Not every instrument is backed by its official text yet. At least one law or rulebook covered here has no official source (tier 1) retrieved for it yet. No finding on this page is shown with confidence above “Probable” until stronger sources are retrieved.

Financial Integrity Monitor

South Korea KR

Domains (D1–D6)
4
Sources
13
Role actions
8
Jurisdiction profile
Largely CompliantTier ARisk: IncreasingMixed

AML/CFT governed by the Act on Reporting and Use of Certain Financial Transaction Information (amended 2021 to cover VASPs) and the 2023 Virtual Asset User Protection Act, with KoFIU as FIU and FSC/FSS as prudential and VASP supervisors.

MoreA won-backed stablecoin framework (Digital Asset Basic Act) is stalled amid FSC-Bank of Korea disagreement over bank-only vs. tech-firm issuance, leaving a regulatory gap in a market larger than domestic equities trading.

Key deficiencies
  • Beneficial ownership, PEP and correspondent-banking measures remain unresolved since the original mutual evaluation
  • Low level of sanctions actually applied by supervisory authorities for AML/CFT breaches despite adequate legal powers
  • No centralized public beneficial ownership registry; UBO identification remains CDD/FI-held rather than centrally verifiable
  • Repeated internal-control failures at licensed VASPs (unreported counterparty transactions, CDD/STR lapses, operational error at scale)
  • Stablecoin and non-bank digital-asset issuance left in regulatory limbo pending stalled legislation
Recent developments (18m)
  • FSC suspended Dunamu/Upbit new-customer virtual-asset transfers for three months (Mar-Jun 2025) over unreported-VASP transactions, CDD and STR violations
  • FATF October 2024/2025 follow-up re-rated Korea's Recommendation 8 to largely compliant, leaving 13 compliant / 20 largely compliant / 7 partially compliant
  • Upbit suffered a ~$30-36m Solana-based exploit (Nov 27, 2025), one day after unveiling Naver's $10.3bn acquisition of parent Dunamu
  • Bithumb erroneously transferred ~$40bn in 'ghost bitcoin' to 695 users (Feb 2026), triggering an FSC industry-wide task force
  • US, Japan and South Korea issued a joint statement (Aug 2025) pledging intensified action against DPRK overseas IT-worker networks
  • FSC/FIU proposed bulk cross-border VASP transaction reporting (transactions >KRW 10m) to close cross-border intelligence gaps (Mar 2025 proposal)
  • Digital Asset Basic Act (won-stablecoin bill) stalled in the National Assembly into 2026 amid FSC-BOK dispute over issuer eligibility
  • Bank of Korea publicly urged limiting stablecoin issuance to licensed banks, citing money-laundering and stability risk (Feb 2026)
Brief

Lead signal

Lead Signal

Read full brief

Lead Signal

South Korea's Financial Intelligence Unit has completed its largest-ever sequential AML enforcement wave against domestic virtual-asset service providers, imposing three separate large fines on Upbit, Korbit and Bithumb between November 2025 and March 2026. Bithumb was fined KRW 36.8 billion, approximately $24.5 million, and given a six-month partial suspension of external transfers for new customers, over approximately 6.65 million AML violations including failed customer identification and 45,772 transfers to 18 unregistered overseas virtual-asset service providers. Dunamu, operator of Upbit, was fined approximately KRW 35.2 billion, around $25 million, for accepting photocopied identification documents, permitting 3.3 million transactions by unverified customers, and failing to report 15 suspicious transactions. Korbit was fined KRW 2.73 billion with an institutional warning for inadequate customer identification, unauthorized transactions with overseas operators, and skipped AML risk assessments on new services including NFTs.

The pattern across all three actions is structurally consistent: domestic exchanges operating under Korea's registration regime under the Act on Reporting and Using Specified Financial Transaction Information nonetheless routed transactions to unregistered overseas virtual-asset service providers, a leakage point at the cross-border counterparty interface that the domestic registration perimeter alone did not close.

Other Developments

A DPRK IT-worker crypto-laundering network was sanctioned by OFAC in March 2026, with cross-cutting relevance to Korean VASP counterparty screening. Six individuals and two entities were designated for laundering approximately $800 million generated through fraudulent DPRK overseas IT-worker employment schemes, funding weapons-of-mass-destruction and ballistic-missile programs. DPRK-backed teams used fraudulent documentation, stolen identities and fabricated personas to gain employment, including at companies in the United States and allied countries. This designation is global in scope but bears directly on the counterparty-screening exposure of any Korean virtual-asset operator transacting with overseas counterparties, given the demonstrated pattern of DPRK actors obscuring their identity within ordinary-looking employment and payment relationships.

The Financial Services Commission is separately hardening technical AML and operational controls following a February 2026 Bithumb payout error. Exchanges are being required to shift from delayed, up to 24-hour, balance checks to real-time reconciliation every five minutes, alongside proposed automated kill-switch and semi-annual inspection requirements. This technical-control reform runs on a parallel track to the AML fines, addressing operational-resilience gaps rather than customer-identification failures directly, though both tracks originate from the same underlying supervisory concern about exchange-level control adequacy.

Cross-Monitor Connections

The crypto monitor's tracking of South Korea's parallel VASP-licensing and cross-border-transfer legislative tightening, including the Foreign Exchange Transactions Act amendment bringing virtual-asset cross-border remittance businesses under a registration duty with criminal penalties, is directly relevant context for the enabler-jurisdiction leakage pattern identified here: a new registration-and-penalty architecture for cross-border virtual-asset transfers is the kind of instrument that could close the exact overseas-VASP leakage this cycle's enforcement wave exposed, once its Presidential Decree detail is finalised. The world-payments monitor's tracking of Korean payment-gateway fund-safeguarding requirements is architecturally adjacent but distinct: that regime addresses merchant-settlement fund protection rather than counterparty AML screening, and the two should not be conflated.

Outlook

Whether the FSC's technical-control reforms, once finalised, measurably reduce the kind of balance-reconciliation and customer-identification failures underlying the Bithumb, Upbit and Korbit fines is the principal item to track. Separately, whether Korea's new cross-border virtual-asset transfer registration duty, once its Presidential Decree is published, functions to close the overseas-unregistered-VASP leakage this cycle's enforcement pattern exposed, or whether that leakage persists despite a nominally tightened domestic perimeter, will determine whether this cycle's enforcement wave represents a point-in-time correction or a structural fix.

weekly_brief_draft · JID KR
Domain intelligence (D1–D6)

D1 Sanctions Architecture and Evasion

Sanctions Architecture and Evasion

Continue reading

In March 2026, OFAC designated six individuals and two entities for laundering approximately $800 million generated through fraudulent DPRK overseas IT-worker employment schemes, with the laundered proceeds funding weapons-of-mass-destruction and ballistic-missile programs. The mechanism documented by Treasury involved DPRK-backed teams using fraudulent documentation, stolen identities and fabricated personas to gain employment with legitimate companies, including companies in the United States and allied countries. This is a Comprehensive sanctions designation under the US sanctions architecture targeting DPRK, distinct from the FATF Call-for-Action classification that also applies to North Korea, and reflects the continued use of employment-based identity fraud as a sanctions-evasion vector for DPRK revenue generation via crypto.

There is no KR-specific sanctions-architecture development this cycle; South Korea itself is not the subject jurisdiction of this designation. However, the case is directly relevant as cross-cutting counterparty-screening context for Korean virtual-asset service providers, since the same employment-fraud and identity-fabrication techniques documented in the OFAC designation are precisely the kind of concealment method that a VASP's counterparty-screening controls are meant to catch, and the designation's timing sits close to this cycle's broader Korean VASP enforcement pattern around overseas-counterparty exposure.

The structural significance for South Korea is indirect but material: as Korean exchanges are shown this cycle to be transacting with unregistered overseas VASPs, the DPRK IT-worker laundering architecture is one of the illicit-finance patterns such overseas counterparty exposure could, in principle, intersect with, even though no claim this cycle directly links the designated entities to a Korean exchange.

Outlook

Whether any of the Korean VASP enforcement actions this cycle, or future ones, identify a direct nexus to DPRK-linked overseas counterparties is the item to track. The structural lesson from the OFAC designation, that employment-based identity fraud is an effective concealment technique, is architecture-level context that should inform how Korean exchanges calibrate screening against seemingly ordinary overseas transaction counterparties going forward.

D2 Beneficial Ownership

Not covered

Beneficial Ownership is not yet covered for this jurisdiction in this report.

D3 Enabler Jurisdictions and Professional Facilitators

Enabler Jurisdictions and Professional Facilitators

Continue reading

South Korea itself sits outside the classic enabler-jurisdiction framing; it operates an established VASP registration regime under the Act on Reporting and Using Specified Financial Transaction Information. What this cycle's enforcement pattern exposes is a different but related structural point: domestically registered, properly licensed Korean exchanges nonetheless transacted with unregistered overseas virtual-asset service providers. Bithumb's enforcement action specifically documented 45,772 transfers to 18 unregistered overseas VASPs, a volume and counterparty count that indicates a structural, not incidental, pattern of flow toward jurisdictions or platforms outside any registration perimeter. Korbit's enforcement action similarly cited unauthorized transactions with overseas operators among its violation grounds.

This is best understood as an enabler-jurisdiction leakage point at the cross-border interface: rather than the enabling jurisdiction being South Korea, the enabling exposure lies in the unregistered overseas VASPs themselves, which operate outside any disclosed registration regime and thereby provide a destination for flows originating in a well-regulated domestic market. The persistence of this pattern despite South Korea's own registration perimeter being in force illustrates the limits of unilateral domestic VASP regulation absent reciprocal registration or counterparty-verification requirements covering the overseas leg of a transaction.

Outlook

Whether Korea's new Foreign Exchange Transactions Act amendment, bringing cross-border virtual-asset transfer businesses under a registration duty with criminal penalties for non-registration, closes this specific leakage once its implementing Presidential Decree is published, is the central item to track. Until that decree is located and its operative thresholds known, it cannot be assessed whether the new registration duty would have prevented transfers of the kind documented in the Bithumb and Korbit enforcement actions.

D4 Conflict Finance

Not covered

Conflict Finance is not yet covered for this jurisdiction in this report.

D5 Crypto, Digital Assets, and Financial Innovation

Crypto, Digital Assets, and Financial Innovation

Continue reading

South Korea's Financial Intelligence Unit completed its largest-ever sequential AML enforcement wave against domestic virtual-asset service providers between November 2025 and March 2026, fining Upbit (via operator Dunamu), Korbit and Bithumb in close succession, all for customer-due-diligence and suspicious-transaction-report failures. Bithumb's fine of KRW 36.8 billion, approximately $24.5 million, came with a six-month partial suspension of external transfers for new customers, following the discovery of approximately 6.65 million AML violations, including failed customer identification and 45,772 transfers to 18 unregistered overseas VASPs. Upbit's operator Dunamu was fined approximately KRW 35.2 billion, around $25 million, for accepting photocopied identification documents, permitting 3.3 million transactions by unverified customers, and failing to report 15 suspicious transactions. Korbit was fined KRW 2.73 billion with an institutional warning for inadequate customer identification, unauthorized overseas transactions, and skipped AML risk assessments on new services including NFTs.

The pattern across all three enforcement actions, spanning the country's largest exchanges, indicates a systemic rather than isolated compliance gap in customer identification and suspicious-activity reporting across Korea's domestic VASP sector, despite the sector operating under an established registration regime. Separately, the Financial Services Commission is pursuing technical-control reforms following a February 2026 Bithumb payout error, requiring exchanges to shift from delayed, up to 24-hour, balance checks to real-time reconciliation every five minutes.

Outlook

Whether this enforcement wave represents the peak of a correction cycle or the start of a sustained higher-enforcement posture for Korean VASPs is the key question going forward. The FSC's parallel technical-control reform track, covering real-time reconciliation and proposed automated kill-switches, is a distinct but related response addressing operational-resilience failures rather than customer-identification failures directly.

D6 Compliance Technology and Active Defence

Compliance Technology and Active Defence

Continue reading

Following a February 2026 Bithumb payout error, South Korea's Financial Services Commission is driving technical-control reforms for domestic crypto exchanges. Exchanges are being required to shift from delayed, up to 24-hour, balance checks to real-time reconciliation every five minutes, a substantial increase in the frequency and immediacy of internal control monitoring. Proposed measures also include automated kill switches and semi-annual inspections, which would represent an escalation from manual or periodic control review toward automated, continuously-operating active-defence infrastructure.

This technical-control reform track runs parallel to, but is analytically distinct from, the AML customer-identification and suspicious-transaction-report enforcement actions against Bithumb, Upbit and Korbit. Where the AML fines addressed failures in who exchanges were transacting with and for, the technical-control reforms address the operational-resilience and reconciliation-accuracy dimension, that is, whether an exchange's internal systems correctly track and report balances and transfers in real time. Both tracks originate from the same underlying supervisory concern about control adequacy at Korea's major exchanges, but they are different compliance-technology problems requiring different remediation.

Outlook

Whether the FSC's proposed automated kill-switch and semi-annual inspection requirements are formally adopted, and on what timeline, is the principal item to track. The move from 24-hour to 5-minute reconciliation cycles, if implemented as proposed, would represent a meaningful uplift in the technical baseline expected of Korean exchanges, and its successful implementation would be a relevant proof point for whether automated active-defence infrastructure can meaningfully reduce the kind of payout and balance errors that triggered this reform track.

D7 AML/CTF Regime

Not covered

AML/CTF Regime is not yet covered for this jurisdiction in this report.

D8 Commercial Activity

Not covered

Commercial Activity is not yet covered for this jurisdiction in this report.

Regulatory horizon
No dated horizon items this cycle. 4 items tracked without a confirmed date.
4 pending date · baseline financial-integrity-2026-07-05
Role action cards
MLRO

Korean VASP sector saw its largest-ever sequential AML enforcement wave, with Bithumb, Upbit and Korbit all fined for CDD and overseas-transfer failures within a six-month window.

The consistent finding across all three actions, failed customer identification and undisclosed or unregistered overseas counterparty transfers, is a direct signal for any institution with Korean VASP exposure to review counterparty-verification depth for cross-border crypto flows, particularly where a counterparty's registration status is not independently confirmed.

3 evidence refs
Compliance

Three sequential large AML fines against Korea's major exchanges point to a systemic customer-identification and suspicious-transaction-reporting gap across the domestic VASP sector.

Institutions maintaining correspondent or counterparty relationships with Korean VASPs should treat this enforcement pattern as evidence that domestic registration status alone does not guarantee counterparty-level CDD adequacy, and should factor the overseas-transfer leakage pattern into any Korea-linked crypto counterparty risk assessment.

3 evidence refs
Legal

No material change this cycle.

No material change for this persona this cycle

Board

South Korea's AML enforcement against domestic VASPs has escalated materially, with the country's three largest exchanges all fined within a six-month window.

The scale and clustering of these enforcement actions signal materially heightened financial-crime and reputational exposure for any institution with Korean crypto-sector counterparty relationships, and warrants board-level awareness given the pattern's consistency across three separately-operated major exchanges.

3 evidence refs
CTO

Korea's FSC is mandating a shift from 24-hour delayed balance checks to real-time reconciliation every five minutes, alongside proposed automated kill-switches, following a February 2026 Bithumb payout error.

This technical-control reform signals a materially higher bar for real-time reconciliation and automated control infrastructure at Korean exchanges, with implications for the technical architecture of any crypto-infrastructure connected to or modeled on the Korean exchange environment.

Risk

A structural leakage point persists at Korea's registered-exchange-to-unregistered-overseas-VASP interface despite an established domestic registration regime.

This is an emerging-typology signal for cross-border crypto counterparty risk concentration: domestic licensing alone did not prevent material volumes of flow to unregistered overseas counterparties, which should inform risk-model weighting for Korea-linked crypto exposure pending resolution of the new cross-border registration duty.

2 evidence refs
Operations

No material change this cycle.

No material change for this persona this cycle

Audit

Bithumb's enforcement action documented approximately 6.65 million individual AML violations, indicating a control-testing and audit-trail gap of substantial scale went undetected internally before regulatory discovery.

The scale of violations relative to the exchange's existing control framework raises the question of whether internal audit functions at comparable institutions would detect a similarly systemic gap before an external regulator does; this is a relevant benchmark for control-testing scope at any institution with comparable transaction volumes.

1 evidence refs
Decision lens
MLRO

Korean VASP sector saw its largest-ever sequential AML enforcement wave, with Bithumb, Upbit and Korbit all fined for CDD and overseas-transfer failures within a six-month window.

Compliance

Three sequential large AML fines against Korea's major exchanges point to a systemic customer-identification and suspicious-transaction-reporting gap across the domestic VASP sector.

Legal

No material change this cycle.

Board

South Korea's AML enforcement against domestic VASPs has escalated materially, with the country's three largest exchanges all fined within a six-month window.

CTO

Korea's FSC is mandating a shift from 24-hour delayed balance checks to real-time reconciliation every five minutes, alongside proposed automated kill-switches, following a February 2026 Bithumb payout error.

Risk

A structural leakage point persists at Korea's registered-exchange-to-unregistered-overseas-VASP interface despite an established domestic registration regime.

Operations

No material change this cycle.

Audit

Bithumb's enforcement action documented approximately 6.65 million individual AML violations, indicating a control-testing and audit-trail gap of substantial scale went undetected internally before regulatory discovery.

Shared evidence: 3 refs
Scenario sketches

AMLA direct-supervision transition reshaping cross-border VASP evasion patterns

Illustrative scenario for analytical orientation only. As the EU's Anti-Money Laundering Authority, established under Reg (EU) 2024/1620, moves from a purely national supervisory model toward direct supervision of a defined set of cross-border obliged entities, alongside the directly-applicable AML Regulation (Reg (EU) 2024/1624) and per-state Sixth AML Directive transposition, illicit actors seeking jurisdictions with weaker supervisory reach could be expected to shift activity toward obliged entities and corridors that fall outside AMLA's direct-supervision perimeter, concentrating evasion pressure on the remaining nationally-supervised segment. This is architecture-over-incident framing: the mechanism illustrated is structural displacement of supervisory arbitrage, not an observed event. It is not a prediction and not a statement of observed fact.

Illustrative scenario for analytical orientation only. Not compliance advice, not a prediction, and not a statement of observed fact.

Standing trackers (T1–T6)
TrackerStatusNote
T1 · Russian Sanctions-Evasion Architectureno_change
T2 · EU AML Package / AMLAno_change
T3 · FATF Grey Listno_changeJune 2026 plenary: blacklist unchanged (Iran, DPRK, Myanmar); grey list added Iraq, Bosnia & Herzegovina; removed Algeria, Namibia.
T4 · Beneficial-Ownership Register Statusno_change
T5 · Crypto & Digital-Asset IntegrityescalatingKorea's FIU completed a sequential enforcement wave (Upbit, Korbit, Bithumb) imposing its largest-ever AML fines on domestic VASPs, alongside FSC-driven technical reforms.
T6 · Sanctions Regime Divergenceno_change
Registers

Enforcement actions

  • FSC suspended new-customer virtual asset transfers at Dunamu for three months after finding the firm transacted with unreported virtual asset operators and violated customer verification and suspicious-transaction-report obligations. 25 Feb 2025
  • The three governments issued a joint statement pledging to intensify disruption of North Korea's use of overseas IT workers who obscure their identities to win contracts and funnel earnings to weapons programs. 28 Aug 2025
  • FSC and KoFIU proposed amendments requiring all regulated VASPs to report cross-border transactions over KRW 10 million involving overseas counterparties, moving beyond suspicion-based SAR filing to bulk cross-border transaction reporting. 1 Mar 2025
  • FSC formed an industry-wide task force after Bithumb erroneously credited 620,000 Bitcoin (~$40bn) to 695 users during a promotional payout, mistakenly inputting Bitcoin instead of won, triggering a brief sell-off and parliamentary hearings. 9 Feb 2026

Sanctions changes

  • OFAC designated Russian national Vitaliy Andreyev, DPRK official Kim Ung Sun, and entities Shenyang Geumpungri Network Technology and Korea Sinjin Trading Corporation for funneling DPRK IT-worker revenue tied to Chinyong, an entity originally co-designated by OFAC and South Korea's MOFA in May 2023. 27 Aug 2025
  • OFAC designated six individuals and two entities, including Amnokgang Technology Development Company and a Vietnam-based facilitator, and listed 21 cryptocurrency addresses across multiple blockchains tied to DPRK IT-worker schemes generating nearly $800m in 2024. 12 Mar 2026
  • The European Commission added Russia to its high-risk third-country list under Delegated Regulation (EU) 2026/46 (4 December 2025), requiring enhanced vigilance by EU obliged entities on Russia-linked transactions. 4 Dec 2025

Regulatory horizon (register)

  • Digital Asset Basic Act (won-stablecoin framework) passage
  • Bulk cross-border VASP transaction reporting rule effective
  • Korea's next FATF mutual evaluation (5th round)
  • Basel Committee crypto-exposure prudential rule reassessment

Active schemes

  • [CRITICAL] DPRK IT-worker crypto revenue-to-WMD pipeline
  • [CRITICAL] Lazarus Group hack-to-launder pipeline via Korean exchanges
  • Won-stablecoin regulatory vacuum ahead of Digital Asset Basic Act
  • Semiconductor trans-shipment risk in Russia-evasion supply chains
Sources
  1. FATF
  2. FATF/APG
  3. FATF
  4. US Department of the Treasury (OFAC)
  5. European Commission (DG FISMA)
  6. Bloomberg
  7. Bloomberg
  8. Bloomberg
  9. Chainalysis
  10. Elliptic
  11. Bloomberg
  12. Elliptic
  13. UNODC
Coverage gaps
Korea operates without a centralized public beneficial owner…
Korea operates without a centralized public beneficial ownership registry; UBO identification remains dependent on financial-institution CDD records rather than a verifiable central register, and FATF continues to flag PEP and correspondent-banking measures as unresolved since the original mutual evaluation.
Repeated internal-control failures at licensed VASPs -- Duna…
Repeated internal-control failures at licensed VASPs -- Dunamu/Upbit's unreported-counterparty and CDD/STR violations (2025) and Bithumb's $40bn erroneous bulk transfer (2026) -- show that licensing under the Virtual Asset User Protection Act has not yet translated into robust operational-risk and AML control maturity.
Legislative deadlock between the FSC and Bank of Korea over …
Legislative deadlock between the FSC and Bank of Korea over bank-only versus non-bank stablecoin issuance has stalled the Digital Asset Basic Act, leaving won-backed stablecoin pilots (KRW1, cross-border remittance projects) to advance without a finalized statutory AML/CFT and reserve framework.
Publicly available English-language reporting on Korea's cur…
Publicly available English-language reporting on Korea's current operational beneficial-ownership data quality (as opposed to legal framework) is thin outside of FATF's own generic synopsis; no recent ICIJ/OCCRP-style forensic BO investigation specific to Korea was located within the 18-month window.

Evidence

Confidence-tiered claims

KRW 36.8 billion fine (approx. $24.5m) and six-month partial external-transfer suspension for new customers, for approximately 6.65 million AML violations including failed customer identification and 45,772 transfers to 18 unregistered overseas VASPs. SRC-fim-KR-001
Probable · 1 source
KRW 35.2 billion (~$25m) fine for accepting photocopied ID documents, permitting 3.3 million transactions by unverified customers, and failing to report 15 suspicious transactions. SRC-fim-KR-003
Probable · 1 source
KRW 2.73 billion fine with institutional warning for inadequate customer identification, unauthorized transactions with overseas operators, and skipped AML risk assessments on new services including NFTs. SRC-fim-KR-002
Probable · 1 source
Six individuals and two entities designated for laundering approximately $800 million generated via fraudulent DPRK overseas IT-worker employment schemes, funding WMD/ballistic-missile programs. SRC-fim-GLOBAL-004
Probable · 1 source
At the June 2026 plenary the Call-for-Action blacklist remained unchanged (Iran, North Korea, Myanmar); grey list added Iraq and Bosnia & Herzegovina, removed Algeria and Namibia. No bearing on South Korea, which is not FATF-listed. SRC-fim-GLOBAL-005
Probable · 1 source