A Loan Taken Out in Your Name in South Korea — When You Do Not Have to Repay It





Banking & Identity Theft

A Loan Taken Out in Your Name in South Korea
When You Do Not Have to Repay It
Soyoung Park · Representative Attorney, Atlas Legal
Cheongju District Court 2024Na57532  ·  Supreme Court of Korea 2024Da236754  ·  Supreme Court of Korea 2024Da310331

Key Answer: Under South Korean law, a non-face-to-face loan executed by an impostor using a forged identification card does not bind the person whose name was used, provided the financial institution failed to properly carry out identity verification. In Cheongju District Court, Judgment of December 4, 2025, 2024Na57532, the lender had completed four separate verification steps and still lost. On August 14, 2025, however, the Supreme Court of Korea issued two judgments on the same day reaching opposite results (2024Da236754 and 2024Da310331).

On April 11, 2023, a Korean resident discovered that a mobile phone line had been opened in their name and that several loans had been drawn against their identity. None of it had been applied for. A police report was filed the same day. Six months later the answer came back: no suspect could be identified, and the case was registered as unsolved.

The perpetrator was never found, and the lender demanded repayment on the ground that it had followed proper procedure. Litigation was the only route left. The named borrower brought an action for a declaration that the debt did not exist, and prevailed at both first instance and on appeal.

What makes this judgment notable is that the lender had not been passive. Mobile phone authentication, a joint certificate electronic signature, an ID authenticity check run against the Ministry of the Interior and Safety database, and a KRW 1 micro-deposit test — all four were completed. The court nonetheless held that the lender had failed to discharge its identity verification duty. This article explains the reasoning and sets it against recent Korean judgments that reached the opposite conclusion.

Am I liable for a loan taken out in my name?

Not if the financial institution failed to carry out the identity verification procedures required by South Korean law. In Cheongju District Court, Judgment of December 4, 2025, 2024Na57532, the court declared that neither the KRW 30 million principal nor the interest existed as a debt of the named borrower. This outcome is not automatic, however; it turns on what the lender actually did.

The starting point should be stated clearly. Even in an electronic financial transaction, if a genuine meeting of the minds is proven, legal effect follows regardless of whether the electronic document formalities were satisfied. Conversely, where the named party had no intention at all, the transaction in principle does not bind that party.

On what basis, then, does a lender demand repayment? Article 7(2)(ii) of the Framework Act on Electronic Documents and Transactions (the “Electronic Documents Act”). That provision allows a recipient to treat a manifestation of intent contained in an electronic document as the originator’s where the document “was transmitted by a person for whom the recipient had justifiable reason to believe that it was based on the intent of the originator or the originator’s agent.”

Article 7(3)(ii) supplies the counterweight. Article 7(2)(ii) does not apply where the recipient knew that the document was not the originator’s, or would have known had it exercised reasonable care or followed the procedure agreed with the originator. The case therefore turns on whether the financial institution exercised reasonable care.

The standard set by the Supreme Court of Korea

The Supreme Court of Korea has framed the test as follows: whether there was justifiable reason to believe that the electronic document was transmitted on the originator’s intent “is determined by whether the recipient properly performed identity verification procedures sufficient to support a belief that the electronic document was transmitted by the originator or the originator’s agent.” In assessing this, courts consider whether the verification procedure was appropriate given the technological standards of the time, whether the institution did all it could by way of identity verification and loss prevention in the manner prescribed by law and suited to the nature of the transaction, and the content and character of the legal act intended (Supreme Court of Korea, Judgment of August 14, 2025, 2024Da236754).

Cheongju District Court applied that standard directly. The point that is easy to miss is this: the question is not whether the formalities were met, but whether the institution actually verified identity in a manner suited to the transaction.

How did the impostor extract KRW 101 million in three days?

By building a chain of credentials, each step supplying the input for the next: a forged ID card opened a mobile line, the mobile line opened a bank account, the account produced a certificate, and the certificate drew the loan. Within roughly ten days, three institutions disbursed approximately KRW 101 million.

Date Event
Mar. 31, 2023 A mobile virtual network operator opened a prepaid mobile line using a forged copy of the victim’s resident registration card
Apr. 7, 2023 A bank opened a savings account in the victim’s name through a non-face-to-face process
Apr. 8, 2023 (Sat.) A joint certificate was issued in the victim’s name using an OTP security device
Apr. 9, 2023 (Sun.) The same bank executed a KRW 3 million revolving credit facility through an online application
Apr. 9, 2023, 2:20 p.m. A lending-focused financial institution disbursed a KRW 30 million loan at 13.7% per annum into that account
Apr. 9, 2023, 3:40–6:23 p.m. The full amount was withdrawn in more than ten transfers to accounts held by various third parties
Apr. 10, 2023 Another financial institution disbursed KRW 68 million under a separate credit agreement
Apr. 11, 2023 The victim discovered the fraud, cancelled the mobile line, and filed a police report
Oct. 26, 2023 Police registered the matter as unsolved, no suspect having been identified

Notably, more than one forged card was used. The copy submitted to the telecommunications carrier matched only the victim’s Korean name and resident registration number; the photograph and address belonged to someone else. The copy submitted to the bank and the lender matched the name, registration number, address, and photograph. The impostor had forged several cards, each tailored to its purpose.

This judgment concerns only the KRW 30 million loan. The other two were resolved separately: the creditors of the KRW 3 million and KRW 68 million loans were co-defendants at first instance, and each accepted a court recommendation for settlement confirming that the respective debt did not exist. Of the three institutions, only one litigated to judgment, and that one lost twice.

The timing also matters. The certificate was issued on a Saturday and the loan executed on a Sunday. Dispersal began 80 minutes after disbursement and the balance was gone within roughly three hours. The court treated this as grounds for suspicion that the lender should have resolved before proceeding. Seoul Central District Court took the same view in its Judgment of October 31, 2024, 2024Na28037, holding that because the transaction “was carried out unusually on a Saturday rather than a weekday, the defendant’s identity verification duty is heightened.”

Why did the Supreme Court reach opposite results on the same day?

On August 14, 2025, the Supreme Court of Korea handed down two judgments on non-face-to-face identity-theft lending. The financial institution won one (2024Da236754) and lost the other (2024Da310331). The law did not shift; the same standard produced different results on different facts.

Item Supreme Court 2024Da236754 Supreme Court 2024Da310331
Outcome Appeal dismissed — loan agreement valid Appeal dismissed — institution liable in damages
Cause of action Declaration of non-existence of debt Damages (claim amended in exchange)
Steps taken ID copy submission, existing-account verification, mobile phone authentication, joint certificate authentication, credit bureau inquiry SMS authentication and joint certificate authentication only
Mandatory methods satisfied Methods (i) and (iv) None of methods (i)–(v)

The reasoning in 2024Da236754 is the key: “whether identity verification procedures were properly performed in a non-face-to-face transaction is to be assessed not by evaluating a single means of authentication in isolation, but by considering mutually independent means of authentication in combination, and in this case the defendant bank, through multiple means of authentication including submission of a copy of the identity verification document, existing-account authentication, mobile phone authentication, joint certificate authentication, and credit information inquiry, can be assessed as having done all it could to confirm that the loan application was based on the plaintiff’s intent.”

The operative words are “mutually independent.” What counts is not the number of authentication steps but whether they originate from different sources and genuinely cross-check one another. In the Cheongju case, all four steps derived from the same forged identification card.

The institution in 2024Da310331, by contrast, performed only SMS authentication and joint certificate authentication. Both are recommended methods under the industry standard, meaning that none of the five mandatory methods was satisfied.

The lender verified identity four times — why did it still lose?

Because completing a count of steps is not the same as verifying identity. The court accepted that the lender had formally performed two of the mandatory methods and two recommended methods, yet held that it had “failed to properly take the measures, or would have known, had it exercised reasonable care, that the loan was not executed on the plaintiff’s intent.”

The regulatory structure

Three Korean statutes operate together.

First, Article 3(1) of the Act on Real Name Financial Transactions and Confidentiality (the “Real Name Act”) requires financial institutions to verify the true identity of the transacting party. For non-face-to-face transactions, the Korea Federation of Banks and the Korea Financial Investment Association jointly adopted the Specific Guidelines on Non-Face-to-Face Identity Verification (the “Verification Guidelines”), applicable to every transaction subject to the statutory duty.

Second, Article 2-4 of the Special Act on the Prevention of Loss Caused by Telecommunications-Based Financial Fraud and Refund of Loss (the “Telecom Fraud Act”) requires identity verification measures when a user applies for a loan, and imposes liability in damages where a breach causes loss. Article 2-3 of its Enforcement Decree refers the method to the Financial Services Commission, which on December 22, 2015 declared that the required method is the non-face-to-face real name verification method under the Real Name Act.

Third, Article 7 of the Electronic Documents Act converts the result into private law effect.

Suwon District Court, Judgment of April 18, 2024, 2023Na97362, states the linkage most clearly: whether an institution properly performed the required identity verification measures “is appropriately assessed by reference to the Verification Guidelines, which the Korea Federation of Banks and the Korea Financial Investment Association prepared and which the Financial Services Commission has authoritatively interpreted as the appropriate method of identity verification in non-face-to-face financial transactions.”

Seven methods, and what this lender did

The Verification Guidelines as amended effective January 1, 2020 set out seven methods and require that at least two of methods (i) through (v) be applied in combination. Methods (vi) and (vii) are recommended supplements.

Class Method In the Cheongju case
Mandatory (i) Submission of a copy of the identity verification document Performed — but the document was a copy of a forged card
Mandatory (ii) Video call or equivalent Not performed
Mandatory (iii) Verification of identification when delivering access media Not performed
Mandatory (iv) Use of an existing account (micro-transfer, etc.) Performed — but that account was itself opened by identity theft
Mandatory (v) Equivalent methods (biometric matching) Not performed
Recommended (vi) Use of verification results from other institutions Performed — joint certificate, mobile phone authentication
Recommended (vii) Verification against multiple customer data points

On paper the lender complied, and the court accepted as much. But the judgment first held that where an electronic financial transaction is conducted on a non-face-to-face basis, an institution seeking to prevent loss and escape liability must “take active measures, including performing the identity verification duty under a strict standard,” and then examined whether each of the two mandatory methods had actually functioned.

Note — method (ii) was broadened in 2024

A practical development matters here. Daegu District Court, Judgment of February 27, 2026, 2024Ga-dan137991, records that the Financial Services Commission designated facial-recognition matching of an ID photograph against a live customer photograph as an innovative financial service on May 27, 2020, extended that designation in 2022 so that the method could substitute for a video call, and that “on March 1, 2024, the existing method (ii) ‘video call’ was amended to ‘video call, etc.,’ partially amending the Verification Guidelines so that real-time remote facial recognition technology and the like may be used in place of a video call.”

Why did a forged ID card pass the government authenticity check?

Because the check validates only the name, resident registration number, and issue date. A card with a substituted photograph and address passes so long as those three fields match. The court held that the lender should therefore have reinforced its verification method.

The copy submitted matched the victim’s name, registration number, address, and photograph. Compared with the genuine card, however, four elements differed.

  • The photograph differed — it was taken from the victim’s 2013 driver’s license.
  • The address differed — it was the current address, not the address at the stated issue date.
  • The administrative district name was anachronistic — it did not exist at the stated issue date.
  • The issuing authority’s seal differed — the current seal appeared instead of the one then in use.

The authenticity check nevertheless returned a positive result, because the Government24 service validates a resident registration card on name, registration number, and issue date alone. An impostor who learns the genuine issue date may substitute the photograph and address freely.

What the courts require: the original, held by the person

This reasoning did not originate with the Cheongju judgment. Suwon District Court Seongnam Branch, Judgment of September 20, 2023, 2022Ga-dan6453, had already held that because submission of a copy substitutes for presenting an identification document at a branch counter, it “requires, to the greatest extent possible and by analogy to a face-to-face transaction, a method sufficient to establish, even indirectly, that the customer is in possession of the original identification document.” The same judgment set the required level: the institution must take “identity verification measures at a level capable of demonstrating that it endeavored to prevent financial fraud loss.”

Both judgments relied on the Ministry of the Interior and Safety’s Technical Standards and Management Criteria for ID Authenticity Verification in Non-Face-to-Face Identity Verification, which presumes that a copy must be photographed directly by the person, from the original, and provides that “a financial institution may require the customer to submit a photograph of the customer’s upper body holding the customer’s own identification document.”

In the Cheongju case, what was submitted was a rephotographed or scanned copy of a forged card. The court held that where an institution cannot be technically certain that the original was photographed, it “should have reinforced its identity verification method, for example by requiring the identification document to be photographed with the customer’s face directly visible, or by additionally requiring method (ii), the video call, under the Verification Guidelines,” adding in parentheses: “such measures are not technically difficult.”

Institutions that actually checked the face have won

The contrast is borne out. The institution in Daegu District Court 2024Ga-dan137991 performed mobile phone authentication, driver’s license submission and authenticity verification, and real-time capture of the customer’s face matched against the license photograph by facial recognition. The court treated this as mandatory methods (i) and (ii) plus recommended method (vi), found the performance adequate, and dismissed the claim.

Daegu High Court, Judgment of November 18, 2025, 2025Na10683, reached the same result, holding that “the non-face-to-face real name verification procedures performed by the defendant can be found to have been appropriate to the extent of confirming that the application to open the deposit account was transmitted by the plaintiff or the plaintiff’s agent.” That case is factually different, however: the named party had voluntarily handed over their own mobile phone and driver’s license to a workplace colleague.

The practical lesson is plain. A positive authenticity check does not, by itself, discharge the duty. Whatever the system does not examine must be examined by a person or by another procedure.

Why did the KRW 1 micro-deposit test fail as identity verification?

Because the account itself had been opened two days earlier by the same impostor. This point, however, is one on which Korean lower courts disagree.

The micro-deposit test is widely used: the institution transfers a nominal sum to the customer’s existing account together with a code, and the customer enters the code. It corresponds to method (iv), use of an existing account, and is intended to confirm that the customer has authority over an account already opened at another institution.

Cheongju District Court reasoned that, unlike method (ii) or method (iii), this method does not directly confirm that the person acting is the named party, so compliance must be assessed more strictly to ensure that the actor and the named party are the same person.

A judgment pointing the other way

Seoul Western District Court, Judgment of June 14, 2024, 2023Na43126, construed the term the opposite way. Rejecting the argument that an account opened by an impostor immediately before the loan cannot be an “existing account,” the court held: “on its wording, an ‘existing account’ means an account already in existence prior to the application for the non-face-to-face electronic financial transaction, and there is no objective and reasonable basis for construing it as further requiring, by reference to a period counted back from the application date, that the account was opened some time ago and has an actual transaction history. In practice a financial institution cannot readily ascertain the opening date of an account held at another institution or whether it is in actual use, and there is no material or circumstance supporting a duty to do so.”

The position, then, is this: whether a newly opened account qualifies is genuinely contestable, and the Seoul Western District Court reading has textual support. Cheongju District Court reached a different result because it did not decide the case on that single issue. A customer with no transaction history, an account two days old, a certificate issued on a Saturday, and a large application on a Sunday combined, and the court held that in such circumstances the lender needed to “resolve the grounds for suspicion in the transaction, for example by requiring additional authentication procedures capable of confirming that the online loan applicant was the plaintiff in person.”

The credential chain

Set out in sequence, the structure shows why independence mattered.

  • Forged ID card opens a prepaid mobile line → mobile authentication credential obtained
  • Forged ID card plus mobile line opens a bank account → existing-account credential obtained
  • That account’s OTP issues a joint certificate → electronic signature credential obtained
  • All three combine in the loan application → four verification steps passed

The four checks were not independent verifications but outputs derived from the same forged document. Since the purpose of requiring combined application is that each method compensate for the weaknesses of the others, adding steps produces no compensating effect in this structure.

Does a joint certificate signature prove that I signed?

No. The wholesale amendment of the Digital Signature Act on June 9, 2020 abolished the accredited certificate regime, and the joint certificate that replaced it carries no presumption as to the authenticity of identity or the integrity of the electronic document.

Many people recall the proposition that a signature made with an accredited certificate is presumed to be the person’s own. That proposition rests on Supreme Court of Korea, Judgment of March 29, 2018, 2017Da257395: “an electronic document transmitted by a person whose identity has been confirmed by an accredited certificate issued by an accredited certification authority is, absent special circumstances, to be regarded as falling within the case prescribed in Article 7(2)(ii) of the Electronic Documents Act, namely ‘where the electronic document received was transmitted by a person for whom the recipient had justifiable reason to believe, by reason of the relationship with the originator or the originator’s agent, that it was based on the intent of the originator or the originator’s agent.’ Accordingly, in such a case the recipient of the electronic document may, without additional identity verification procedures such as a telephone call or an interview, treat the manifestation of intent contained in the electronic document as the originator’s and perform a legal act.”

That judgment does not carry over to cases under the current statute

Seoul Central District Court, Judgment of April 11, 2023, 2021Ga-dan5243198, addressed the point directly, holding that the earlier judgment’s reasoning “may apply only to cases governed by the former Digital Signature Act, and can no longer apply to cases governed by the new Digital Signature Act.” It added that even under the former statute the reasoning is displaced where special circumstances exist, or where the institution would have known, on reasonable care, that the signature was made by an impostor.

Cheongju District Court is to the same effect. The lender had merely “mechanically completed identity authentication through a joint certificate rather than an accredited certificate,” and “unlike the former accredited certificate, for which the authenticity of identity and the integrity of the electronic document were presumed and recognized in respect of an accredited electronic signature, the joint certificate introduced by the wholesale amendment of the Digital Signature Act on June 9, 2020 is recognized only as having the effect of a signature, a signature and seal, or a name and seal in respect of the electronic signature.”

The strongest formulation appears in Seoul Central District Court 2024Na28037, which pointed to “the fact that the joint certificate that emerged after the abolition of the accredited certificate under the former Digital Signature Act does not even possess an identity verification function, and the fact that the Verification Guidelines likewise prescribe SMS authentication and joint certificate authentication as recommended measures to be performed in addition to the mandatory methods (i) through (v).”

Item Former accredited certificate Current joint certificate
Basis Accredited electronic signature under the former Digital Signature Act Digital Signature Act as wholly amended June 9, 2020
Authenticity of identity Presumed Not presumed
Integrity of the document Presumed Not presumed
Effect recognized Including the above presumptions Effect of a signature, signature and seal, or name and seal
Status under the Verification Guidelines Recommended method (vi), not a mandatory method

The implications reach beyond banking disputes. Foreign-invested companies operating in the Incheon Free Economic Zone (IFEZ) — across Songdo International Business District, Cheongna International City, and Yeongjong International City — that execute contracts electronically in Korea should not assume that a joint certificate signature carries a presumption of due execution. Alongside the certificate signature it is prudent to retain separate evidence that the signatory was in fact that person: video confirmation, an upper-body photograph, a face-to-face verification step, and preserved logs.

If the contract stands, do I recover nothing?

Not at all. Even where the contract binds the named party, damages remain available under Article 2-4(2) of the Telecom Fraud Act. In the Seoul Central District Court line of cases the claimant recovered 50% of the loan amount, confirmed by the Supreme Court of Korea on August 14, 2025. The route there was not straightforward.

The construction adopted in Cheongju District Court 2024Na57532 — that the contract has no effect as against the named party — is not always accepted. In Supreme Court 2024Da236754 the contract was held valid. Where that happens, damages are what remain.

Five stages over four years

Stage Judgment Outcome
First instance Seoul Central District Court, Apr. 11, 2023, 2021Ga-dan5243198 Loan agreement valid → but debt declared not to exist beyond 50% of the loan amount, reflecting the institution’s liability; remainder of claim dismissed
Appeal Seoul Central District Court, Dec. 14, 2023, 2023Na21565 Defendant’s appeal dismissed
Supreme Court Supreme Court of Korea, May 30, 2024, 2024Da202188 Reversed and remanded ex officio — a policy loan is not a loan for consumption, so there was no interest in seeking a declaration
On remand Seoul Central District Court, Oct. 31, 2024, 2024Na28037 Claim amended in exchange to damages of KRW 25 million → granted in full
Second appeal Supreme Court of Korea, Aug. 14, 2025, 2024Da310331 Appeal dismissed — final

Why the first instance held the contract valid

A point easily misread: the first instance judgment did not favor the named party on the principal issue. The primary claim was that the loan agreement was void, and the court rejected it.

The decisive reason was that the transaction fell outside the Real Name Act. A policy loan forms one contract together with the insurance policy rather than a separate one, has the character of an advance on the surrender value, and the underlying insurance contract had already been concluded through real name verification; the Korea Federation of Banks’ guidance likewise excludes insurance transactions from real name transactions. On that basis the court held that “the policy loan transaction in this case is difficult to regard as subject to the Real Name Act.”

The analysis then split in two. “Even if the defendant failed properly to perform the identity verification measures required by the Electronic Financial Transactions Act or the Telecom Fraud Act, so long as it went through SMS authentication using the plaintiff’s own mobile phone and identity verification through the joint certificate,” the agreement fell within Article 7(2)(ii) and its effect attached to the named party. The contract was valid; the verification breach was handled separately as a question of damages.

This is where the case diverges from Cheongju District Court 2024Na57532, which concerned an unsecured loan by a lending-focused financial institution. That transaction was subject to the Real Name Act, and breach of the verification duty went directly to the validity of the contract.

The 50% reduction was comparative fault, not set-off

How, then, did a valid debt halve? The judgment records neither a set-off defense nor a counterclaim. The court treated the very existence of the loan debt as the named party’s loss, and then applied comparative fault.

The connecting passage reads: “so long as the effect of the policy loan agreement attaches to the plaintiff, if the plaintiff does not repay the policy loan, then when an insured event later occurs or the policy is terminated and a surrender value arises, the loan principal and interest are deducted from the insurance proceeds or surrender value, and therefore the principal and interest of this policy loan all devolve upon the plaintiff as loss.”

With the loss fixed at the full loan amount, what remained was limitation of liability. The court weighed three matters against the named party: that the fraud succeeded because the victim, deceived by the impostor, “did not merely provide personal information voluntarily but went so far as to install TeamViewer, a remote control program, on the plaintiff’s mobile phone”; that the victim, a 51-year-old who had worked for roughly 30 years, could sufficiently have recognized the prevalence of voice phishing in Korea; and that a loan notification message was received and read without timely action being taken. On that basis the court held that “the defendant’s liability in damages arising from this policy loan is appropriately limited to 50% of the loan amount.”

KRW 50m
Valid loan debt
(contract upheld)
KRW 25m
Institution’s liability
(after 50% comparative fault)
=
KRW 25m
Debt actually remaining
(half the claim dismissed)

The named party sought a declaration as to the whole KRW 50 million, obtained it as to half, and bore one half of the costs. It was a win, but only half a win.

The Supreme Court’s first reversal turned on the form of the action rather than on the verification duty: “the economic substance of a policy loan is to be regarded as an advance payment of insurance proceeds or surrender value that the insurer will later be obliged to pay. Although the policy uses the term ‘loan,’ this differs from an ordinary loan and does not have the legal character of a loan for consumption” (Supreme Court of Korea, Judgment of May 30, 2024, 2024Da202188). On remand the claim was amended in exchange from a declaration of non-existence of debt to damages, and KRW 25 million was awarded. Dismissing the second appeal, the Supreme Court held that “the conclusion of the court below, which found the defendant liable in damages on the ground that it had failed properly to perform the identity verification measures prescribed by the Telecom Fraud Act, is acceptable.”

Three points deserve note.

First, the verification duty applies even outside the Real Name Act. A policy loan is not a financial transaction under the Real Name Act, yet the court held that “the Electronic Financial Transactions Act or the Telecom Fraud Act differ in purpose and legislative intent from those of the Real Name Act, and therefore it cannot be said that the identity verification duty or the duty to prevent telecommunications-based financial fraud required by the Electronic Financial Transactions Act or the Telecom Fraud Act is inapplicable or exempted merely because there is no identity verification duty under the Real Name Act.”

Second, the form of the action drives the outcome. This claimant won twice on a declaration, was reversed by the Supreme Court, and then secured a final judgment by reframing the claim as damages. Which cause of action to pursue must be settled when proceedings are commenced.

Third, comparative fault applies. Unlike the invalidity route, the damages route absorbs the claimant’s own fault in full. Installing a remote control program cut recovery in half here. Where the contract itself is held ineffective, as in Cheongju, no question of comparative fault arises and the debt disappears entirely.

Why did the apparent-authority defense fail?

Because no basic authority existed and there was no justifiable ground. The Supreme Court of Korea restated this doctrine in June 2025.

The lender argued apparent authority in the alternative: the photograph on the submitted card was genuinely the named party’s, the address matched the named party’s current residence, and the bank account had been opened using another account in the named party’s name — none of which, it said, would be possible unless the named party had supplied personal information and completed authentication steps. Authority, or at least basic authority, must therefore have existed.

Name-impersonation ordinarily defeats apparent authority

The starting point is long settled. In Supreme Court of Korea, Judgment of June 28, 2002, 2001Da49814 — a case in which a forged resident registration card bearing the impostor’s photograph was used to obtain a loan — the Court held that “where a person, by artifice, does not indicate that the act is done as agent but merely impersonates the principal’s name and, deceiving the counterparty into believing that the person is the principal, performs a legal act directly in the principal’s name, apparent authority under that provision cannot, absent special circumstances, be established.”

The Supreme Court clarified the narrow exception in 2025: apparent authority under Article 126 of the Civil Act applies by analogy “only where the person impersonating the principal had basic authority to act for the principal and the counterparty had justifiable grounds to believe that the impersonator was exercising the principal’s authority as the principal” (Supreme Court of Korea, Judgment of June 5, 2025, 2023Da232526).

The same judgment set a heavier standard for financial institutions: taking into account “the fact that a financial institution owes a higher duty of care than an ordinary person with respect to verification of the principal and of authority in financial transactions,” even where a loan solicitor exploits an entrustment relationship to impersonate another and the institution is unaware, justifiable grounds are not readily to be found.

The court’s findings

On basic authority. Absent any material indicating that the named party had supplied personal details or information to the impostor, the grounds advanced by the lender were insufficient to establish basic authority.

On justifiable grounds. The court weighed three matters: that the impostor forged several resident registration cards and used them to open a mobile line, open an account, and apply for multiple loans; that the lender had mechanically completed authentication through a joint certificate rather than an accredited certificate; and that it could not be found to have discharged its verification duty in that process.

In short, the finding that the verification duty was not discharged also defeats the justifiable grounds required for apparent authority. For a financial institution the two lines of defense stand or fall together.

What should a victim of identity theft do first?

Two things at once: stop the loss spreading, and preserve evidence. The named party here cancelled the prepaid line and filed a police report on the day of discovery, and that report became the factual backbone of the later litigation.

1. Cut off the compromised credentials immediately

Identify and cancel any mobile line opened, account established, or certificate issued through the identity theft. The loan succeeded here because line, account, and certificate were chained together; breaking one link disables the authentications built on top of it.

2. File a police report and obtain the receipt

The report matters even if no suspect is found. Police here registered the case as unsolved six months later, yet the named party used that notice and the investigation record to establish that the loan had not been applied for.

3. Establish the full scope of the loss

Identity theft rarely stops at one transaction; three institutions disbursed loans here. Review every account, mobile line, and loan in your name through the integrated account information service and the carriers’ identity-theft inquiry services.

4. Object to the institution, but avoid acknowledging the debt

Partial payment or an application to defer repayment may be construed as acknowledgment. Where the matter will be litigated, it is better to record in writing from the outset that the contract was not concluded by you.

5. Choose the cause of action, then commence proceedings

There are two routes: a declaration that the debt does not exist, which contests the validity of the contract, and damages under Article 2-4(2) of the Telecom Fraud Act, which accepts validity. Which is preferable depends on the verification steps the institution actually took and on the legal character of the transaction. Note also that the second route is subject to comparative fault.

6. Obtain the institution’s verification records in documentary form

The decisive issue in litigation is what identity verification the institution performed and how. Orders for production of financial transaction information and factual inquiries to telecommunications carriers are the means of obtaining the authentication records and the submitted ID copy. In the Cheongju case, the results of the first instance court’s production order and carrier inquiry were among the grounds of the findings.

The outcome of an identity theft case usually turns not on proving that you did not do it, but on proving that the other side did not properly check.

What should financial institutions and companies strengthen?

The points identified in these judgments form a checklist. What matters is not the number of authentication methods but whether each functions as an independent check.

1. Confirm that the checks are mutually independent

As the Supreme Court put it, mutually independent means of authentication must be capable of being considered in combination. If the ID copy and the existing account both derive from the same forged document, no compensating effect arises. Whether the sources diverge should be tested at the design stage.

2. Actually perform two or more of mandatory methods (i)–(v)

SMS authentication plus a joint certificate is not enough; both are recommended method (vi). That is precisely why the institution in Supreme Court 2024Da310331 lost.

3. Build in a step that assures the original was photographed

Operate at least one of the following, if only conditionally: an upper-body photograph holding the ID, forced live capture, or a video call. Since the March 1, 2024 amendment permits real-time remote facial recognition in place of a video call, operational burden is a weaker justification for deferral. The Cheongju court’s remark that “such measures are not technically difficult” should be taken seriously.

4. Have a person review what the authenticity system does not

The Government24 check examines name, registration number, and issue date. The photograph, the address, the chronological consistency of the district name, and the seal are outside its scope. Without a separate review of those elements, a forgery passes.

5. Require additional authentication where grounds for suspicion exist

A new customer with no transaction history, a freshly opened account, and certificate issuance or a large application at the weekend or at night together constitute suspicion. Courts treat the verification duty as heightened for weekend transactions.

6. Review irrespective of whether the Real Name Act applies

Products outside the Real Name Act, such as policy loans, remain subject to the verification duty under the Telecom Fraud Act. Lowering the standard because a product falls outside the Real Name Act leaves liability in damages intact.

7. Revisit the evidentiary assumptions behind electronic signatures

A joint certificate carries no presumption as to authenticity of identity or integrity. Companies operating electronic contracting in South Korea — including foreign-invested companies in Songdo International Business District, Cheongna International City, and Yeongjong International City — should ensure their procedures capture evidence of the signatory’s identity alongside the certificate signature.

Frequently Asked Questions

Q. A loan was taken out in my name in South Korea. Do I have to repay it?

A. Not if the financial institution failed properly to perform identity verification. Cheongju District Court, Judgment of December 4, 2025, 2024Na57532, declared that neither the KRW 30 million principal nor the interest existed as a debt where an impostor had used a forged resident registration card. Where the institution did follow proper procedure, however, the contract has been upheld (Supreme Court of Korea, Judgment of August 14, 2025, 2024Da236754), so the first step is to establish what the institution actually did.

Q. Can I win if the perpetrator is never caught?

A. Yes. Korean police registered this matter as unsolved in October 2023, no suspect having been identified, yet the named party prevailed at first instance and on appeal. Civil proceedings determine not the punishment of the perpetrator but whether the financial institution exercised reasonable care.

Q. The Supreme Court issued opposite judgments on the same day. Which one governs?

A. Both are good law and they do not conflict. In Supreme Court of Korea, Judgment of August 14, 2025, 2024Da236754, the institution had performed multiple independent authentications — ID copy submission, existing-account verification, mobile phone authentication, joint certificate authentication, and a credit bureau inquiry — and the contract was upheld. In 2024Da310331, decided the same day, the institution had performed only SMS authentication and joint certificate authentication, and was held liable in damages for breach of the verification duty. What separated them was performance, not doctrine.

Q. The lender says it verified identity several times. Can the loan still be challenged?

A. A count of steps is not sufficient. The Supreme Court held that whether identity verification was properly performed “is to be assessed not by evaluating a single means of authentication in isolation, but by considering mutually independent means of authentication in combination” (Supreme Court of Korea, Judgment of August 14, 2025, 2024Da236754). Where every authentication derives from the same forged document, the methods cannot compensate for one another.

Q. The forged ID passed the government authenticity check. Is the institution still liable?

A. It may be. South Korea’s Government24 authenticity check validates only the name, resident registration number, and issue date, so a card with a substituted photograph and address passes. Cheongju District Court held that because the photograph on the submitted copy differed markedly from that on the genuine card, and given the form and content of the forgery, it did not appear that detecting the forgery was altogether impossible; a positive authenticity check alone therefore did not establish proper performance.

Q. Is a copy of the ID enough, or is facial confirmation required?

A. Because submission of a copy substitutes for presenting an ID at a branch counter, a method sufficient to establish, even indirectly, that the customer holds the original is required (Suwon District Court Seongnam Branch, Judgment of September 20, 2023, 2022Ga-dan6453). An institution that captured the customer’s face in real time and matched it against the ID photograph by facial recognition was found to have performed adequately (Daegu District Court, Judgment of February 27, 2026, 2024Ga-dan137991). Since March 1, 2024, real-time remote facial recognition may substitute for a video call.

Q. Is the KRW 1 micro-deposit test not accepted as identity verification?

A. It is an accepted method, but it did not function here because the account had been opened two days earlier by the same impostor. Korean lower courts differ on this point. Seoul Western District Court, Judgment of June 14, 2024, 2023Na43126, held that “on its wording, an ‘existing account’ means an account already in existence prior to the application for the non-face-to-face electronic financial transaction,” disregarding the opening date. Cheongju District Court reached a different result because the absence of transaction history, weekend certificate issuance, and a large application combined as grounds for suspicion.

Q. If a joint certificate was used to sign, am I presumed to have signed?

A. No. The joint certificate introduced by the wholesale amendment of the Digital Signature Act on June 9, 2020 is recognized only as having the effect of a signature, a signature and seal, or a name and seal, unlike the former accredited certificate for which authenticity of identity and integrity of the document were presumed. Seoul Central District Court, Judgment of October 31, 2024, 2024Na28037, went so far as to state that the joint certificate “does not even possess an identity verification function.”

Q. Can the 2018 Supreme Court judgment on accredited certificates still be relied on?

A. Not for cases governed by the current statute. Supreme Court of Korea, Judgment of March 29, 2018, 2017Da257395, held that an electronic document transmitted by a person whose identity was confirmed by an accredited certificate could be treated as the originator’s without additional verification. Seoul Central District Court, Judgment of April 11, 2023, 2021Ga-dan5243198, stated that that reasoning “may apply only to cases governed by the former Digital Signature Act, and can no longer apply to cases governed by the new Digital Signature Act.”

Q. If the contract is upheld, can I recover nothing?

A. Damages remain available. Article 2-4(2) of the Telecom Fraud Act imposes liability where a failure to perform identity verification measures causes loss to the user. Seoul Central District Court, Judgment of October 31, 2024, 2024Na28037, awarded KRW 25 million, being 50% of a KRW 50 million loan, and the award was confirmed by Supreme Court of Korea, Judgment of August 14, 2025, 2024Da310331. Comparative fault may prevent full recovery.

Q. Does “the effect attaches to the named party” mean the contract is valid?

A. Yes — the named party owes the loan debt, and the primary claim of invalidity was rejected. Seoul Central District Court, Judgment of April 11, 2023, 2021Ga-dan5243198, held that a policy loan is not subject to the Real Name Act, so that even if the institution had failed properly to perform identity verification measures, the effect attached to the named party under Article 7(2)(ii) of the Electronic Documents Act because SMS and joint certificate authentication had been completed. The verification breach was addressed separately as a matter of damages.

Q. If the contract is valid, why did the debt halve? Was it a set-off?

A. No set-off defense or counterclaim appears in the judgment. The court held that, the effect of the agreement having attached to the named party, non-repayment would cause the principal and interest to be deducted from future insurance proceeds or surrender value, so that “the principal and interest of this policy loan all devolve upon the plaintiff as loss.” Treating the debt itself as the loss, the court applied comparative fault to limit the institution’s liability to 50% and expressed the result in the form of a declaration. The named party sought a declaration as to the whole KRW 50 million, obtained it as to half, and bore one half of the costs.

Q. What happens if the institution pleads apparent authority?

A. Name-impersonation ordinarily defeats apparent authority. The Supreme Court of Korea has held that where a person merely impersonates the principal’s name and performs a legal act directly in that name, apparent authority cannot, absent special circumstances, be established (Judgment of June 28, 2002, 2001Da49814), and that the doctrine applies by analogy only where the impersonator had basic authority and the counterparty had justifiable grounds (Judgment of June 5, 2025, 2023Da232526). The latter judgment also confirmed that a financial institution owes a higher duty of care than an ordinary person as to verification of the principal and of authority.

Q. What should a victim of identity theft in South Korea do first?

A. Cancel the compromised mobile line, account, and certificate immediately to break the credential chain, and file a police report to create a record. Then review every account, mobile line, and loan in your name to establish the scope of the loss, and avoid conduct that may be construed as acknowledging the debt. In litigation, orders for production of financial transaction information and factual inquiries to telecommunications carriers are essential to obtain the institution’s authentication records and the submitted ID copy, and the choice between a declaration of non-existence of debt and a damages claim must be made when proceedings are commenced.

In non-face-to-face banking disputes the outcome turns not on how many procedures were completed, but on what those procedures actually verified. That is why the Supreme Court of Korea reached opposite conclusions on the same day. For anyone whose identity has been used, the starting point is to establish in documentary form what the financial institution checked and what it did not.

Soyoung Park, Representative Attorney — Atlas Legal

Soyoung Park | Representative Attorney
Family Law, Inheritance, Construction & Real Estate Disputes
Judicial Research and Training Institute, 33rd Class
Korea University, Department of Law
Atlas Legal | Incheon Songdo, South Korea

Visit Atlas Legal Homepage →

Similar Posts