclosure obligation regarding the ultimate beneficial owner of publicly traded companies, a gap that persists despite the otherwise material strengthening of governance disclosure.

Pattern across Korea's largest exchanges. Dunamu, operator of Upbit, received a three-month partial suspension and a KRW35.2 billion fine in 2025 for compliance gaps, a sanction that now reads as part of an escalating pattern of FIU enforcement against Korea's largest virtual-asset platforms rather than a standalone event, reinforcing the assessment that Bithumb's violations reflect a sector-wide rather than firm-specific control deficiency.

Cross-Monitor Connections

The Bithumb operational-control failure surfaces directly in World Payments Monitor's operational-resilience tracking, where the same ghost-bitcoin incident is read as an asset-matching and account-segregation control weakness in payment-adjacent digital-asset infrastructure. The amended Terrorist Financing Act's criminalisation of unauthorised dealing with FSC-prohibited persons is a shared data point with the Advennt gambling monitor, where the same statute is read as tightening payment-flow due diligence for gambling-adjacent intermediaries — the same primary legislation, two different operator-facing lenses. On the digital-asset side, the unresolved Bank of Korea/Financial Services Commission dispute over stablecoin-issuer ownership, tracked in depth by the crypto monitor, is the structural constraint delaying the Digital Asset Basic Act that would otherwise establish a comprehensive licensing perimeter for the crypto-asset activity generating this cycle's AML findings.

Outlook

The Digital Asset Basic Act remains the single most consequential item on Korea's financial-integrity horizon, targeted for the second half of 2026 but contingent on resolving the stablecoin-issuer ownership dispute between the Bank of Korea and the Financial Services Commission that remained unresolved as of April 2026; its passage would establish a licensing and AML perimeter for crypto-asset issuance, custody, and stablecoin issuance not currently codified in a single statute. Watch also whether the Bithumb fine is ultimately upheld following the suspension reversal, and whether the FSS's committed AI-monitoring and punitive IT-incident-fine regime materialises in a form that measurably reduces the recurrence of exchange-level control failures.

weekly_brief_draft · JID KR
Domain intelligence (D1–D6)

D1 Sanctions Architecture and Evasion

Sanctions Architecture and Evasion

Continue reading

South Korea's sanctions-adjacent architecture saw one concrete development this cycle: the amended Terrorist Financing Act, effective 22 January 2026, which criminalises transacting with a person on the Financial Services Commission's financial-transaction-prohibited list without prior FSC approval, punishable by up to three years' imprisonment or a KRW30 million fine. The provision does not itself constitute an international sanctions-listing mechanism, but it functions as a domestic targeted-financial-sanctions-adjacent tool that strengthens the designation-enforcement toolkit available to Korean authorities, closing a gap in how unauthorised dealing with prohibited persons is punished. No international sanctions are currently in force against South Korea. Architecturally, the amendment is significant less for its scale than for what it signals: Korea is willing to attach direct criminal liability, rather than purely administrative consequence, to unauthorised dealing with designated persons, a posture that raises the compliance stakes for financial institutions and cross-sector obliged entities operating in or transacting with the Korean market. The absence of any parallel enforcement action taken under the new provision this cycle should not be read as evidence the mechanism lacks force; rather, given its 22 January 2026 effective date, this cycle simply predates any reportable application.

Outlook

Watch for enforcement actions actually brought under the amended TFA in coming cycles, which would test how the new criminal-liability provision operates in practice; none had been reported as of this cycle's substrate. The TFA amendment is worth tracking as a leading indicator of how aggressively Korea will pursue designation-adjacent violations going forward.

D2 Beneficial Ownership and Corporate Transparency

Beneficial Ownership and Corporate Transparency

Continue reading

For South Korea, a non-EEA jurisdiction, the directly relevant beneficial-ownership development this cycle is domestic: the 2026 Commercial Act amendments, promulgated 6 March 2026, deliver the most consequential overhaul of Korean corporate governance since the post-Asian-financial-crisis reforms of 1998-1999, introducing a 3% voting cap for audit-committee elections and mandatory treasury-share cancellation. Materially, however, the reform leaves entirely unaddressed the absence of any disclosure obligation regarding the ultimate beneficial owner of publicly traded companies; such disclosure remains required only in certain regulated industries such as financial institutions. This is a governance-quality improvement that does not close Korea's structural beneficial-ownership transparency gap for listed issuers — the reform strengthens minority-shareholder protection and disclosure generally without adding a UBO registry requirement, leaving this specific transparency risk materially unresolved despite the headline overhaul.

Globally, the EU AML Package sets the structural direction for beneficial-ownership supervision: the AML Regulation (Reg (EU) 2024/1624, directly applicable), the sixth AML Directive transposed per Member State, and the AMLA Regulation (Reg (EU) 2024/1620) establishing the Anti-Money Laundering Authority together shift supervision from purely national authorities toward a hybrid EU-level regime. South Korea sits outside this perimeter entirely — it is not an EEA member state and no 6AMLD transposition tracking applies to it — so the EU architecture is durable global backdrop rather than a directly applicable framework for Korean issuers. No AMLA horizon anchor specific to Korea was identified this cycle, so this architecture is stated here as standing structural context rather than as a Korea-specific development.

Outlook

Korea's beneficial-ownership registry gap for listed issuers remains the domain's structural watch item: absent a dedicated UBO disclosure requirement for public companies, the gap identified this cycle persists unaddressed by the 2026 Commercial Act reform. Watch for any follow-on regulatory or legislative proposal specifically targeting listed-issuer UBO disclosure, which has not yet been signalled in the current reform pipeline.

D3 Enabler Jurisdictions

Not covered

Enabler Jurisdictions is not yet covered for this jurisdiction in this report.

D4 Conflict Finance

Not covered

Conflict Finance is not yet covered for this jurisdiction in this report.

D5 Crypto / Digital Assets / Financial Innovation

Crypto, Digital Assets, and Financial Innovation

Continue reading

Bithumb sits at the centre of this cycle's crypto-integrity picture. Regulators found approximately 6.65 million alleged AML violations at the exchange — 3.55 million identity-verification failures and 3.04 million transaction-blocking failures — and imposed a six-month partial business suspension, which a Korean court subsequently overturned on appeal; the status of an associated $24.6 million fine remains unclear following the ruling. Separately, a $40 billion 'ghost bitcoin' mis-crediting incident in February 2026 prompted the Financial Supervisory Service to commit to deploying AI-based real-time trading-surveillance tools, introducing punitive fines for IT incidents, and increasing executive security accountability — a direct supervisory response to a documented control failure rather than a generic policy initiative. These two episodes at the same firm, arriving within months of each other, point toward a systemic rather than isolated compliance and operational-control deficiency.

That reading is reinforced by the wider sector pattern: Dunamu, operator of Upbit, received a three-month partial suspension and a KRW35.2 billion fine in 2025 for compliance gaps, meaning three of Korea's largest exchanges have now been sanctioned within an eighteen-month window. The Bithumb court reversal, however, introduces genuine near-term uncertainty about how enforcement outcomes ultimately resolve — a sanctioned firm winning a suspension reversal on appeal complicates any straightforward narrative of escalating and effective enforcement, even as the underlying violation-finding volume remains substantial.

Outlook

Watch whether the $24.6 million Bithumb fine is upheld or further contested following the suspension reversal, and whether the FSS's committed AI-surveillance and punitive IT-incident-fine framework is formalised and actually deployed. The passage of the Digital Asset Basic Act, targeted for the second half of 2026 but contingent on resolving the Bank of Korea/Financial Services Commission dispute over stablecoin-issuer ownership, would be the structural development most likely to reshape this domain's supervisory architecture going forward.

D6 Compliance Technology and Active Defence

Compliance Technology and Active Defence

Continue reading

The Bithumb $40 billion 'ghost bitcoin' mis-crediting incident in February 2026 is this cycle's defining compliance-technology signal. In direct response, the Financial Supervisory Service committed to investigating high-risk practices, deploying AI tools to detect suspicious trading in real time, introducing punitive fines for IT incidents, and increasing executive security accountability. This is a high-confidence, cross-pillar finding that marks a shift toward proactive, technology-driven supervisory expectations directly triggered by a documented control failure rather than a pre-planned policy rollout — the incident itself is the origin of the reform commitment, not an independent regulatory initiative.

Outlook

The domain's key open question is implementation: whether the FSS's AI real-time monitoring commitment and punitive IT-incident-fine framework are formalised into binding rules, and on what timeline, following what is currently a post-incident commitment rather than an enacted regime. Watch for the FSS's own account of high-risk-practice findings from its planned investigation, which would be the first concrete test of whether the committed active-defence measures translate into enforcement capability.

D7 AML/CTF Regime

Not covered

AML/CTF Regime is not yet covered for this jurisdiction in this report.

Regulatory horizon
Consultation2026-Q4 · ±half_year

Digital Asset Basic Act (DABA)

Would establish a licensing/AML perimeter for crypto-asset issuance, custody and stablecoin issuance not currently codified in a single statute.
1 dated · 4 pending date · baseline financial-integrity-2026-07-05
Role action cards
MLROHigh

Bithumb's ~6.65 million alleged AML/KYC violations and a wider exchange-sanction pattern define this cycle's Korean crypto-sector exposure.

Three of Korea's largest exchanges have now been sanctioned within an eighteen-month window, which MLROs should read as a systemic KYC/transaction-monitoring control gap rather than a firm-specific event, even though Bithumb's own suspension was subsequently overturned on appeal.

3 evidence refs
ComplianceAssessed

Korea's 2026 Commercial Act reform strengthens governance disclosure but leaves the listed-issuer beneficial-ownership gap unresolved.

Compliance functions monitoring Korean corporate counterparties should treat the governance overhaul as a disclosure-quality improvement, not a beneficial-ownership transparency fix; the same crypto-exchange AML violation pattern flagged for MLRO is also a control-framework adequacy signal for compliance.

2 evidence refs
LegalAssessed

A Korean court overturned Bithumb's six-month AML-related business suspension, leaving an associated fine's status unresolved.

Legal counsel should treat the enforcement outcome as unsettled pending clarification of the fine's status, and should not assume the underlying AML violation findings themselves were disturbed by the suspension reversal.

1 evidence refs
BoardHigh

A dual Bithumb crisis — AML violations and a $40 billion ghost-bitcoin mis-crediting incident — is this cycle's material financial-crime and operational risk in Korea.

The board-level signal is that Korea's largest exchanges face compounding AML and operational-control exposure simultaneously, which the FSS has answered with a committed but not-yet-formalised AI-surveillance and punitive-fine regime.

2 evidence refs
CTOHigh

The FSS has committed to deploying AI-based real-time trading-surveillance tools following Bithumb's ghost-bitcoin incident.

Technology functions should anticipate a shift toward proactive, technology-driven supervisory expectations in Korea, including punitive IT-incident fines, even though the framework's binding form and timeline are not yet settled.

1 evidence refs
RiskAssessed

Escalating FIU enforcement against Korea's largest exchanges signals a persistent, sector-wide AML/KYC control gap.

Risk functions should read the Bithumb and Dunamu/Upbit sanctions as concentration-relevant: exposure concentrated in Korea's largest virtual-asset platforms carries elevated AML-control risk regardless of individual-firm litigation outcomes.

2 evidence refs
OperationsAssessed

The amended Terrorist Financing Act criminalises unauthorised dealing with FSC-prohibited-list persons, effective 22 January 2026.

Operations teams screening counterparties with Korean exposure should confirm screening processes capture the FSC's prohibited-persons list given the new criminal-liability exposure for unauthorised dealing.

1 evidence refs
AuditPossible

The 2026 Commercial Act reform materially changes Korean listed-issuer governance controls without adding UBO disclosure.

Audit should note that documented governance controls for Korean listed counterparties will reflect new treasury-share and voting-cap rules, but that beneficial-ownership documentation gaps for such issuers remain unaddressed by this reform.

1 evidence refs
Decision lens
MLRO

Bithumb's ~6.65 million alleged AML/KYC violations and a wider exchange-sanction pattern define this cycle's Korean crypto-sector exposure.

Compliance

Korea's 2026 Commercial Act reform strengthens governance disclosure but leaves the listed-issuer beneficial-ownership gap unresolved.

Legal

A Korean court overturned Bithumb's six-month AML-related business suspension, leaving an associated fine's status unresolved.

Board

A dual Bithumb crisis — AML violations and a $40 billion ghost-bitcoin mis-crediting incident — is this cycle's material financial-crime and operational risk in Korea.

CTO

The FSS has committed to deploying AI-based real-time trading-surveillance tools following Bithumb's ghost-bitcoin incident.

Risk

Escalating FIU enforcement against Korea's largest exchanges signals a persistent, sector-wide AML/KYC control gap.

Operations

The amended Terrorist Financing Act criminalises unauthorised dealing with FSC-prohibited-list persons, effective 22 January 2026.

Audit

The 2026 Commercial Act reform materially changes Korean listed-issuer governance controls without adding UBO disclosure.

Shared evidence: 5 refs
Scenario sketches

AMLA direct/indirect supervision transition and cross-border obliged entities

As the AMLA Regulation (Reg (EU) 2024/1620) transitions supervisory authority for a subset of cross-border obliged entities from purely national authorities toward direct or indirect AMLA oversight, alongside the directly-applicable AMLR (Reg 2024/1624) and per-state 6AMLD transposition, the practical evasion landscape could shift toward jurisdictions and entity types that remain furthest from the new EU-level supervisory perimeter. This is an illustrative structural sketch of the transition, not an observed development, and it is not specific to South Korea's own AML architecture, which sits outside the EU perimeter entirely.

Illustrative scenario for analytical orientation only. Not compliance advice, not a prediction, and not a statement of observed fact.

Standing trackers (T1–T6)
TrackerStatusNote
T1 · Russian Sanctions-Evasion Architectureno_changeNo material KR-specific Russian sanctions-evasion architecture development surfaced this cycle.
T2 · EU AML Package / AMLAno_changeNot applicable this cycle — KR is outside the EEA/AMLR/6AMLD/AMLA supervisory perimeter.
T3 · FATF Grey Listno_changeThe FATF grey list contained 23 jurisdictions under increased monitoring as of the February 2026 plenary; Korea is not on the grey or black list this cycle.
T4 · Beneficial-Ownership Register StatusworseningKorea has no disclosure obligation regarding the ultimate beneficial owner of publicly traded companies; the 2026 Commercial Act governance reform did not add a UBO registry requirement despite otherwise materially strengthening disclosure obligations.
T5 · Crypto & Digital-Asset IntegrityescalatingBithumb's ~6.65m AML/KYC violation finding, a subsequently overturned six-month suspension, and a separate $40bn 'ghost bitcoin' mis-crediting incident prompting FSS AI-surveillance commitments together constitute the cycle's dominant crypto-integrity development for KR.
T6 · Sanctions Regime Divergenceno_changeNo KR-specific EU/US/UK autonomous-listing divergence signal surfaced this cycle.
Registers

Enforcement actions

  • FSC suspended new-customer virtual asset transfers at Dunamu for three months after finding the firm transacted with unreported virtual asset operators and violated customer verification and suspicious-transaction-report obligations. 25 Feb 2025
  • The three governments issued a joint statement pledging to intensify disruption of North Korea's use of overseas IT workers who obscure their identities to win contracts and funnel earnings to weapons programs. 28 Aug 2025
  • FSC and KoFIU proposed amendments requiring all regulated VASPs to report cross-border transactions over KRW 10 million involving overseas counterparties, moving beyond suspicion-based SAR filing to bulk cross-border transaction reporting. 1 Mar 2025
  • FSC formed an industry-wide task force after Bithumb erroneously credited 620,000 Bitcoin (~$40bn) to 695 users during a promotional payout, mistakenly inputting Bitcoin instead of won, triggering a brief sell-off and parliamentary hearings. 9 Feb 2026

Sanctions changes

  • OFAC designated Russian national Vitaliy Andreyev, DPRK official Kim Ung Sun, and entities Shenyang Geumpungri Network Technology and Korea Sinjin Trading Corporation for funneling DPRK IT-worker revenue tied to Chinyong, an entity originally co-designated by OFAC and South Korea's MOFA in May 2023. 27 Aug 2025
  • OFAC designated six individuals and two entities, including Amnokgang Technology Development Company and a Vietnam-based facilitator, and listed 21 cryptocurrency addresses across multiple blockchains tied to DPRK IT-worker schemes generating nearly $800m in 2024. 12 Mar 2026
  • The European Commission added Russia to its high-risk third-country list under Delegated Regulation (EU) 2026/46 (4 December 2025), requiring enhanced vigilance by EU obliged entities on Russia-linked transactions. 4 Dec 2025

Regulatory horizon (register)

  • Digital Asset Basic Act (won-stablecoin framework) passage
  • Bulk cross-border VASP transaction reporting rule effective
  • Korea's next FATF mutual evaluation (5th round)
  • Basel Committee crypto-exposure prudential rule reassessment

Active schemes

  • [CRITICAL] DPRK IT-worker crypto revenue-to-WMD pipeline
  • [CRITICAL] Lazarus Group hack-to-launder pipeline via Korean exchanges
  • Won-stablecoin regulatory vacuum ahead of Digital Asset Basic Act
  • Semiconductor trans-shipment risk in Russia-evasion supply chains
Sources
  1. FATF
  2. FATF/APG
  3. FATF
  4. US Department of the Treasury (OFAC)
  5. European Commission (DG FISMA)
  6. Bloomberg
  7. Bloomberg
  8. Bloomberg
  9. Chainalysis
  10. Elliptic
  11. Bloomberg
  12. Elliptic
  13. UNODC
Coverage gaps
Korea operates without a centralized public beneficial owner…
Korea operates without a centralized public beneficial ownership registry; UBO identification remains dependent on financial-institution CDD records rather than a verifiable central register, and FATF continues to flag PEP and correspondent-banking measures as unresolved since the original mutual evaluation.
Repeated internal-control failures at licensed VASPs -- Duna…
Repeated internal-control failures at licensed VASPs -- Dunamu/Upbit's unreported-counterparty and CDD/STR violations (2025) and Bithumb's $40bn erroneous bulk transfer (2026) -- show that licensing under the Virtual Asset User Protection Act has not yet translated into robust operational-risk and AML control maturity.
Legislative deadlock between the FSC and Bank of Korea over …
Legislative deadlock between the FSC and Bank of Korea over bank-only versus non-bank stablecoin issuance has stalled the Digital Asset Basic Act, leaving won-backed stablecoin pilots (KRW1, cross-border remittance projects) to advance without a finalized statutory AML/CFT and reserve framework.
Publicly available English-language reporting on Korea's cur…
Publicly available English-language reporting on Korea's current operational beneficial-ownership data quality (as opposed to legal framework) is thin outside of FATF's own generic synopsis; no recent ICIJ/OCCRP-style forensic BO investigation specific to Korea was located within the 18-month window.

Evidence

Confidence-tiered claims

No structured claims published for this jurisdiction yet.