We Resolve Legal Matters
How can we assist you?
PRACTICES
More-
Cross-border · Dispute Resolution
International Laws & Regulations, Overseas Company Incorporation, Global Expansion (FLIP), International Investment, International Contracts
-
Entertainment
Exclusive Contracts, Contract Termination, Copyright, Publishing, Overseas Expansion
-
Sports
Broadcasting Agreements, Player Contracts, Esports, Sports Agents, International Competitions
Blogs
More-
Generative AI and Personal Data: What Businesses Should Check Before Uploading Customer Information or Contracts
Businesses are increasingly using generative AI to review contracts, summarize meetings, respond to customer inquiries, and draft documents. However, when contracts or other materials entered into an AI service contain personal data relating to customers or employees, the issue extends beyond operational efficiency. It may raise concerns regarding personal data processing, confidentiality, and the management of internal business information. Businesses should therefore understand how an AI service stores and uses input data and establish internal rules that reflect how generative AI is actually used within the organization. How Is Information Entered into Generative AI Processed? From the user’s perspective, generative AI appears to involve simply entering a question and receiving a response. In practice, however, prompts and uploaded files are transmitted to the service provider’s systems. Depending on the service policy and account type, they may be retained as conversation records or system logs and may also be used to improve the service. Before entering business materials, companies should check: ▪️ Whether input data may be used to train the AI model ▪️ How long conversations and uploaded files are retained ▪️ Whether conversations and uploaded materials can be deleted ▪️ In which country and on which servers the data is processed ▪️ What access permissions are granted when the AI is connected to external applications or internal systems Using a paid or enterprise account does not automatically resolve every data protection issue. The relevant contractual terms and actual data-processing arrangements must also be reviewed. Is Information No Longer Personal Data Once the Name Is Removed? Removing a customer’s name or contact information from a contract does not necessarily mean that the remaining information is no longer personal data. Personal data includes not only information that directly identifies an individual, such as a name, but also information that may identify a person when combined with other readily available information. Even after a name has been removed, an individual may still be identifiable through a combination of information such as: ▪️ The company name and a specific job title ▪️ The contract date and transaction amount ▪️ The employee’s department and performance evaluation ▪️ Detailed consultation history and family relationships ▪️ A case number and the location of a dispute A company name alone is generally information about a legal entity. However, when combined with a specific position, transaction details, or other contextual information, it may make an individual employee or representative identifiable. Businesses should therefore remove information that is unnecessary for the intended task rather than deleting names alone. Actual names, contact details, company names, and similar identifiers may also need to be replaced with fictional or generic information. Does Entering Customer Information Automatically Violate Korea’s Personal Information Protection Act? Entering customer information into a generative AI service does not automatically constitute a violation of Korea’s Personal Information Protection Act, commonly referred to as the PIPA. However, a business may generally use personal data only within the scope of the original purpose of collection and an appropriate legal basis. It is therefore necessary to assess whether the intended AI use is related to the original processing purpose and whether additional consent or another legal basis is required. The relationship between the business and the AI service provider must also be reviewed. The applicable legal framework may differ depending on whether the provider processes data solely on the company’s instructions or also uses the input data for its own purposes, such as model training or service improvement. Depending on the actual arrangement, the use of the service may involve outsourced processing, third-party provision, or other forms of data processing. If personal data is transferred to servers or service providers located outside Korea, the requirements governing overseas transfers must also be considered. The applicable rules cannot be determined solely from the fact that customer information was entered into an AI service. Businesses should review the actual contractual structure and data flow, including: ▪️ The legal basis for using personal data in the relevant AI task ▪️ The purposes for which the service provider uses input data ▪️ Whether the data is used for training or service improvement ▪️ The data-retention period and deletion procedures ▪️ The server locations and countries to which data is transferred ▪️ The involvement of subprocessors or downstream service providers ▪️ How input data is handled after the service contract ends Contracts and Consultation Records Raise More Than Personal Data Issues Contracts and customer consultation records may contain confidential business information in addition to personal data. Examples include: ▪️ Transaction terms and supply prices ▪️ Sales strategies and business plans ▪️ Technical materials and development information ▪️ Confidentiality obligations agreed with customers or business partners ▪️ Strategies for litigation, investigations, or other disputes ▪️ Non-public financial information and internal decision-making materials Entering such information into an external generative AI service may raise issues under the PIPA, but it may also create risks involving contractual confidentiality obligations, trade secret protection, customer security agreements, and internal company policies. A corporate generative AI policy should therefore cover not only personal data but also trade secrets, contractual information, technical materials, and dispute-related documents. Internal Rules Businesses Should Establish for Generative AI Use When employees are left to decide individually how generative AI should be used, the company may be unable to identify what information has been entered into which external service. Rather than issuing a general instruction not to enter personal data, businesses should establish practical and specific rules that employees can follow in their day-to-day work. 1. Approved Services and Accounts The company should designate the generative AI services and account types that employees are permitted to use. Employees should also be prohibited from entering business materials through personal accounts or unapproved services. 2. Prohibited Input Data The company should clearly define the information that must not be entered into generative AI services. This may include resident registration numbers, bank account information, health information, other sensitive or high-risk personal data, trade secrets, non-public contractual terms, and materials relating to litigation or criminal investigations. 3. Approval Procedures for High-Risk Documents High-risk materials, such as contracts, human resources documents, and customer consultation records, may be made subject to prior review or approval by the responsible department. 4. Standards for Removing or Replacing Identifying Information Businesses should establish standards for removing or replacing information that could identify an individual or a transaction party, including names, contact details, company names, and transaction amounts. Rather than uploading an entire contract, employees should extract only the clauses required for the relevant task. Actual customer information may also be replaced with fictional names or sample data. 5. Conversation History and Model-Training Settings The company should determine whether the service allows input data to be excluded from model training, whether conversation history can be disabled, and how deletion features operate. 6. Internal Reporting and Incident Response Employees should be required to report promptly if personal data or confidential business information is entered into an AI service by mistake. The company should also establish procedures for deleting records, disabling external integrations, requesting deletion from the service provider, and taking any other necessary measures. What Should a Business Do If Customer Information Has Already Been Entered? If an employee mistakenly enters customer information or an internal document into a generative AI service, the company should first stop any further sharing or use of the resulting output. The following matters should then be reviewed: ▪️ Which account and AI service were used ▪️ What personal data or confidential information was entered ▪️ Whether the conversation and uploaded files can be deleted ▪️ Whether the service was connected to any external applications ▪️ Whether the information may have been used for training or service improvement ▪️ Whether a third party may have gained access to the information Where necessary, the company should delete the conversation history and uploaded files, revoke external access permissions, and request that the service provider stop processing or delete the relevant information. Whether the incident requires a personal data breach report or notification to affected individuals should be determined by considering the type and volume of information involved, the possibility of third-party access, whether the data has been deleted, and the potential harm to the individuals concerned. Effective Generative AI Use Requires Governance, Not Just Prohibition Generative AI can improve efficiency in contract review, document drafting, and customer communications. However, when its use is left entirely to individual employees, a business may have little control over where customer information and internal documents are transmitted or how they are subsequently used. Businesses should establish specific rules regarding approved services, prohibited data, the removal or replacement of identifying information, approval procedures for high-risk documents, and incident response. Decent Law Firm advises businesses on the legal use of generative AI, including compliance with Korean personal data protection requirements, review of service terms and data-processing agreements, overseas data transfers, trade secret protection, and the preparation of internal AI-use policies. This content is provided for general informational purposes only and does not constitute legal advice regarding any specific matter or business.
-
Fraud Charges Under Korean Law: How You Could Become a Convict Overnight
What Are the Legal Requirements for Fraud Under Korean Law? Fraud under Korean law is defined by Article 347 of the Criminal Act, and all four of the following elements must be satisfied for a fraud charge to be established. Deceptive act — deceiving the other party (including not only affirmative lies but also omissions that conceal facts) Mistake and disposition of property — the deception causes the other party to fall into a mistaken belief and dispose of property Causation — a causal relationship must exist between the deceptive act and the disposition of property Intent to defraud — the intent to obtain property or a proprietary benefit through the deceptive act Simply failing to repay money does not, by itself, satisfy the legal requirements for fraud. The key question is whether the person lacked the intention or ability to repay at the time of the transaction. What Is the Process, From Investigation to Trial? Whether the legal requirements for fraud are met is typically determined through the following process. 1) Filing a criminal complaint — the investigation begins when the victim files a complaint 2) Questioning of the parties — the circumstances of the transaction, use of funds, and ability to repay are examined 3) Gathering evidence — contracts, text messages, and account records are used to prove intent 4) Referral to the prosecution and indictment decision — the key issue is whether intent to defraud is recognized 5) Trial proceedings — the court makes a final determination on whether the legal requirements for fraud are met Because the circumstances surrounding the transaction and the flow of funds at the time largely determine the outcome, anyone who has been accused should respond carefully from the very beginning. A Real Case: How the Elements of Fraud Were Assessed [Case We Handled] Mr. B, a small business owner, borrowed money from an acquaintance because he urgently needed business funds, but was unable to repay it after a sudden drop in sales and was accused of fraud. With the help of Decent Law Firm, however, he was able to demonstrate — through his business ledgers, records of legitimate transactions, and evidence of efforts to repay at the time of borrowing — that he never had the intent to defraud, and the case ultimately ended in a non-indictment decision. As this shows, if intent to defraud cannot be established, the matter remains a civil default and does not become subject to criminal punishment. The Role of Defense Counsel, and Why You Should Work With Decent Cases involving disputes over the legal requirements for fraud call for the following professional response. Legal analysis of the circumstances of the transaction and the flow of funds Gathering objective evidence to prove the absence of intent to defraud Developing a statement strategy for each stage of the investigation Drawing on its experience handling numerous fraud cases, Decent Law Firm closely analyzes each client's transaction history and builds a systematic defense strategy from the early stages of the investigation through trial. We stand by our clients from beginning to end, so that those wrongly accused of fraud are not unfairly disadvantaged. Whether the legal requirements for fraud are met can vary greatly depending on the facts and how the evidence is interpreted. If you have already been accused or are facing an investigation, we recommend consulting with an attorney experienced in criminal cases rather than trying to assess the situation on your own. Decent is always ready to provide prompt, accurate legal advice and help you find the best direction for your specific situation.
-
Korea’s AI Basic Act Six Months On: Disclosure and Labeling Duties for Generative AI Businesses
Korea’s AI Basic Act took effect on January 22, 2026. Under the Act, businesses that provide generative AI products or services are subject to transparency obligations. Compliance, however, does not end with adding a notice to a service screen. The applicable legal risks depend on the AI model used, the information entered by users, where that information is transferred, and how the generated output is used. Advance Disclosure and Output Labeling Are Separate Obligations Article 31 of the AI Basic Act divides transparency obligations into two categories. First, an AI business operator intending to provide a product or service based on generative AI must inform users of that fact in advance. Second, when generative AI or an AI-powered service produces content, the business must indicate that the output was generated using AI. For example, a chatbot or AI document-generation service may need to disclose its use of generative AI through its terms of service or user interface before the service is used. Separately, text, images, audio, or video generated by the service may require an AI-generated content label. Synthetic audio, images, and video that could easily be mistaken for real content require particularly clear disclosure. In practical terms: Before use: disclose that the product or service uses generative AI. After generation: indicate that the resulting content was generated using AI. AI-Generated Content Does Not Always Require a Visible Watermark The required label does not necessarily have to be a visible watermark. The Enforcement Decree permits both: ▪️ Human-readable labeling ▪️ Machine-readable labeling Where only a machine-readable method is used, users must still be informed at least once, through text, audio, or another accessible method, that the content was generated using AI. All or part of the disclosure and labeling requirements may not apply where: ▪️ The service name or interface already makes the use of AI obvious ▪️ The AI is used exclusively for the operator’s internal business purposes ▪️ A separately issued government notice recognizes an exception The internal-use exception should be applied carefully. Materials initially generated for internal use may fall outside the exception once they are included in advertisements, customer reports, consultation materials, or other externally distributed content. Businesses should therefore distinguish between outputs that remain within the service and outputs that can be downloaded, shared, or provided to customers. Businesses Using External AI APIs May Also Be Covered A business does not need to develop its own AI model to fall within the scope of the AI Basic Act. The Act also covers businesses that use AI developed by another provider to offer AI products or services. A company may therefore qualify as an AI business operator where it connects an external large language model through an API and provides services such as: ▪️ AI chatbots ▪️ Image-generation tools ▪️ Document drafting or summarization ▪️ Automated customer consultation The key question is not who developed the underlying model. What matters is whether the company uses AI to provide a product or service to users. Businesses using third-party APIs should therefore review whether they are subject to advance disclosure and AI-output labeling obligations. Disclosure Compliance Is Only One Part of the Legal Review Generative AI services commonly send user inputs to an external AI model and return generated outputs to the user. This process may raise data protection and copyright issues that are legally separate from the labeling requirements under the AI Basic Act. 1. Personal Data Entered into AI Services Where customers or employees enter names, consultation records, contracts, photographs, or internal documents into an external AI service, the business should verify: ▪️ Whether input data is stored or used for model training ▪️ The location and country of the servers processing the data ▪️ Applicable retention periods and deletion procedures ▪️ Whether the arrangement constitutes outsourcing, third-party provision, or overseas transfer ▪️ Whether the data is retransmitted to plug-ins or other external services The legal classification should be based on the actual data flow rather than the name of the agreement with the AI provider. A privacy policy should accurately reflect how personal data is collected, transferred, retained, and deleted throughout the AI service structure. 2. Copyright in AI-Generated Outputs A business does not automatically acquire exclusive copyright merely because an image, document, video, or source code was generated using AI. Relevant considerations include: ▪️ The degree of human creative involvement ▪️ Whether the source materials were lawfully used ▪️ Whether the AI provider’s terms permit commercial use ▪️ Whether the output is substantially similar to existing protected works AI-generated content may also infringe third-party copyrights, image rights, or other intellectual property rights. Businesses using generated outputs for advertising, websites, software, games, or commercial publications should retain records of the model used, prompts, initial outputs, and subsequent human edits. AI Used to Evaluate Individuals May Qualify as High-Impact AI Not every generative AI service is classified as high-impact AI. However, additional review may be required where AI is used beyond basic drafting or guidance and affects a person’s rights, opportunities, or access to essential services. Relevant examples include AI used in: ▪️ Recruitment and applicant evaluation ▪️ Lending, credit scoring, and insurance assessment ▪️ Medical diagnosis or treatment-related decision-making ▪️ Student admission, selection, or performance evaluation For instance, an AI tool that summarizes a résumé may present a different level of legal risk from one that calculates an applicant’s probability of being hired. The assessment depends on how the AI output is used in the actual decision-making process. Where a system qualifies as high-impact AI, the operator may need to implement: ▪️ Risk-management measures ▪️ Procedures for explaining major decision-making criteria ▪️ User-protection procedures ▪️ Human management and oversight ▪️ Preparation and retention of relevant records Documents to Review Before Launching a Generative AI Service Legal review should not begin by drafting a disclaimer in isolation. A business should first map: ▪️ The AI model being used ▪️ The information entered by users ▪️ The data-transfer route ▪️ How generated outputs are used ▪️ Where human review takes place The following documents should then be aligned with the actual service structure. AI Disclosure and Labeling Notices Separate advance disclosure before use from labeling of generated outputs. Terms of Service Define the permitted use of AI outputs and procedures for handling errors, rights infringement, and user complaints. Privacy Policy Reflect the actual collection, processing, storage, overseas transfer, and deletion of personal data involving external AI providers. AI Supply Agreements and API Terms Review provisions concerning data use, cybersecurity incidents, intellectual property, service interruptions, and liability allocation. Internal AI Use Policy Establish restrictions and approval procedures for entering customer data, contracts, source code, and confidential business information into AI tools. Legal Review Based on the Actual AI Service Structure Under Korea’s AI Basic Act, generative AI transparency obligations are divided into advance disclosure before use and labeling of AI-generated outputs. In practice, however, legal risk extends beyond how a notice is displayed. Businesses should also review the use of external AI models, personal data processing and overseas transfers, rights in generated content, potential classification as high-impact AI, and the allocation of liability with AI vendors. Decent Law Firm’s Corporate Practice Group advises AI and technology companies based on their actual service functions and data flows. Our review covers the applicability of the AI Basic Act, disclosure and labeling design, privacy and copyright issues, external AI model agreements, and the legal documentation required for launching and operating AI services in Korea. This content is provided for general informational purposes only and does not constitute legal advice for any individual matter.
-
Korea’s Suspicious Account Transaction Freeze System: What Scam Victims and Account Holders Need to Know
Since June 30, 2026, financial institutions in Korea have been able to promptly restrict transactions involving accounts suspected of being used in emerging phishing schemes, including no-show scams and romance scams. Victims should report the incident before the funds are transferred elsewhere. At the same time, an account holder whose account has been frozen despite receiving legitimate payment must be prepared to prove the underlying transaction with objective evidence. What Is the Suspicious Account Transaction Freeze System? Korea’s 「Special Act on the Prevention of Loss Caused by Telecommunications-Based Financial Fraud and Refund for Losses」 provides procedures for freezing accounts used in voice phishing schemes and refunding eligible victims. However, fraudulent schemes disguised as ordinary transactions involving goods or services have generally fallen outside the scope of the conventional voice phishing refund framework. This created practical difficulties in promptly restricting accounts used in scams presented as product purchases, investments, or service transactions. To address this issue, the Financial Services Commission, the Korea Financial Intelligence Unit, and the National Police Agency introduced a system on June 30, 2026, allowing suspicious accounts linked to emerging phishing schemes to be temporarily restricted through existing customer due diligence procedures. Once an account is identified as potentially connected to such a scheme, the financial institution may classify the account holder as subject to enhanced customer due diligence under the 「Act on Reporting and Using Specified Financial Transaction Information」 and restrict incoming and outgoing transactions. What Types of Scams May Be Covered? The system may apply to various forms of emerging phishing fraud, including the following. ▪️No-Show Scams A fraudster impersonates a public institution or corporate buyer, promises a large order, and instructs the victim to purchase goods or materials from a designated supplier. ▪️Romance Scams A fraudster builds a personal relationship through social media or messaging applications and later requests money for investments, business expenses, customs charges, medical costs, or similar reasons. ▪️Investment Scams A fraudster promises profits from stocks, virtual assets, overseas futures, or other investments, receives funds from the victim, and then blocks withdrawals or demands additional payments. However, an account is not automatically frozen simply because money was transferred and a dispute later arose. Authorities must distinguish between an ordinary contractual dispute and conduct involving deception through telecommunications and circumstances indicating possible fraud. Financial institutions and the police may review transaction records, communications, the method used by the suspected offender, and whether the promised goods or services were actually provided. How Does the Transaction Freeze Process Work? 1. Victim Report and Temporary Action by the Financial Institution A person who suspects that they have been targeted by an emerging phishing scam should immediately report the matter by calling 112 or visiting a nearby police station in Korea. A financial institution may take temporary action when it identifies a suspicious transaction through its fraud detection system or receives a report from the victim or the police. The account may therefore be temporarily restricted before the authorities have conclusively determined whether the case involves conventional voice phishing or another form of emerging phishing fraud. 2. Police Review of the Fraud Type The National Police Agency’s Integrated Response Center for Telecommunications Financial Fraud reviews whether the transaction involved a genuine sale of goods or services and examines the specific method used by the suspected offender. When the case is classified as conventional voice phishing, the existing account freeze and victim refund procedures under the telecommunications financial fraud legislation may apply. When the case is classified as an emerging phishing scheme, the relevant account may instead be placed under enhanced customer due diligence procedures. 3. Temporary Transaction Freeze for Seven Business Days Once the account is identified as being connected to an emerging phishing scheme, the financial institution may temporarily restrict both incoming and outgoing transactions. The Korea Financial Intelligence Unit then reviews the transaction history and the relationship between the victim and the account holder within seven business days of receiving the report. 4. Additional Freeze of Up to 60 Business Days When the Korea Financial Intelligence Unit determines that the restriction should remain in place, the financial institution may continue the freeze for an additional 30 business days after the initial seven-business-day period. At the request of the police, the restriction may be extended once for another 30 business days. During this period, the police may investigate the account’s connection to the suspected crime and trace the movement of funds. An Account Freeze Does Not Automatically Guarantee a Refund A suspicious account transaction freeze is intended to prevent funds from being transferred out of an account believed to have been used in a fraudulent scheme. It does not mean that the victim is automatically entitled to an immediate or full refund. In conventional voice phishing cases, the statutory process for extinguishing the account balance and refunding eligible victims may apply. By contrast, a transaction freeze involving an emerging phishing scheme relies on customer due diligence measures under Korea’s financial transaction reporting legislation. It therefore operates differently from the statutory refund process applicable to conventional voice phishing cases. The method and likelihood of recovery may depend on factors including: ▪️The amount remaining in the account ▪️The number of victims ▪️The nature of the suspected fraud ▪️The outcome of the criminal investigation ▪️Whether the account holder or another participant received or transferred the funds Depending on the circumstances, the victim may need to file a criminal complaint and separately consider a civil claim for unjust enrichment or damages against the account holder or the persons who participated in the fraud. Evidence Victims Should Preserve Delays in reporting may allow the funds to be transferred through multiple accounts, converted into cash, or exchanged for virtual assets. Rather than continuing to negotiate with the suspected offender, the victim should first consider reporting the matter and requesting that the relevant account be restricted. Important evidence may include: ▪️Bank transfer receipts, transfer dates, account numbers, and account holder names ▪️Text messages and conversations through KakaoTalk, Telegram, or other messaging services ▪️Screenshots of investment or trading platforms ▪️Requests for additional deposits, fees, or taxes ▪️Contracts, purchase orders, quotations, and business registration information ▪️Telephone numbers, social media accounts, and original files provided by the suspected offender Leaving a chatroom or replacing a mobile phone may make it difficult to preserve the original evidence. Victims should retain not only screenshots but also exported chat records, attachments, and original electronic files where possible. What If a Legitimate Business Account Is Frozen? A business may receive genuine payment for goods or services but still have its account reported as suspicious because the payment is connected to a broader fraudulent fund flow. Even when the underlying transaction was legitimate, restrictions on a business account may significantly affect payroll, supplier payments, and ordinary business operations. The account holder may raise an objection with the relevant financial institution or contact the National Police Agency’s Integrated Response Center for Telecommunications Financial Fraud at 1394. If the police determine that the account is unlikely to be connected to criminal activity, they may request that the financial institution lift the transaction restriction. A general statement that the payment came from a legitimate transaction may not be sufficient. The account holder should provide objective evidence demonstrating the commercial basis for receiving the funds. Relevant materials may include: ▪️Contracts and purchase orders ▪️Tax invoices, receipts, and payment records ▪️Delivery and receipt records ▪️Evidence showing that services were actually performed ▪️Communications with the customer or counterparty ▪️Records showing how the received funds were used ▪️Evidence explaining repeated or similar transactions If the account, debit card, password, or another means of account access was transferred or rented to another person, the matter may go beyond a simple transaction freeze and raise issues under Korea’s Electronic Financial Transactions Act. Similarly, withdrawing cash or transferring funds while knowing that the money was connected to a fraudulent scheme may result in an investigation for aiding and abetting fraud. The account holder should therefore organize the facts and supporting evidence from the earliest stage. Key Points for Responding to a Suspicious Account Freeze Victims of emerging phishing scams should report the incident promptly and preserve all transaction records and communications before the funds are transferred elsewhere. A person or business whose account has been frozen despite receiving legitimate payment should demonstrate the substance of the transaction and the lawful basis for receiving the funds through contracts, invoices, delivery records, and other objective evidence. Decent Law Firm assists clients with criminal complaints arising from emerging phishing scams, reviews potential avenues for recovering transferred funds, and advises account holders on objections to transaction freezes and related criminal investigations. This content is provided for general informational purposes only and does not constitute legal advice for any individual matter.
-
The CATFI Rug Pull Case and Unfair Trading Under Korea’s Virtual Asset User Protection Act
Meme coins often attract investors because they can be launched relatively quickly and may experience sharp price increases within a short period. Decentralized exchanges, or DEXs, facilitate trades through smart contracts and automated protocols rather than a centralized order-matching system. Once a token has been issued, trading can begin by creating a liquidity pool without going through the formal listing review typically required by a centralized exchange. This structure can attract investors seeking early exposure to newly launched tokens. At the same time, there has been growing concern over so-called rug pulls, in which project operators use false or misleading information to drive up the price of a token and then sell their holdings all at once. In May 2026, the Seoul Southern District Prosecutors’ Office indicted individuals involved in the issuance of the meme coin CATFI on charges including violations of Korea’s Act on the Protection of Virtual Asset Users. Prosecutors alleged that the defendants circulated false positive announcements, manipulated the token’s trading activity, and obtained unlawful profits. The case was the first in which prosecutors applied the Act’s provisions on fraudulent unfair trading. This article examines the laws that may apply to rug pulls and the key legal issues arising from such cases. Laws That May Apply to Rug Pull Schemes A rug pull is not a separately defined criminal offense under Korean law. Depending on how the scheme was structured, several provisions may apply. Where false disclosures, artificial trading activity, or market manipulation are involved, Article 10 of the Act on the Protection of Virtual Asset Users, which prohibits unfair trading practices, may become relevant. Category Main Conduct Relevant Provision Use of material non-public information A virtual asset service provider, issuer, or other relevant party uses undisclosed material information for trading Article 10(1) Market manipulation through matched or wash trades Parties coordinate transactions in advance or conduct trades without a genuine transfer of economic ownership Article 10(2) Market manipulation through actual trades Trades are carried out to induce others to buy or sell by artificially moving the market price Article 10(3) Fraudulent unfair trading A person uses fraudulent means, schemes, or deceptive practices, or makes false statements about material facts Article 10(4) If the parties behind a rug pull used multiple wallets to trade among themselves and artificially inflate transaction volume, Article 10(2) may apply. If investors were attracted through false lock-up announcements, fabricated social media engagement, or other misleading representations, Article 10(4) may also become relevant. A violation of these provisions may result in imprisonment for at least one year or a fine equal to three to five times the profit obtained or loss avoided through the violation under Article 19(1). Where the unlawful profit or avoided loss is at least KRW 500 million but less than KRW 5 billion, the offender may be sentenced to imprisonment for at least three years. Where the amount is KRW 5 billion or more, the punishment may be life imprisonment or imprisonment for at least five years under Article 19(3). Separate from criminal penalties, the Financial Services Commission may also impose an administrative surcharge in connection with unfair trading conduct. Administrative sanctions and criminal proceedings are legally distinct and may be pursued through separate procedures. The CATFI Case and the Legal Test for a Rug Pull According to the prosecution, the individuals involved in CATFI divided their holdings across multiple wallets and announced a lock-up plan on social media even though the promised restrictions were not actually observed. An influencer allegedly presented himself as an independent third party with no connection to the issuing group and encouraged investors to purchase the token. The defendants were also accused of using multiple wallets to create the appearance of active trading and rising demand. Once purchases by ordinary investors increased, they sold their holdings in a large-scale disposal. The token reportedly increased in value by approximately 1,001 times within 26 hours of issuance. Around 6,000 individuals purchased the token, and 256 investors were found to have suffered losses totaling approximately KRW 900 million. Prosecutors alleged that the defendants used approximately KRW 10 million in initial funds and obtained roughly KRW 400 million in sale proceeds. At the first trial hearing held on June 30, 2026, the defendants admitted the charges. Prosecutors requested a sentence of four years and six months for the influencer alleged to have led the scheme. However, a sharp decline in a token’s price or the failure of a project does not automatically establish a criminal rug pull. Virtual asset investments inherently involve price volatility. It is therefore necessary to distinguish between a genuine business failure and a scheme designed from the outset to deceive investors and extract funds. In practice, investigators may examine whether: ▪️ The parties had planned to sell their holdings before the token was issued or concealed the true amount held by the project team ▪️ Lock-up or token-burning plans were falsely announced, or holdings were distributed across multiple wallets to disguise common ownership ▪️ Trading volume and price movements were artificially created, followed by the closure of social media channels or online communities immediately after the sale Key Legal Issues and Response Options 🔹Criminal Liability of Influencers and Marketing Personnel A person does not avoid criminal liability simply because they did not personally issue the token. An influencer, marketing agency, or account operator may be investigated as a principal offender or an accomplice if they coordinated with the issuing group, published false information, or recommended the token while falsely presenting themselves as an independent third party. Relevant evidence may include: ▪️ Records showing that tokens were transferred to the promoter before the marketing campaign ▪️ Messages concerning the sharing of sale proceeds or trading profits ▪️ Records showing that promotional content was published despite knowledge that the information was false These materials may be important in determining whether the person merely provided advertising services or knowingly participated in the scheme. 🔹Options for Investor Recovery Article 10(6) of the Act on the Protection of Virtual Asset Users provides that a person who violates the unfair trading provisions may be liable for losses caused to users by the violation. Accordingly, investors may consider a civil claim for damages separately from any criminal complaint or prosecution. In practice, however, recovery may be difficult where the issuer operated through anonymous wallets. Identifying the responsible parties and proving a causal connection between the unlawful conduct and the investment loss can require a detailed review of both blockchain records and online promotional materials. Investors should therefore preserve relevant evidence as early as possible, including wallet addresses, transaction hashes, purchase records, social media posts, and announcements concerning lock-ups, listings, or partnerships. Decent Law Firm’s Virtual Asset Practice The CATFI case demonstrates that even where a meme coin is traded through a DEX, false announcements, coordinated trading, and artificial price movements may lead to liability under Korea’s Virtual Asset User Protection Act. It also shows that affected investors may need to consider both criminal proceedings and civil claims for damages. Decent Law Firm’s Virtual Asset Practice reviews on-chain transaction structures and blockchain fund flows in connection with rug pulls, market manipulation, criminal complaints, investigations, and civil damages claims. Where an investment loss appears to involve a rug pull or other unfair trading conduct, legal advice should be obtained at an early stage, beginning with the preservation and review of evidence. This content is provided for general informational purposes only and does not constitute legal advice for any specific matter.
-
Crypto Referral Liability in Korea: Why the FSC Issued a Warning on Unregistered Virtual Asset Service Providers
Sharing overseas crypto exchange referral links on YouTube, Telegram, or open chat rooms may seem like simple advertising. However, in its press release dated June 24, 2026, the Financial Services Commission (FSC) stated that referral or recommendation-link activities may be viewed as assisting unregistered virtual asset business operations. The FSC also noted that referrers themselves may be subject to criminal liability depending on the circumstances. If you operate or participate in crypto referral marketing, private stablecoin exchange, or promotion of overseas crypto exchanges targeting Korean users, it is important to review whether your activities may raise issues under Korea’s Specified Financial Information Act. Key Points from the FSC Warning The FSC explained that, under the Specified Financial Information Act, any entity conducting virtual asset business targeting Korean users must be reported to the Korea Financial Intelligence Unit (KoFIU), unless it is one of the 28 registered virtual asset service providers. If an entity conducts virtual asset trading, exchange, transfer, custody, brokerage, or intermediary services as a business without proper reporting, this may constitute a violation of the Specified Financial Information Act. Unregistered virtual asset business activities may be punishable by imprisonment of up to 5 years or a fine of up to KRW 50 million. The FSC also noted that, after the amended Specified Financial Information Act takes effect in August 2026, those involved in unregistered illegal business activities may face additional restrictions. These may include restrictions on becoming a major shareholder of a domestic virtual asset service provider or serving as a representative or executive officer for a certain period. In this sense, the FSC press release is not merely a general user warning. It can also be understood as a signal that Korean authorities may strengthen investigations and sanctions against unregistered virtual asset service providers and those who assist their business activities. Three Types of Illegal Activity Highlighted by the FSC The FSC identified three major types of illegal virtual asset business activities recently observed in Korea. First, overseas exchanges conducting business in Korea without reporting. Even if an exchange is based overseas, Korea’s Specified Financial Information Act may apply if the exchange conducts business targeting Korean users. Factors such as Korean-language websites, KRW payment support, Korean user acquisition events, and domestic marketing activities may be considered together. Second, private stablecoin exchange businesses. Private exchange operators who buy, sell, or exchange stablecoins such as USDT for KRW may also raise legal issues. These services may target foreign students, tourists, foreign residents in Korea, or users who wish to avoid identity exposure. Even if the operator claims that the activity was merely a private exchange, it may still be viewed as an unregistered virtual asset business if repetition, fees, customer solicitation, and business structure are confirmed. Third, SNS-based referral promotion. This refers to cases where a person receives commissions from an overseas virtual asset service provider and promotes that exchange through YouTube, Telegram, open chat rooms, or similar channels. In particular, if the promotion is combined with referral links, invitation codes, fee paybacks, VIP chat rooms, or user-management activities, it may go beyond simple advertising and be viewed as user solicitation or assistance to unregistered business operations. Why Crypto Referral Marketing May Become a Criminal Issue Crypto referral programs are commonly operated in the following structure. 1. Distribution of overseas exchange referral links or invitation codes 2. Receipt of commissions based on referred users’ trading volume 3. Guidance on how to use the exchange through Telegram or open chat rooms 4. Promotion based on events, profit claims, fee discounts, or other incentives 5. Repeated promotion targeting Korean users The legal issue is whether this structure is merely advertising or whether it assists an unregistered virtual asset service provider’s business in Korea. In its press release, the FSC specifically warned against participating in referral or recommendation-link solicitation activities and stated that referrers may also be subject to criminal liability. Therefore, YouTubers, influencers, investment chat room operators, Telegram channel operators, and open chat room administrators may be investigated even if they did not directly operate the exchange. Investigators may review how the promotion was conducted, how referral fees were paid, whether there was a contractual relationship with the exchange, and how Korean users were recruited. Can Private Exchange or OTC Transactions Also Lead to Investigation? The same issue may arise in private exchange or OTC transactions. A person may believe that they were simply buying or selling crypto. However, the following circumstances may raise issues under the Specified Financial Information Act. 1. Repeated transactions with an unspecified number of users 2. Receipt of fees or exchange-rate margins for each transaction 3. Customer solicitation through Telegram, KakaoTalk, or SNS 4. Continuous exchange between KRW and stablecoins such as USDT 5. Brokerage or intermediary activity for the convenience of others The Supreme Court of Korea has also held that, unlike an ordinary exchange user, a person may be considered a virtual asset service provider if they continuously and repeatedly conduct virtual asset transactions for the benefit of an unspecified number of customers or users and receive compensation for doing so. The key issue is whether the activity was simple holding or investment, or whether it can be viewed as repeated, compensated virtual asset transactions conducted as a business. Why Ordinary Users Should Not Simply Assume They Are Safe Using an unregistered exchange or private exchange service does not automatically make a user a suspect under the Specified Financial Information Act. However, the FSC has warned that users of illegal virtual asset operators may face unexpected disadvantages. For example, the user’s funds may become mixed with criminal funds, or the user may become subject to investigation during the process of verifying counterparties and the source of funds. The following situations may make it difficult to characterize the person as a mere user. 1. Sharing referral links with acquaintances and receiving rewards 2. Repeatedly encouraging others to use an unregistered exchange 3. Introducing private exchange transactions and receiving commissions 4. Dealing with funds suspected to be connected to phishing, narcotics, fraud, or other crimes 5. Allowing one’s bank account to be used as a deposit or withdrawal channel for multiple people In such cases, authorities may review not only potential violations of the Specified Financial Information Act, but also issues under the Electronic Financial Transactions Act, the Criminal Proceeds Concealment Act, fraud aiding and abetting, or other money-laundering-related allegations. If You Have Already Been Contacted by Investigators If you have been contacted by the police, KoFIU, or another investigative authority, the first step is to accurately identify your role. The defense strategy will differ depending on whether you were a mere user, promoter, broker, intermediary, or private exchange operator. At the early stage of investigation, it is important to organize the following materials. · How you joined or used the exchange · Referral link or referral code usage history · Commission or fee settlement records · Telegram, KakaoTalk, or open chat room messages · Virtual asset deposit and withdrawal records · KRW bank account transaction records · Contracts or settlement records with overseas exchanges or advertisers · Whether you recruited Korean users The important point is not simply to claim that you were only a user. Before making a statement, it is necessary to analyze how investigators may view the transaction structure, revenue structure, promotion method, user recruitment, repetition, compensation, and awareness of illegality. How Decent Law Firm Can Assist Decent Law Firm has reviewed a wide range of matters involving virtual asset service provider reporting, violations of the Specified Financial Information Act, crypto referral marketing, OTC and P2P transactions, stablecoin exchange, and criminal cases involving overseas exchanges. Virtual asset investigations are not limited to crypto transaction records. Investigative authorities may review Telegram messages, referral-fee settlement structures, relationships with exchanges, KRW bank account flows, wallet address movements, advertising phrases, and user recruitment methods. Before attending an investigative interview, the following issues should be carefully reviewed. 1. Whether the activity constitutes a virtual asset business under the Specified Financial Information Act 2. Whether the alleged unregistered business activity had continuity, repetition, and compensation 3. Whether referral promotion was simple advertising or user solicitation 4. Whether private exchange activity was personal trading or business operation 5. Whether the matter may expand into money laundering or criminal proceeds allegations 6. What should and should not be stated during a police interview If you have been contacted by investigators in relation to crypto referrals, private exchange, or use of an unregistered overseas exchange, legal review before your initial statement is essential. Decent Law Firm’s Virtual Asset Practice Group analyzes the transaction structure and investigation issues together to provide a response strategy tailored to each client’s situation. Key Takeaways The FSC press release dated June 24, 2026 is not merely a general warning about unregistered virtual asset service providers. It clearly indicates that overseas exchanges targeting Korean users, private stablecoin exchange operators, and SNS-based crypto referral promoters may all be subject to investigation under the Specified Financial Information Act.In particular, because the FSC officially mentioned that referral participants may also face criminal liability, YouTubers, influencers, channel operators, and investment chat room operators should immediately review their existing promotion structures. After being contacted by investigators, simply saying that you did not know may not be enough. The first step should be to legally assess whether your conduct may be viewed as business operation, brokerage, intermediation, or solicitation under Korean law. Source: Financial Services Commission, Press Release on Caution Against Using and Trading with Illegal Virtual Asset Operators, June 24, 2026. This content is provided for general informational purposes only and does not constitute legal advice for any specific case.