{"id":1953,"date":"2026-09-02T08:08:38","date_gmt":"2026-09-02T08:08:38","guid":{"rendered":"https:\/\/atlaw.kr\/en-blog\/voice-phishing-bank-liability-south-korea\/"},"modified":"2026-09-02T08:09:20","modified_gmt":"2026-09-02T08:09:20","slug":"voice-phishing-bank-liability-south-korea","status":"publish","type":"post","link":"https:\/\/atlaw.kr\/en-blog\/voice-phishing-bank-liability-south-korea\/","title":{"rendered":"KRW 2.1 Billion Left in Five Days \u2014 Why the Bank Owed Nothing"},"content":{"rendered":"<p><!--  -->\n\n\n\n<!--  --><\/p>\n<p><!-- ATLAS_SEO_BLOCK_START --><br \/>\n<script type=\"application\/ld+json\">{\"@context\":\"https:\/\/schema.org\",\"@type\":\"Article\",\"@id\":\"https:\/\/atlaw.kr\/en-blog\/voice-phishing-bank-liability-south-korea\/#article\",\"mainEntityOfPage\":{\"@type\":\"WebPage\",\"@id\":\"https:\/\/atlaw.kr\/en-blog\/voice-phishing-bank-liability-south-korea\/#webpage\"},\"headline\":\"KRW 2.1 Billion Left in Five Days \u2014 Why the Bank Owed Nothing\",\"description\":\"How far does a Korean bank's liability extend when a deceived customer transfers the money personally? The Seoul Southern District Court in 2025Gahap100965 dismissed a KRW 2 billion claim while setting out the two circumstances in which a bank breaches its temporary measure duty.\",\"datePublished\":\"2026-09-02T09:00:00+09:00\",\"dateModified\":\"2026-09-02T09:00:00+09:00\",\"inLanguage\":\"en-US\",\"author\":{\"@type\":\"Person\",\"@id\":\"https:\/\/atlaw.kr\/soyoung-park\/#person\",\"name\":\"Soyoung Park\",\"alternateName\":\"\ubc15\uc18c\uc601\",\"jobTitle\":\"Representative Attorney\",\"worksFor\":{\"@id\":\"https:\/\/atlaw.kr\/#legalservice\"}},\"publisher\":{\"@type\":\"LegalService\",\"@id\":\"https:\/\/atlaw.kr\/#legalservice\",\"name\":\"Atlas Legal\",\"url\":\"https:\/\/atlaw.kr\"},\"about\":[\"Voice phishing victim's damages claim against a bank in South Korea\",\"Scope of the duty to ensure safety under Article 21 of the Electronic Financial Transactions Act\",\"Meaning of identity verification measures under the Telecommunications Fraud Refund Act\",\"Standard for breach of the temporary measure duty under Article 2-5\",\"Reasonableness and social acceptability of a bank's fraud detection criteria\",\"Suspicious transaction detection systems in Korean banking\",\"Transfers made after a temporary measure is lifted\",\"Distinguishing impersonation fraud from identity theft loans in South Korea\",\"Statutory refunds and deduction from recoverable loss\",\"Seoul Southern District Court 2025Gahap100965\"]}<\/script><br \/>\n<script type=\"application\/ld+json\">{\"@context\":\"https:\/\/schema.org\",\"@type\":\"FAQPage\",\"@id\":\"https:\/\/atlaw.kr\/en-blog\/voice-phishing-bank-liability-south-korea\/#faqpage\",\"inLanguage\":\"en-US\",\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"Can I recover from a Korean bank money I transferred in a voice phishing scam?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"It is difficult but not impossible. In case 2025Gahap100965, decided on 10 June 2026, the Seoul Southern District Court dismissed in full the claim of a victim who had transferred KRW 2.137 billion, because a customer who transfers personally cannot readily rely on Article 21 of the Electronic Financial Transactions Act or Article 2-4 of the Telecommunications Fraud Refund Act. The same judgment nonetheless held that a bank breaches its temporary measure duty where it fails to follow its own self-inspection criteria, or where those criteria are themselves manifestly unreasonable. This is a first instance judgment and its finality has not been confirmed.\"}},{\"@type\":\"Question\",\"name\":\"Can I rely on the duty to ensure safety under Article 21?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Not where you were deceived into transferring the money yourself. The court held that Article 21(1) imposes a duty to prevent errors or electronic intrusions arising in the course of electronic financial transactions. An \\\"error\\\" means a case where, without the user's intent or negligence, a transaction is not executed as contracted or instructed; a transfer executed exactly as instructed is not an error. Separate facts amounting to forgery or alteration of an access medium, or intrusion into an information and communications network, are required.\"}},{\"@type\":\"Question\",\"name\":\"Should the bank employee have probed the circumstances of the deposit termination?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"There is no legal duty to do so. The court held that the identity verification measure under Article 2-4(1) does not extend to confirming whether the customer is transacting with genuine intent. The measure is limited to confirming that the person who concluded the contract and the person using the transaction are the same, and does not include confirming whether the customer is acting entirely on their own judgment, free from improper external interference.\"}},{\"@type\":\"Question\",\"name\":\"Is identity verification mandatory when terminating a deposit in South Korea?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Yes. Article 2-4(1) of the Telecommunications Fraud Refund Act requires an identity verification measure where a user applies for a loan or terminates a savings deposit, instalment savings or similar product, and Article 2-4(2) imposes liability for resulting loss. Article 2-3(1) of the Enforcement Decree permits use of the registered telephone, face-to-face confirmation, or another method recognised by the Financial Services Commission. Here face-to-face confirmation at the branch satisfied the procedural requirement.\"}},{\"@type\":\"Question\",\"name\":\"If the bank detects an abnormal transaction but does not block it, is it liable?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Detection alone does not create liability. While a financial institution has discretion in setting its self-inspection criteria and methods, the court held that those criteria, and the decision whether to impose a temporary measure following self-inspection, must objectively possess reasonableness, appropriateness and social acceptability. Liability arises where the criteria are manifestly unreasonable, or where the institution failed to operate in accordance with them.\"}},{\"@type\":\"Question\",\"name\":\"Precisely when does a bank breach the temporary measure duty?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"The court identified two situations. First, where the institution failed properly to carry out self-inspection in accordance with the criteria and methods it had established for detecting abnormal transactions. Second, where it carried out self-inspection properly but those criteria and methods were deficient, being objectively so manifestly lacking in reasonableness and appropriateness that social acceptability cannot be recognised. In either case the breach lies in failing to impose a temporary measure despite circumstances warranting the inference that the account was being used as a suspicious transaction account, and this covers both failure to recognise those circumstances and recognising them without acting.\"}},{\"@type\":\"Question\",\"name\":\"What criteria does a Korean bank's FDS use to screen transactions?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"According to the judgment, this bank operated 101 detection scenarios: 51 from the FDS operating guidelines issued by the Financial Supervisory Service and the Financial Security Institute, plus 50 developed in-house. Transactions are classified using factors such as the transaction period, number of deposits and withdrawals, customer particulars, time of transfer, deposit amount, prior transaction frequency, withdrawal amounts, repetition and access IP address. Medium-risk transactions attract a warning text message only; high-risk transactions are blocked and released after telephone identity verification.\"}},{\"@type\":\"Question\",\"name\":\"The transfer was detected before it completed. Was failing to stop it unlawful?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Not in this case. The transaction was detected at 10:41 and the KRW 50 million transfer completed at 11:20, but the transaction fell within the \\\"large-value transfer immediately following certificate issuance\\\" type, which was medium risk under the bank's criteria. The court held that the mere fact of a large transaction following certificate issuance cannot by itself establish a situation in which telecommunications fraud is to be apprehended, and that the later discovery of fraud did not render the grading manifestly unreasonable.\"}},{\"@type\":\"Question\",\"name\":\"How should transfers made after a hold is lifted be challenged?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Through Article 2-5(1) rather than Article 2-5(3). The court held that because Article 2-5(3) expressly makes release turn on the result of the identity verification measure, no additional duty to take other effective steps to detect fraud before release can be implied. A claim concerning the period after release must therefore be framed as a breach of the temporary measure duty, on the basis that no self-inspection criteria covered that period or that the criteria were deficient.\"}},{\"@type\":\"Question\",\"name\":\"How does this differ from an identity theft loan case?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"It turns on who operated the account. Where a third party used the victim's identity, the issue is whether the institution properly performed identity verification, and the principal tools are the \\\"justifiable reason\\\" test under Article 7(2)2 of the Framework Act on Electronic Documents and a declaration of non-existence of debt. Where the customer was deceived into transferring personally, neither that Act nor Article 21 of the Electronic Financial Transactions Act applies, and the temporary measure duty under Article 2-5 is in practice the only route.\"}},{\"@type\":\"Question\",\"name\":\"How does a statutory refund affect the damages claim?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"It is deducted. Having transferred KRW 2.137 billion, this claimant received refunds totalling KRW 99,307,589 between March and June 2025 under Article 10(1) of the Telecommunications Fraud Refund Act, and claimed the balance of KRW 2,037,692,410. Because the refund is funded from the frozen balance, the speed of reporting determines the amount recovered.\"}},{\"@type\":\"Question\",\"name\":\"Is this judgment final?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"No. It is a first instance judgment handed down by the 12th Civil Division of the Seoul Southern District Court on 10 June 2026, and any appeal or appellate ruling has not been confirmed. It is nonetheless of considerable practical value because judgments setting out the standard for breach of the temporary measure duty directly are rare. Any application to a particular case should be checked against the subsequent procedural history.\"}}]}<\/script><br \/>\n<script type=\"application\/ld+json\">{\"@context\":\"https:\/\/schema.org\",\"@type\":[\"LegalService\",\"LocalBusiness\"],\"@id\":\"https:\/\/atlaw.kr\/#legalservice\",\"name\":\"Atlas Legal\",\"alternateName\":[\"\ubc95\ubb34\ubc95\uc778 \uc544\ud2c0\ub77c\uc2a4\",\"Atlas Law Firm\"],\"url\":\"https:\/\/atlaw.kr\/en\/home-en\/\",\"telephone\":\"+82-32-864-8300\",\"email\":\"info@atlaw.kr\",\"priceRange\":\"$$$\",\"address\":{\"@type\":\"PostalAddress\",\"streetAddress\":\"B-2901, 323 Incheon Tower-daero\",\"addressLocality\":\"Yeonsu-gu, Incheon\",\"addressRegion\":\"Incheon Metropolitan City\",\"postalCode\":\"22007\",\"addressCountry\":\"KR\"},\"geo\":{\"@type\":\"GeoCoordinates\",\"latitude\":37.399438,\"longitude\":126.629812},\"openingHoursSpecification\":[{\"@type\":\"OpeningHoursSpecification\",\"dayOfWeek\":[\"Monday\",\"Tuesday\",\"Wednesday\",\"Thursday\",\"Friday\"],\"opens\":\"09:00\",\"closes\":\"18:00\"}],\"areaServed\":[{\"@type\":\"Country\",\"name\":\"South Korea\"},{\"@type\":\"Place\",\"name\":\"Songdo International Business District\"},{\"@type\":\"Place\",\"name\":\"Cheongna International City\"},{\"@type\":\"Place\",\"name\":\"Yeongjong International City\"},{\"@type\":\"Place\",\"name\":\"Incheon\"},{\"@type\":\"Place\",\"name\":\"Seoul Metropolitan Area\"},{\"@type\":\"Place\",\"name\":\"Incheon Free Economic Zone (IFEZ)\"}],\"knowsAbout\":[\"Voice Phishing Bank Liability in South Korea\",\"Electronic Financial Transactions Act Article 21 Duty to Ensure Safety\",\"Telecommunications Fraud Refund Act Identity Verification Measures\",\"Temporary Measures on User Accounts under Korean Financial Fraud Law\",\"Fraud Detection Systems and Suspicious Transaction Detection in Korean Banking\",\"Financial Institution Liability for Telecommunications-Based Financial Fraud\",\"Korean Civil Act Article 750 Tort Liability\"],\"serviceType\":[\"Financial Services Litigation\",\"Banking and Electronic Finance Disputes\",\"Civil Litigation in South Korea\",\"Regulatory Compliance Advisory\",\"Corporate Legal Advisory\"]}<\/script><br \/>\n<!-- ATLAS_SEO_BLOCK_END --><\/p>\n<style>@import url('https:\/\/cdn.jsdelivr.net\/gh\/orioncactus\/pretendard@v1.3.9\/dist\/web\/static\/pretendard.css'); \/* \u2500\u2500 Kadence \ud14c\ub9c8 \ucee8\ud150\uce20 \ud3ed override \u2500\u2500 *\/ :root { --global-content-narrow-width: 1290px !important; } .entry-content-wrap { max-width: 1290px !important; } .entry-content { margin-top: 0 !important; } *, *::before, *::after { box-sizing: border-box; margin: 0; padding: 0; } :root { --navy: #0a2540; --navy2: #1a3353; --wine: #722f37; --text: #1a1f36; --muted: #697386; --rule: #e3e8ee; } body { font-family: 'Pretendard', -apple-system, BlinkMacSystemFont, 'Apple SD Gothic Neo', sans-serif; background: #fff; color: var(--text); font-size: 18px; line-height: 1.82; -webkit-font-smoothing: antialiased; } \/* \u2500\u2500 \ud788\uc5b4\ub85c \u2500\u2500 *\/ .hero { max-width: 1000px; margin: 0 auto; padding: 72px 48px 48px; text-align: center; } .category-tag { font-size: 11px; font-weight: 700; letter-spacing: 1.5px; text-transform: uppercase; color: var(--wine); display: block; margin-bottom: 20px; } .hero h1 { font-size: 44px; font-weight: 700; line-height: 1.22; color: var(--navy); margin-bottom: 28px; word-break: keep-all; } \/* \ud788\uc5b4\ub85c \uc81c\ubaa9 \u2014 h1 \ub300\uc2e0 \uc0ac\uc6a9 (\ud14c\ub9c8 \uc790\ub3d9 h1\uacfc \uc911\ubcf5 \ubc29\uc9c0) *\/ .hero-title { font-size: 44px; font-weight: 700; line-height: 1.22; color: var(--navy); margin-bottom: 28px; word-break: keep-all; } .hero-meta { display: flex; align-items: center; justify-content: center; gap: 12px; padding-bottom: 40px; border-bottom: 1px solid var(--rule); } .hero-info { font-size: 13.5px; color: var(--text); line-height: 1.4; } .hero-info strong { color: var(--text); font-weight: 500; } \/* \u2500\u2500 \uc989\uc2dc \ub2f5\ubcc0 \ubc15\uc2a4 \u2500\u2500 *\/ .direct-answer { background: #f6f9fc; border-left: 4px solid var(--navy); border-radius: 0; padding: 20px 24px; margin: 32px 0 40px; font-size: 17px; line-height: 1.75; color: var(--text); } \/* \u2500\u2500 \ubcf8\ubb38 \u2500\u2500 *\/ .content { max-width: 1000px; margin: 0 auto; padding: 52px 48px 100px; } \/* \ubaa9\ucc28 *\/ .toc-nav { margin-bottom: 60px; border: 1px solid #d0d5dd; border-radius: 6px; padding: 28px 32px; } .toc-label { font-size: 20px; font-weight: 700; color: var(--navy); margin-bottom: 14px; } .toc-nav ol { list-style: none; padding-left: 0; } .toc-nav ol li { display: flex; gap: 14px; align-items: baseline; padding: 6px 0; font-size: 17px; } .toc-nav ol li::before { content: none; } .toc-nav ol li a { color: var(--text); text-decoration: none; font-weight: 400; } .toc-nav ol li a:hover { color: var(--wine); } \/* \ub9ac\ub4dc\u00b7\uc694\uc57d\u00b7\ucee8\ud14d\uc2a4\ud2b8 \ud14d\uc2a4\ud2b8 *\/ .lead-text { font-size: 20px; font-weight: 400; color: var(--text); line-height: 1.8; margin-bottom: 24px; } .summary-text { font-size: 18px; color: var(--text); line-height: 1.8; margin-bottom: 20px; } .context-text { font-size: 17px; color: var(--text); line-height: 1.8; margin-bottom: 52px; } \/* \u2500\u2500 \uc81c\ubaa9 \u2500\u2500 *\/ h2 { font-size: 30px; font-weight: 700; color: var(--wine); margin: 68px 0 16px; word-break: keep-all; } h3 { font-size: 17px; font-weight: 700; color: var(--wine); margin: 38px 0 10px; } p { font-size: 18px; color: var(--text); line-height: 1.82; margin-bottom: 18px; } \/* \ud45c *\/ table { width: 100%; border-collapse: collapse; margin: 24px 0; font-size: 14px; } thead tr { background: #fff; } th { color: var(--navy); font-weight: 600; padding: 11px 16px; text-align: left; font-size: 16px; border-bottom: 2px solid var(--navy); } td { padding: 12px 16px; border-bottom: 1px solid var(--rule); color: var(--text); font-size: 16px; } tbody tr:hover { background: #f6f9fc; } \/* \ubd88\ub9bf \ub9ac\uc2a4\ud2b8 *\/ ul, ol:not(.toc-nav ol) { padding-left: 20px; margin-bottom: 16px; } li { font-size: 18px; line-height: 1.78; margin-bottom: 6px; color: var(--text); } \/* \uacc4\uc0b0 \uacf5\uc2dd *\/ .formula { display: flex; align-items: center; gap: 8px; background: #f6f9fc; border: 1px solid var(--rule); border-radius: 8px; padding: 28px 24px; margin: 32px 0; flex-wrap: wrap; justify-content: center; } .f-item { text-align: center; padding: 12px 18px; background: #fff; border: 1px solid var(--rule); border-radius: 5px; } .f-result { background: #fff; border: 2px solid var(--navy); } .f-num { font-size: 22px; font-weight: 700; color: var(--navy); line-height: 1.2; } .f-result .f-num { color: var(--wine); } .f-label { font-size: 11px; color: var(--text); margin-top: 4px; } .f-op { font-size: 20px; color: var(--text); padding: 0 2px; font-weight: 300; } \/* FAQ *\/ .faq-item { border-top: 1px solid var(--rule); padding: 22px 0; } .faq-item:last-of-type { border-bottom: 1px solid var(--rule); } .faq-q { font-size: 17px; font-weight: 600; color: var(--navy); margin-bottom: 8px !important; } .faq-item p:not(.faq-q) { font-size: 17px; color: var(--text); margin: 0; line-height: 1.75; } \/* \ub9c8\ubb34\ub9ac \ubb38\uc7a5 *\/ p.closing { font-size: 15.5px; color: var(--text); margin: 40px 0 0; padding-top: 32px; border-top: 1px solid var(--rule); } \/* \uc800\uc790 \ubc15\uc2a4 *\/ .author-box { display: flex; align-items: center; gap: 14px; padding-top: 40px; margin-top: 40px; border-top: 1px solid var(--rule); } .author-avatar { width: 56px; height: 56px; border-radius: 50%; object-fit: cover; flex-shrink: 0; align-self: flex-start; } .author-text { flex: 1; } .author-name { font-size: 18px; font-weight: 600; color: var(--navy); } .author-meta { font-size: 13px; color: var(--text); margin-top: 2px; } .author-link { display: inline-block; margin-top: 8px; font-size: 15px; font-weight: 600; color: var(--wine); text-decoration: none; } .author-link:hover { text-decoration: underline; } .author-section-label { font-size: 15px; font-weight: 700; letter-spacing: 1px; text-transform: uppercase; color: var(--muted); margin-bottom: 8px; } .author-detail { font-size: 16px; color: var(--text); line-height: 1.7; margin-bottom: 1px; } @media (max-width: 640px) { body { font-size: 15px; } p { font-size: 15px; } li { font-size: 15px; } .hero { padding: 32px 14px 24px; } .hero h1 { font-size: 22px; } .hero-title { font-size: 22px; } .hero-info { font-size: 12px; } .content { padding: 28px 0 60px; } .toc-nav { margin-left: -14px; margin-right: -14px; border-radius: 0; border-left: none; border-right: none; padding: 12px 4px; margin-bottom: 28px; } .toc-label { font-size: 16px; } .toc-nav ol li { font-size: 14px; padding: 3px 0; } h2 { font-size: 20px; margin: 44px 0 10px; } h3 { font-size: 15px; margin: 24px 0 8px; } .lead-text { font-size: 16px; } .summary-text { font-size: 15px; } .context-text { font-size: 14px; } .formula { flex-direction: column; padding: 16px 12px; } .f-num { font-size: 18px; } th { font-size: 13px; padding: 8px 10px; } td { font-size: 13px; padding: 8px 10px; } .faq-q { font-size: 14px; } .faq-item p:not(.faq-q) { font-size: 14px; } .author-box { display: block; overflow: hidden; } .author-avatar { float: left; width: 36px; height: 36px; margin-right: 10px; border-radius: 50%; } .author-section-label { display: inline; font-size: 11px; letter-spacing: 0; margin: 0 3px 0 0; } .author-name { display: inline; font-size: 14px; } .author-detail { clear: both; font-size: 13px; line-height: 1.55; margin-top: 8px; margin-bottom: 1px; } .author-detail ~ .author-detail { clear: none; margin-top: 2px; } .author-link { clear: both; display: block; font-size: 13px; margin-top: 8px; } p.closing { font-size: 14px; } }<\/style>\n<div class=\"hero\">\n  <span class=\"category-tag\">Finance \u00b7 Voice Phishing<\/span><\/p>\n<div class=\"hero-title\">KRW 2.1 Billion Left in Five Days<br \/>Why the Bank Owed Nothing<\/div>\n<div class=\"hero-meta\">\n<div class=\"hero-info\">\n      <strong>Soyoung Park<\/strong> \u00b7 Representative Attorney, Atlas Legal<br \/>\n      Seoul Southern District Court 2025Gahap100965 &nbsp;\u00b7&nbsp; decided 10 June 2026 &nbsp;\u00b7&nbsp; first instance (finality unconfirmed)\n    <\/div>\n<\/p><\/div>\n<\/div>\n<div class=\"content\">\n<div class=\"direct-answer\">\n    <strong>Direct answer:<\/strong> Under Korean law, a voice phishing case in which the deceived customer transfers the money personally follows a completely different legal track from one in which a third party impersonates the account holder. The Seoul Southern District Court, in its judgment of 10 June 2026 in case 2025Gahap100965, dismissed in full a KRW 2.037 billion damages claim brought against a bank by a victim who had made 23 transfers totalling KRW 2.137 billion over five days. Article 21 of the Electronic Financial Transactions Act imposes a duty to prevent errors and electronic intrusions, not third-party fraud, and the identity verification measure under the Telecommunications Fraud Refund Act confirms who the customer is, not whether the transaction reflects that customer&#8217;s genuine intent. The same judgment, however, expressly set out the two circumstances in which a bank does breach its temporary measure duty. This is a first instance judgment and its finality has not been confirmed.\n  <\/div>\n<div class=\"toc-nav\">\n<p class=\"toc-label\">Contents<\/p>\n<ol>\n<li><a href=\"#sec-1\">1. Why did the bank owe nothing after a KRW 2.1 billion loss?<\/a><\/li>\n<li><a href=\"#sec-2\">2. How did the victim send KRW 2.1 billion in five days?<\/a><\/li>\n<li><a href=\"#sec-3\">3. Why can Article 21 of the Electronic Financial Transactions Act not be used?<\/a><\/li>\n<li><a href=\"#sec-4\">4. What did the bank actually verify?<\/a><\/li>\n<li><a href=\"#sec-5\">5. What does a Korean bank&#8217;s FDS screen for?<\/a><\/li>\n<li><a href=\"#sec-6\">6. Was a warning text message enough on the first transfer?<\/a><\/li>\n<li><a href=\"#sec-7\">7. So when must a Korean bank pay?<\/a><\/li>\n<li><a href=\"#sec-8\">8. Why is the period after a hold is lifted the most dangerous?<\/a><\/li>\n<li><a href=\"#sec-9\">9. How does this differ from an identity theft loan case?<\/a><\/li>\n<li><a href=\"#sec-10\">10. What should a victim do first?<\/a><\/li>\n<li><a href=\"#sec-11\">11. What should financial institutions review?<\/a><\/li>\n<li><a href=\"#sec-faq\">12. Frequently asked questions<\/a><\/li>\n<\/ol><\/div>\n<p class=\"lead-text\">In late November 2024, a customer of a Korean bank received a call from someone posing as a post office employee, claiming that a credit card had been issued in the customer&#8217;s name without authorisation. Following the caller&#8217;s instructions, the customer installed an application on their mobile phone. That was the beginning.<\/p>\n<p class=\"summary-text\">Callers then identified themselves as a prosecutor and as officials of the Financial Supervisory Service. The customer was told that they had been implicated in a crime and that, to establish innocence, all assets had to be consolidated into a single account. The customer visited a bank branch twice, raised the transfer limit, and terminated deposits totalling KRW 2.256 billion. Over the following five days, 23 transfers totalling KRW 2.137 billion left the account.<\/p>\n<p class=\"context-text\">The customer sued the bank for more than KRW 2 billion. The bank&#8217;s fraud detection system had in fact flagged the transfers, and on one occasion had suspended electronic banking altogether. Even so, the court dismissed the claim in its entirety. This article explains why, and sets out the standard the same judgment left on the other side of the line \u2014 <strong>the circumstances in which a Korean bank is liable<\/strong>.<\/p>\n<p><\/p>\n<h2 id=\"sec-1\">Why did the bank owe nothing after a KRW 2.1 billion loss?<\/h2>\n<p class=\"lead-text\">Because the customer, although deceived, <strong>executed every transfer personally<\/strong>. That places the case on a different legal footing from one in which a third party impersonates the account holder. The Seoul Southern District Court dismissed the claim in full on 10 June 2026 in case 2025Gahap100965.<\/p>\n<p>The claim rested on three statutory duties: the duty to ensure safety under Article 21 of the Electronic Financial Transactions Act; the identity verification duty under Article 2-4 of the Act on Special Cases Concerning the Prevention of Loss Caused by Telecommunications-Based Financial Fraud and Refund for Loss (the &#8220;Telecommunications Fraud Refund Act&#8221;); and the temporary measure duty under Article 2-5 of the same Act. Breach of these duties was said to give rise to liability in tort under Article 750 of the Civil Act. The customer claimed KRW 2,037,692,410, being the KRW 2.137 billion transferred less KRW 99,307,589 already recovered as a refund.<\/p>\n<table>\n<thead>\n<tr>\n<th>Cause of action<\/th>\n<th>Claimant&#8217;s argument<\/th>\n<th>Court&#8217;s finding<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Electronic Financial Transactions Act, Article 21<br \/>(duty to ensure safety)<\/td>\n<td>A financial institution must exercise the care of a good manager so that electronic financial transactions are processed safely<\/td>\n<td>The provision addresses errors and electronic intrusions, not the protection of users against third-party fraud \u2192 <strong>no room for application<\/strong><\/td>\n<\/tr>\n<tr>\n<td>Telecommunications Fraud Refund Act, Article 2-4<br \/>(identity verification)<\/td>\n<td>On termination of a deposit the bank had to confirm not only identity but genuine intent<\/td>\n<td>The measure extends only to confirming that the contracting party and the transacting party are the same person \u2192 <strong>no breach<\/strong><\/td>\n<\/tr>\n<tr>\n<td>Telecommunications Fraud Refund Act, Article 2-5<br \/>(temporary measures)<\/td>\n<td>The bank observed 23 large transfers over five days yet imposed a hold only once, and lifted it after a formality<\/td>\n<td>Classifying the transactions as medium risk and sending warning messages under its own criteria was not manifestly unreasonable \u2192 <strong>no breach<\/strong><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>With all three routes closed, the court never reached quantum or comparative negligence. The lesson lies less in the outcome than in <strong>which provision a claimant should be pleading<\/strong>.<\/p>\n<p><\/p>\n<h2 id=\"sec-2\">How did the victim send KRW 2.1 billion in five days?<\/h2>\n<p class=\"lead-text\">At every stage the customer personally attended the branch or operated the mobile banking application. That fact governs everything that follows.<\/p>\n<p>The customer held deposits totalling KRW 2.256 billion, placed in March, September and November 2024. The September deposit matured one day before the balance payment date for an apartment purchased that August; the November deposit was structured around the capital gains and acquisition tax deadlines arising from that purchase. This was money with a fixed purpose and a fixed date, not idle savings.<\/p>\n<table>\n<thead>\n<tr>\n<th>Date<\/th>\n<th>Event<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Late Nov 2024<\/td>\n<td>Caller posing as a post office employee \u2192 malicious application installed on the customer&#8217;s phone<\/td>\n<\/tr>\n<tr>\n<td>Late Nov \u2013 1 Dec 2024<\/td>\n<td>Callers posing as a prosecutor and Financial Supervisory Service officials \u2192 &#8220;consolidate your assets into one account&#8221;<\/td>\n<\/tr>\n<tr>\n<td>2 Dec 2024<\/td>\n<td>Branch visit \u2192 OTP (One Time Password) issued; transfer limit raised from KRW 5 million per day to <strong>KRW 500 million per day and KRW 100 million per transaction<\/strong><\/td>\n<\/tr>\n<tr>\n<td>4 Dec 2024<\/td>\n<td>Second branch visit \u2192 <strong>all deposits terminated<\/strong> (identity confirmed face to face)<\/td>\n<\/tr>\n<tr>\n<td>5 Dec 2024, 10:41<\/td>\n<td>First KRW 50 million transfer flagged by the FDS (Fraud Detection System) \u2192 <strong>warning text message only<\/strong><\/td>\n<\/tr>\n<tr>\n<td>5 Dec 2024, 11:20<\/td>\n<td>KRW 50 million transfer completed \u2192 electronic banking suspended immediately afterwards<\/td>\n<\/tr>\n<tr>\n<td>5 Dec 2024 (afternoon)<\/td>\n<td>Customer telephoned to request release \u2192 bank staff asked two questions and <strong>lifted the suspension<\/strong> (about 20 minutes before the 13:07 transfer)<\/td>\n<\/tr>\n<tr>\n<td>5 Dec 2024, 13:07\u201316:30<\/td>\n<td>Five further transfers totalling KRW 450 million \u2192 flagged again, warning message only<\/td>\n<\/tr>\n<tr>\n<td>5\u20139 Dec 2024<\/td>\n<td>23 transfers over five days, totalling <strong>KRW 2.137 billion<\/strong><\/td>\n<\/tr>\n<tr>\n<td>Mar \u2013 Jun 2025<\/td>\n<td>Refunds totalling KRW 99,307,589 received<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>What matters is that <strong>both the limit increase and the deposit termination took place face to face at the counter<\/strong>. This was not a case in which it is unclear who operated the account. The person sitting across from the bank employee was unquestionably the account holder.<\/p>\n<p><\/p>\n<h2 id=\"sec-3\">Why can Article 21 of the Electronic Financial Transactions Act not be used?<\/h2>\n<p class=\"lead-text\">Because the risk that provision contemplates is <strong>system failure and intrusion, not fraud<\/strong>. The court disposed of this argument without needing to examine it further.<\/p>\n<p>The wording of Article 21(1) appears broad: a financial institution must exercise the care of a good manager so that electronic financial transactions are processed safely. It is therefore natural to argue that failing to stop a voice phishing transfer breaches that duty, and this is the most commonly pleaded cause of action in Korean practice.<\/p>\n<h3>The four reasons the court gave<\/h3>\n<p>First, the Electronic Financial Transactions Act was enacted to clarify the rights and obligations of parties to electronic financial transactions, reflecting features such as the absence of face-to-face contact, and to systematise licensing and supervision of the electronic financial business. Second, Article 9 of the same Act confines a financial institution&#8217;s liability to three categories of incident: <strong>forgery or alteration of an access medium, incidents arising in the electronic transmission or processing of a contract or transaction instruction, and use of an access medium obtained by intrusion into an information and communications network<\/strong>.<\/p>\n<p>Third, Article 21(2) to (4) requires only compliance with standards on personnel, facilities, electronic devices and authentication methods, and the submission of information technology plans. Fourth, the other provisions of Chapter 3 of the Act \u2014 vulnerability analysis of electronic financial infrastructure, prohibition of electronic intrusion \u2014 deal only with <strong>measures needed for transactions to be executed as instructed<\/strong>, and contain nothing about protecting users from third-party fraud.<\/p>\n<p>On that basis the court concluded that Article 21(1) imposes a duty to prevent errors or electronic intrusions arising in the course of electronic financial transactions. Where a customer has been deceived into transferring money, absent any assertion or proof of an &#8220;error&#8221; or &#8220;electronic intrusion&#8221; within the meaning of the Act, there is no room to find a breach of the duty to ensure safety. An &#8220;error&#8221; is defined as a case where, without the user&#8217;s intent or negligence, a transaction is not executed in accordance with the contract or the user&#8217;s instruction. These transfers were executed exactly as instructed, so no error occurred.<\/p>\n<p><strong>The practical consequence<\/strong> is clear. Even where a malicious application was installed, if that application did not <em>alter the content of the transaction<\/em>, the route through Article 21 is closed. Before filing, confirm whether the facts actually disclose forgery or alteration of an access medium, or an electronic intrusion.<\/p>\n<p><\/p>\n<h2 id=\"sec-4\">What did the bank actually verify?<\/h2>\n<p class=\"lead-text\">That the person at the counter was the depositor. The court held that the bank had <strong>no duty to go further and confirm that the transaction reflected the customer&#8217;s genuine intent<\/strong>.<\/p>\n<p>Article 2-4(1) of the Telecommunications Fraud Refund Act requires a financial institution to carry out an identity verification measure where a user (i) applies for a loan or (ii) terminates a savings deposit, instalment savings or similar product; Article 2-4(2) imposes liability for loss caused by breach. This case fell under <strong>(ii), termination of deposits<\/strong>. Article 2-3(1) of the Enforcement Decree prescribes the permitted methods: use of the user&#8217;s registered telephone, face-to-face confirmation, or another method recognised and published by the Financial Services Commission. The bank used <strong>face-to-face confirmation<\/strong>.<\/p>\n<p>The claimant&#8217;s argument was carefully framed. Identity had indeed been confirmed in person, but for the measure to be satisfied the bank had to confirm not merely that the customer was who they said they were, but that they were <strong>transacting of their own genuine volition<\/strong>. The bank, it was said, failed to ask how an elderly depositor came to terminate KRW 2.2 billion in deposits at once, without the involvement of family members, contrary to previous practice.<\/p>\n<h3>Why the court read the text narrowly<\/h3>\n<p>The court applied established principles of statutory construction: the object of interpretation is to find concrete justice without undermining legal certainty, and where the text is relatively clear, other interpretive methods are correspondingly constrained. It then gave four reasons.<\/p>\n<p>First, the provision speaks only of a &#8220;measure to confirm that the person is the principal&#8221;. Second, on that wording the measure means confirming that the person who concluded the contract with the financial institution and the person using the electronic financial transaction under that contract are the same; there is nothing in the text from which one could read in a measure directed at whether the user is transacting entirely on their own judgment, free from improper external interference. Third, the Enforcement Decree prescribes only the <em>means<\/em> of verification and does not widen its scope. Fourth, it would be improper to use Article 2-5(3), which governs the release of a temporary measure, to expand the scope of the separate identity verification measure under Article 2-4(1).<\/p>\n<p>The conclusion was that the identity verification measure does not extend to confirming whether the customer is transacting with genuine intent.<\/p>\n<table>\n<thead>\n<tr>\n<th>Aspect<\/th>\n<th>Within the identity verification measure<\/th>\n<th>Outside it<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Subject of confirmation<\/td>\n<td>Whether the contracting party and the transacting party are the <strong>same person<\/strong><\/td>\n<td>The customer&#8217;s <strong>internal intent<\/strong> or motive for the transaction<\/td>\n<\/tr>\n<tr>\n<td>Prescribed methods<\/td>\n<td>Registered telephone, face-to-face confirmation, FSC-recognised methods<\/td>\n<td>Questioning about circumstances, contacting family, imposing a cooling-off period<\/td>\n<\/tr>\n<tr>\n<td>Practical effect<\/td>\n<td>Compliance with the prescribed form can be challenged<\/td>\n<td>An argument that the bank &#8220;should have probed further&#8221; cannot be run on this provision<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>This holding sits at <strong>the opposite pole from identity theft cases<\/strong>. There, the issue is that the institution <em>did not<\/em> verify identity. Here, the issue was whether, having verified, it had to do more. The answer was no.<\/p>\n<p><\/p>\n<h2 id=\"sec-5\">What does a Korean bank&#8217;s FDS screen for?<\/h2>\n<p class=\"lead-text\">The judgment describes the internal architecture of a Korean commercial bank&#8217;s fraud detection system in unusual detail. It is a useful guide to what to request in litigation.<\/p>\n<p>The court recorded that the bank&#8217;s FDS is a system that comprehensively detects and analyses terminal information, access information, transaction information and customer information used in electronic financial services, identifies abnormal financial transactions, and responds to electronic financial incidents and telecommunications-based financial fraud. It was introduced as part of the <strong>suspicious transaction detection system<\/strong> contemplated by Article 2-5(1)1 of the Telecommunications Fraud Refund Act and its Enforcement Decree.<\/p>\n<p><small>\u203b <strong>FDS (Fraud Detection System)<\/strong> \u2014 an internal bank system that, at the moment a transfer is made, automatically compares the device, access location, amount, timing and the customer&#8217;s ordinary transaction patterns in order to isolate transactions that deviate from the norm. It works on the same principle as a card issuer telephoning when an unusually large payment is made abroad: no employee reviews each transaction individually; the system triggers automatically when a pre-defined <em>scenario<\/em> is matched. Its statutory name in Korea is the suspicious transaction detection system, but the industry calls it the FDS.<\/small><\/p>\n<table>\n<thead>\n<tr>\n<th>Item<\/th>\n<th>Detail<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Detection scenarios<\/td>\n<td><strong>51<\/strong> from the FDS operating guidelines issued by the Financial Supervisory Service and the Financial Security Institute + <strong>50<\/strong> developed in-house = <strong>101<\/strong> in total<\/td>\n<\/tr>\n<tr>\n<td>Factors assessed<\/td>\n<td>Transaction period, number of deposits and withdrawals, customer particulars, time of transfer, deposit amount, prior transaction frequency, withdrawal amounts, repetition, prior transaction types, access IP address<\/td>\n<\/tr>\n<tr>\n<td>Medium risk<\/td>\n<td><strong>Warning text message only<\/strong><\/td>\n<\/tr>\n<tr>\n<td>High risk<\/td>\n<td>Warning + <strong>electronic banking blocked<\/strong>; released after telephone identity verification when the customer calls in<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Both sets of transfers in this case were classified as <strong>medium risk<\/strong>: the first as a &#8220;large-value transfer immediately following certificate issuance&#8221;, and the later repeated transfers as &#8220;abnormal repeated transfers following certificate issuance&#8221;. Under the bank&#8217;s own criteria, both attracted a warning message only.<\/p>\n<p>For a claimant, <strong>this table is effectively a document production list<\/strong>. How many scenarios are operated, which type sits at which risk grade, when and on what basis that grading was set, and which scenario the transaction in question actually triggered \u2014 all of this must be identified before the case can advance.<\/p>\n<p><\/p>\n<h2 id=\"sec-6\">Was a warning text message enough on the first transfer?<\/h2>\n<p class=\"lead-text\">The court held that it was. What matters is the reason: not that detection came too late, but that <strong>the risk grading was not manifestly unreasonable<\/strong>.<\/p>\n<p>The facts looked favourable to the claimant. At 10:41 on 5 December 2024 the FDS had already flagged the transaction as abnormal, yet the bank sent only a warning message stating that a suspicious transfer had been detected in mobile banking, and the KRW 50 million transfer completed at 11:20. <strong>Detection preceded the transfer by 39 minutes, and the transfer was not stopped.<\/strong><\/p>\n<p>The court nonetheless declined to treat those 39 minutes as unlawful in themselves. The bank does not block every flagged transaction; it grades them, and a &#8220;large-value transfer immediately following certificate issuance&#8221; is medium risk, so sending a warning message <strong>was not a failure to apply its own criteria<\/strong>.<\/p>\n<p>Could the criteria themselves be inadequate? On this the court held that the mere fact of a large transaction following certificate issuance cannot by itself establish a situation in which telecommunications fraud is to be apprehended; the subsequent discovery that the transfers were fraudulent did not make the medium-risk classification manifestly lacking in reasonableness and appropriateness.<\/p>\n<p>This is a refusal to judge with hindsight. Obtaining a new certificate and making a large transfer is a common combination in legitimate banking, and blocking on that basis alone would over-restrict ordinary customers.<\/p>\n<p><\/p>\n<h2 id=\"sec-7\">So when must a Korean bank pay?<\/h2>\n<p class=\"lead-text\">This is the most valuable part of the judgment. In dismissing the claim, the court <strong>expressly identified two circumstances in which the temporary measure duty is breached<\/strong>. A defeat for the claimant, it functions as a map of the elements of a successful claim.<\/p>\n<h3>The purpose of the provision<\/h3>\n<p>The temporary measure duty under Article 2-5(1) was inserted by the amendment of 28 January 2014 (Act No. 12384). The court cited the stated reason for the amendment as published by the Ministry of Government Legislation: to require financial institutions to detect abnormal transactions across all user accounts and, where an account is recognised as a suspicious transaction account, to impose measures such as delaying transfers, <strong>while leaving the specific categories of abnormal transaction to be determined autonomously by each institution<\/strong>.<\/p>\n<p>What counts as a suspicious transaction is therefore for the institution to decide. Read alone, that looks close to a blank cheque.<\/p>\n<h3>But the discretion has limits<\/h3>\n<p>The court drew the line precisely there. The self-inspection criteria and methods adopted in the exercise of that discretion, and the decision whether to impose a temporary measure following such self-inspection, <strong>must objectively possess reasonableness, appropriateness and social acceptability<\/strong>.<\/p>\n<p>It then enumerated the circumstances amounting to breach. A financial institution breaches Article 2-5(1) where, (i) because it failed properly to carry out self-inspection in accordance with the criteria and methods it had established for detecting abnormal transactions, or (ii) because, although it carried out self-inspection properly, those criteria and methods were deficient \u2014 objectively so manifestly lacking in reasonableness and appropriateness that social acceptability cannot be recognised \u2014 it failed to impose a temporary measure despite circumstances warranting the inference that the account was being used as a suspicious transaction account. The court expressly stated that this <strong>covers both the case where the institution failed to recognise those circumstances and the case where it recognised them and still did nothing<\/strong>.<\/p>\n<table>\n<thead>\n<tr>\n<th>Type of breach<\/th>\n<th>What is alleged<\/th>\n<th>What must be proved<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><strong>(i) Non-compliance with own criteria<\/strong><\/td>\n<td>The institution did not follow the rules it wrote<\/td>\n<td>The scenario the transaction should have triggered, the response prescribed for that grade, and the divergence in what was actually done<\/td>\n<\/tr>\n<tr>\n<td><strong>(ii) Deficient criteria<\/strong><\/td>\n<td>The criteria were followed but are themselves socially unacceptable<\/td>\n<td>Criteria used by comparable institutions, the gap against FSS and Financial Security Institute guidelines, and the absence of any basis for the risk grading<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Neither type was made out here, because the bank had adopted all 51 supervisory guideline scenarios, added 50 of its own, and handled the transactions as medium risk in accordance with those criteria. Conversely, <strong>an institution that has not implemented the guidelines, or that cannot explain its risk grading, is exposed under type (ii)<\/strong>. The express inclusion of cases where the institution knew and did nothing is also likely to be significant in practice.<\/p>\n<p><\/p>\n<h2 id=\"sec-8\">Why is the period after a hold is lifted the most dangerous?<\/h2>\n<p class=\"lead-text\">Because transactions immediately after release are treated as <strong>already verified<\/strong> and are not caught again. KRW 450 million left through that gap in this case.<\/p>\n<p>After the first KRW 50 million transfer, the bank messaged the customer to say that a suspicious transfer had been detected and that electronic financial transactions were restricted from that point, and suspended the account. When a further KRW 98 million transfer was blocked, the customer telephoned the bank to ask for the restriction to be lifted.<\/p>\n<p>The employee confirmed that the customer was transferring the money personally, then asked two questions: whether any family member or acquaintance had asked the customer to photograph an identification card or confirm an account number, and whether the customer had been asked to click an English-language address attached to an obituary or wedding invitation sent by text or messenger. Both questions target <em>messenger phishing and smishing<\/em>, which are quite distinct from impersonation of public authorities. The customer answered no, and the suspension was lifted.<\/p>\n<p>Between 13:07 and 16:30, five transfers totalling KRW 450 million followed. The FDS flagged them as &#8220;abnormal repeated transfers following certificate issuance&#8221; and sent a warning message at 16:29, but imposed no further hold.<\/p>\n<h3>Why the court found no breach<\/h3>\n<p>Four reasons. First, that transaction type was medium risk, so a warning message was the prescribed response. Second, a temporary measure had already been imposed roughly an hour earlier and lifted some twenty minutes earlier following identity verification. Third, the call recording showed that the customer requested release <strong>because a KRW 98 million transfer had been blocked<\/strong>, so it would have been difficult for the bank to conclude that the very same transfer, executed at 13:07, required a fresh hold. Fourth, the four subsequent transfers went to <strong>the same counterparty account<\/strong> as the 13:07 transfer, so repetition alone did not signal fraud.<\/p>\n<p>The claimant also argued that, before lifting the hold, the bank should have checked whether the customer was acting under deception or coercion, relying on Article 2-5(3), which requires release where identity verification shows that the account is not a suspicious transaction account. The court held that because the provision expressly makes the determination turn on the <strong>result of the identity verification measure<\/strong>, legislative purpose cannot be used to impose an additional duty to take other effective steps to detect fraud. The same reasoning as under Article 2-4 was applied again.<\/p>\n<p><strong>The remaining practical route<\/strong> is therefore clear. To challenge what happens after a release, a claimant must plead <strong>Article 2-5(1)<\/strong> rather than Article 2-5(3), and must fit the facts into type (i) or type (ii) \u2014 for example, by arguing that the absence of any separate scenario for consecutive transfers to the same account following a release amounts to deficient criteria.<\/p>\n<p><\/p>\n<h2 id=\"sec-9\">How does this differ from an identity theft loan case?<\/h2>\n<p class=\"lead-text\">Although both are described as financial fraud, <strong>the legal routes diverge from the outset<\/strong>. This is the distinction most often confused in practice.<\/p>\n<table>\n<thead>\n<tr>\n<th>Aspect<\/th>\n<th>Identity theft (a third party impersonates you)<\/th>\n<th>Deceived transfer (you are tricked)<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Who transacted<\/td>\n<td>An unidentified third party<\/td>\n<td><strong>The account holder<\/strong><\/td>\n<\/tr>\n<tr>\n<td>Central issue<\/td>\n<td>Whether the institution <strong>verified identity<\/strong><\/td>\n<td>Whether the institution <strong>should have blocked<\/strong> the transaction<\/td>\n<\/tr>\n<tr>\n<td>Principal claim<\/td>\n<td>Declaration of non-existence of debt, or damages under Article 2-4(2)<\/td>\n<td>Damages for breach of the Article 2-5 temporary measure duty<\/td>\n<\/tr>\n<tr>\n<td>Framework Act on Electronic Documents, Article 7<\/td>\n<td>Central (whether there was a justifiable reason)<\/td>\n<td>No application<\/td>\n<\/tr>\n<tr>\n<td>Electronic Financial Transactions Act, Article 21<\/td>\n<td>Available as a supporting argument<\/td>\n<td><strong>Excluded on this judgment<\/strong><\/td>\n<\/tr>\n<tr>\n<td>Statutory refund<\/td>\n<td>Rarely relevant in loan cases<\/td>\n<td>Amounts received are deducted from loss<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>The criteria that decide identity theft cases, and the recent Supreme Court authorities on them, are set out separately in <a href=\"https:\/\/atlaw.kr\/en-blog\/identity-theft-loan-verification-south-korea\/\">Identity Theft Loans in South Korea: When You Owe Nothing<\/a>. The Supreme Court judgments discussed there, both handed down on 14 August 2025, concern <strong>whether identity verification procedures were properly performed<\/strong>, so the order of analysis is different from this case.<\/p>\n<p>One question separates the two tracks: <strong>who operated the account?<\/strong> If a third party did, the first track applies; if you did, this one does. Even where a malicious application was installed, if you pressed the transfer button, you are on this track.<\/p>\n<p><\/p>\n<h2 id=\"sec-10\">What should a victim do first?<\/h2>\n<p class=\"lead-text\">Sequence determines outcome. Following the order below preserves both the prospect of recovery and the evidence needed for litigation.<\/p>\n<p><strong>1. Request a payment suspension immediately.<\/strong> Contact both the receiving institution and your own bank to request suspension, and report the matter to the police. A refund under the Telecommunications Fraud Refund Act is funded from the frozen balance, so the speed of this step effectively determines the recoverable amount. This claimant recovered only KRW 99,307,589 of KRW 2.137 billion.<\/p>\n<p><strong>2. Preserve the malicious application before removing it.<\/strong> Do not reset the phone first. With expert assistance, <strong>preserve evidence<\/strong> of the installed applications and any remote-access traces, then remove them. Resetting immediately destroys the only physical evidence. Then revoke and reissue certificates and OTP devices.<\/p>\n<p><strong>3. Secure the bank&#8217;s messages and call recordings.<\/strong> Warning messages, restriction notices and the recording of any release request are central to a temporary measure claim. Under Article 2-5(4), institutions must preserve records of notification, release and identity verification in writing, by recording or by other prescribed means, so <strong>an answer that no record exists is itself significant<\/strong>.<\/p>\n<p><strong>4. Demand the FDS detection record in documentary form.<\/strong> Identify which scenario was triggered and when, the risk grade assigned to that type, and the response prescribed for that grade. As this judgment shows, institutions produce these materials to defend themselves. It is better to hold them first.<\/p>\n<p><strong>5. Choose the cause of action before filing.<\/strong> This judgment establishes that Article 21 and Article 2-4 are difficult routes in this category of case. Decide first whether the claim is <strong>type (i) non-compliance or type (ii) deficient criteria<\/strong> under Article 2-5(1), and assemble the evidence accordingly.<\/p>\n<p><strong>6. Assess your own contributory fault.<\/strong> The claim here was dismissed entirely, so comparative negligence never arose. Where breach is established, however, active participation in raising transfer limits or terminating deposits can substantially reduce recovery.<\/p>\n<p><\/p>\n<h2 id=\"sec-11\">What should financial institutions review?<\/h2>\n<p class=\"lead-text\">The bank won, but <strong>the reasons it won are the review checklist<\/strong>. An institution that cannot meet those conditions cannot run the same defence.<\/p>\n<p><strong>1. Document the self-inspection criteria.<\/strong> The decisive factor was that the bank could <strong>produce in evidence<\/strong> a framework of 101 scenarios built on 51 supervisory guideline scenarios. Without documented criteria, a type (ii) defence is difficult.<\/p>\n<p><strong>2. Record the basis for risk grading.<\/strong> If there is no recorded reasoning for placing a transaction type at medium risk, the grading cannot be defended against an allegation of arbitrariness.<\/p>\n<p><strong>3. Verify through logs that the criteria were actually applied.<\/strong> Type (i) is an <strong>operational<\/strong> failure rather than a design failure. Review the interval between detection and response, and the number of omitted responses, on a regular basis.<\/p>\n<p><strong>4. Design separately for the period after a release.<\/strong> The KRW 450 million left immediately after the hold was lifted. The court found no breach on the present criteria, but the absence of any dedicated scenario for <strong>consecutive transfers to the same account following a release<\/strong> is exposed to a type (ii) challenge in a future case.<\/p>\n<p><strong>5. Reconsider the scope of verification questions.<\/strong> The two questions asked here addressed messenger phishing and smishing and did not reach impersonation of public authorities. The court held there is no <em>legal duty<\/em> to go further, but the absence of a duty is not the same as the absence of a preventable loss.<\/p>\n<p><strong>6. Review the Article 2-4(1) triggers.<\/strong> Loan applications and terminations of savings products are moments where identity verification is a <strong>statutory obligation<\/strong>. Omission at those points engages liability under Article 2-4(2) directly.<\/p>\n<p><strong>7. Comply with the preservation duty.<\/strong> Article 2-5(4) requires records of notification, release and identity verification to be preserved. Here the bank produced the call recording and established facts in its favour. Preservation is itself a defence.<\/p>\n<p>Atlas Legal advises financial institutions and international companies in Incheon&#8217;s Songdo International Business District, and across the Incheon Free Economic Zone including Cheongna International City and Yeongjong International City, as well as Seoul and Gyeonggi Province, on disputes arising from electronic financial transactions in South Korea.<\/p>\n<p><\/p>\n<h2 id=\"sec-faq\">Frequently asked questions<\/h2>\n<div class=\"faq-item\">\n<p class=\"faq-q\">Q. Can I recover from a Korean bank money I transferred in a voice phishing scam?<\/p>\n<p>A. It is difficult but not impossible. In case 2025Gahap100965, decided on 10 June 2026, the Seoul Southern District Court dismissed in full the claim of a victim who had transferred KRW 2.137 billion, because a customer who transfers personally cannot readily rely on Article 21 of the Electronic Financial Transactions Act or Article 2-4 of the Telecommunications Fraud Refund Act. The same judgment nonetheless held that a bank breaches its temporary measure duty where it fails to follow its own self-inspection criteria, or where those criteria are themselves manifestly unreasonable. This is a first instance judgment and its finality has not been confirmed.<\/p>\n<\/div>\n<div class=\"faq-item\">\n<p class=\"faq-q\">Q. Can I rely on the duty to ensure safety under Article 21?<\/p>\n<p>A. Not where you were deceived into transferring the money yourself. The court held that Article 21(1) imposes a duty to prevent errors or electronic intrusions arising in the course of electronic financial transactions. An &#8220;error&#8221; means a case where, without the user&#8217;s intent or negligence, a transaction is not executed as contracted or instructed; a transfer executed exactly as instructed is not an error. Separate facts amounting to forgery or alteration of an access medium, or intrusion into an information and communications network, are required.<\/p>\n<\/div>\n<div class=\"faq-item\">\n<p class=\"faq-q\">Q. Should the bank employee have probed the circumstances of the deposit termination?<\/p>\n<p>A. There is no legal duty to do so. The court held that the identity verification measure under Article 2-4(1) does not extend to confirming whether the customer is transacting with genuine intent. The measure is limited to confirming that the person who concluded the contract and the person using the transaction are the same, and does not include confirming whether the customer is acting entirely on their own judgment, free from improper external interference.<\/p>\n<\/div>\n<div class=\"faq-item\">\n<p class=\"faq-q\">Q. Is identity verification mandatory when terminating a deposit in South Korea?<\/p>\n<p>A. Yes. Article 2-4(1) of the Telecommunications Fraud Refund Act requires an identity verification measure where a user applies for a loan or terminates a savings deposit, instalment savings or similar product, and Article 2-4(2) imposes liability for resulting loss. Article 2-3(1) of the Enforcement Decree permits use of the registered telephone, face-to-face confirmation, or another method recognised by the Financial Services Commission. Here face-to-face confirmation at the branch satisfied the procedural requirement.<\/p>\n<\/div>\n<div class=\"faq-item\">\n<p class=\"faq-q\">Q. If the bank detects an abnormal transaction but does not block it, is it liable?<\/p>\n<p>A. Detection alone does not create liability. While a financial institution has discretion in setting its self-inspection criteria and methods, the court held that those criteria, and the decision whether to impose a temporary measure following self-inspection, must objectively possess reasonableness, appropriateness and social acceptability. Liability arises where the criteria are manifestly unreasonable, or where the institution failed to operate in accordance with them.<\/p>\n<\/div>\n<div class=\"faq-item\">\n<p class=\"faq-q\">Q. Precisely when does a bank breach the temporary measure duty?<\/p>\n<p>A. The court identified two situations. First, where the institution failed properly to carry out self-inspection in accordance with the criteria and methods it had established for detecting abnormal transactions. Second, where it carried out self-inspection properly but those criteria and methods were deficient, being objectively so manifestly lacking in reasonableness and appropriateness that social acceptability cannot be recognised. In either case the breach lies in failing to impose a temporary measure despite circumstances warranting the inference that the account was being used as a suspicious transaction account, and this covers both failure to recognise those circumstances and recognising them without acting.<\/p>\n<\/div>\n<div class=\"faq-item\">\n<p class=\"faq-q\">Q. What criteria does a Korean bank&#8217;s FDS use to screen transactions?<\/p>\n<p>A. According to the judgment, this bank operated 101 detection scenarios: 51 from the FDS operating guidelines issued by the Financial Supervisory Service and the Financial Security Institute, plus 50 developed in-house. Transactions are classified using factors such as the transaction period, number of deposits and withdrawals, customer particulars, time of transfer, deposit amount, prior transaction frequency, withdrawal amounts, repetition and access IP address. Medium-risk transactions attract a warning text message only; high-risk transactions are blocked and released after telephone identity verification.<\/p>\n<\/div>\n<div class=\"faq-item\">\n<p class=\"faq-q\">Q. The transfer was detected before it completed. Was failing to stop it unlawful?<\/p>\n<p>A. Not in this case. The transaction was detected at 10:41 and the KRW 50 million transfer completed at 11:20, but the transaction fell within the &#8220;large-value transfer immediately following certificate issuance&#8221; type, which was medium risk under the bank&#8217;s criteria. The court held that the mere fact of a large transaction following certificate issuance cannot by itself establish a situation in which telecommunications fraud is to be apprehended, and that the later discovery of fraud did not render the grading manifestly unreasonable.<\/p>\n<\/div>\n<div class=\"faq-item\">\n<p class=\"faq-q\">Q. How should transfers made after a hold is lifted be challenged?<\/p>\n<p>A. Through Article 2-5(1) rather than Article 2-5(3). The court held that because Article 2-5(3) expressly makes release turn on the result of the identity verification measure, no additional duty to take other effective steps to detect fraud before release can be implied. A claim concerning the period after release must therefore be framed as a breach of the temporary measure duty, on the basis that no self-inspection criteria covered that period or that the criteria were deficient.<\/p>\n<\/div>\n<div class=\"faq-item\">\n<p class=\"faq-q\">Q. How does this differ from an identity theft loan case?<\/p>\n<p>A. It turns on who operated the account. Where a third party used the victim&#8217;s identity, the issue is whether the institution properly performed identity verification, and the principal tools are the &#8220;justifiable reason&#8221; test under Article 7(2)2 of the Framework Act on Electronic Documents and a declaration of non-existence of debt. Where the customer was deceived into transferring personally, neither that Act nor Article 21 of the Electronic Financial Transactions Act applies, and the temporary measure duty under Article 2-5 is in practice the only route.<\/p>\n<\/div>\n<div class=\"faq-item\">\n<p class=\"faq-q\">Q. How does a statutory refund affect the damages claim?<\/p>\n<p>A. It is deducted. Having transferred KRW 2.137 billion, this claimant received refunds totalling KRW 99,307,589 between March and June 2025 under Article 10(1) of the Telecommunications Fraud Refund Act, and claimed the balance of KRW 2,037,692,410. Because the refund is funded from the frozen balance, the speed of reporting determines the amount recovered.<\/p>\n<\/div>\n<div class=\"faq-item\">\n<p class=\"faq-q\">Q. Is this judgment final?<\/p>\n<p>A. No. It is a first instance judgment handed down by the 12th Civil Division of the Seoul Southern District Court on 10 June 2026, and any appeal or appellate ruling has not been confirmed. It is nonetheless of considerable practical value because judgments setting out the standard for breach of the temporary measure duty directly are rare. Any application to a particular case should be checked against the subsequent procedural history.<\/p>\n<\/div>\n<p><\/p>\n<p class=\"closing\">Voice phishing by impersonation of public authorities differs from identity theft in that the victim personally takes every step, and the applicable provisions differ accordingly. That this judgment dismissed the claim while expressly identifying the two types of breach of the temporary measure duty is, read the other way, an indication of where to aim. If you have suffered loss, secure the institution&#8217;s FDS detection records and temporary measure documentation first.<\/p>\n<div class=\"author-box\">\n    <img decoding=\"async\" class=\"author-avatar\" src=\"https:\/\/atlaw.kr\/wp-content\/uploads\/2022\/12\/\ubc15\uc18c\uc601-1.png\" alt=\"Soyoung Park, Representative Attorney \u2014 Atlas Legal\"><\/p>\n<div class=\"author-text\">\n<div class=\"author-section-label\">About the author<\/div>\n<div class=\"author-name\">Soyoung Park | Representative Attorney<\/div>\n<div class=\"author-detail\">Family law, inheritance, construction and real estate disputes<\/div>\n<div class=\"author-detail\">Judicial Research and Training Institute, 33rd class<\/div>\n<div class=\"author-detail\">Korea University, School of Law<\/div>\n<div class=\"author-detail\">Atlas Legal | Songdo, Incheon, South Korea<\/div>\n<p>      <a class=\"author-link\" href=\"https:\/\/atlaw.kr\" target=\"_blank\" rel=\"noopener noreferrer\">Visit the Atlas Legal website \u2192<\/a>\n    <\/div>\n<\/p><\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>When a deceived customer transfers the money themselves, how far does a Korean bank&#8217;s liability go? A KRW 2 billion claim dismissed, and when a bank is liable.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"_kad_post_transparent":"","_kad_post_title":"","_kad_post_layout":"","_kad_post_sidebar_id":"","_kad_post_content_style":"","_kad_post_vertical_padding":"","_kad_post_feature":"","_kad_post_feature_position":"","_kad_post_header":false,"_kad_post_footer":false,"_kad_post_classname":"","footnotes":""},"categories":[17],"tags":[951,948,950,949,947],"class_list":["post-1953","post","type-post","status-publish","format-standard","hentry","category-civil","tag-bank-liability-korea","tag-electronic-financial-transactions-act","tag-fraud-detection-system","tag-telecommunications-fraud-refund-act","tag-voice-phishing-south-korea"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Voice Phishing Bank Liability in South Korea | Atlas Legal<\/title>\n<meta name=\"description\" content=\"When a deceived customer transfers the money themselves, how far does a Korean bank&#039;s liability go? A KRW 2 billion claim dismissed, and when a bank is liable.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/atlaw.kr\/en-blog\/voice-phishing-bank-liability-south-korea\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Voice Phishing Bank Liability in South Korea | Atlas Legal\" \/>\n<meta property=\"og:description\" content=\"When a deceived customer transfers the money themselves, how far does a Korean bank&#039;s liability go? A KRW 2 billion claim dismissed, and when a bank is liable.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/atlaw.kr\/en-blog\/voice-phishing-bank-liability-south-korea\/\" \/>\n<meta property=\"og:site_name\" content=\"Atlas Legal Blog\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-02T08:08:38+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-02T08:09:20+00:00\" \/>\n<meta name=\"author\" content=\"\ubc95\ubb34\ubc95\uc778 \uc544\ud2c0\ub77c\uc2a4\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"\ubc95\ubb34\ubc95\uc778 \uc544\ud2c0\ub77c\uc2a4\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"28 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/atlaw.kr\\\/en-blog\\\/voice-phishing-bank-liability-south-korea\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/atlaw.kr\\\/en-blog\\\/voice-phishing-bank-liability-south-korea\\\/\"},\"author\":{\"name\":\"\ubc95\ubb34\ubc95\uc778 \uc544\ud2c0\ub77c\uc2a4\",\"@id\":\"https:\\\/\\\/atlaw.kr\\\/en-blog\\\/#\\\/schema\\\/person\\\/184bcdecc06f89fd6c36b29781165b55\"},\"headline\":\"KRW 2.1 Billion Left in Five Days \u2014 Why the Bank Owed Nothing\",\"datePublished\":\"2026-09-02T08:08:38+00:00\",\"dateModified\":\"2026-09-02T08:09:20+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/atlaw.kr\\\/en-blog\\\/voice-phishing-bank-liability-south-korea\\\/\"},\"wordCount\":5665,\"publisher\":{\"@id\":\"https:\\\/\\\/atlaw.kr\\\/en-blog\\\/#organization\"},\"keywords\":[\"Bank Liability Korea\",\"Electronic Financial Transactions Act\",\"Fraud Detection System\",\"Telecommunications Fraud Refund Act\",\"Voice Phishing South Korea\"],\"articleSection\":[\"Civil\\\/Administrative\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/atlaw.kr\\\/en-blog\\\/voice-phishing-bank-liability-south-korea\\\/\",\"url\":\"https:\\\/\\\/atlaw.kr\\\/en-blog\\\/voice-phishing-bank-liability-south-korea\\\/\",\"name\":\"Voice Phishing Bank Liability in South Korea | Atlas Legal\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/atlaw.kr\\\/en-blog\\\/#website\"},\"datePublished\":\"2026-09-02T08:08:38+00:00\",\"dateModified\":\"2026-09-02T08:09:20+00:00\",\"description\":\"When a deceived customer transfers the money themselves, how far does a Korean bank's liability go? A KRW 2 billion claim dismissed, and when a bank is liable.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/atlaw.kr\\\/en-blog\\\/voice-phishing-bank-liability-south-korea\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/atlaw.kr\\\/en-blog\\\/voice-phishing-bank-liability-south-korea\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/atlaw.kr\\\/en-blog\\\/voice-phishing-bank-liability-south-korea\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\ud648\",\"item\":\"https:\\\/\\\/atlaw.kr\\\/en-blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"KRW 2.1 Billion Left in Five Days \u2014 Why the Bank Owed Nothing\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/atlaw.kr\\\/en-blog\\\/#website\",\"url\":\"https:\\\/\\\/atlaw.kr\\\/en-blog\\\/\",\"name\":\"Atlas Legal English Blog\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/atlaw.kr\\\/en-blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/atlaw.kr\\\/en-blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/atlaw.kr\\\/en-blog\\\/#organization\",\"name\":\"Atlas Legal English Blog\",\"url\":\"https:\\\/\\\/atlaw.kr\\\/en-blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/atlaw.kr\\\/en-blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/atlaw.kr\\\/en-blog\\\/wp-content\\\/uploads\\\/sites\\\/3\\\/2025\\\/09\\\/\ud3f4\ub354-\uc0c1\ub2e8-\uc9c1\uc0ac\uac01\ud615.png\",\"contentUrl\":\"https:\\\/\\\/atlaw.kr\\\/en-blog\\\/wp-content\\\/uploads\\\/sites\\\/3\\\/2025\\\/09\\\/\ud3f4\ub354-\uc0c1\ub2e8-\uc9c1\uc0ac\uac01\ud615.png\",\"width\":540,\"height\":485,\"caption\":\"Atlas Legal English Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/atlaw.kr\\\/en-blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/atlaw.kr\\\/en-blog\\\/#\\\/schema\\\/person\\\/184bcdecc06f89fd6c36b29781165b55\",\"name\":\"\ubc95\ubb34\ubc95\uc778 \uc544\ud2c0\ub77c\uc2a4\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f03bca99acfafded0c4fa1b01dee8839b10f831ccba39db4d9dc175f44d3d640?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f03bca99acfafded0c4fa1b01dee8839b10f831ccba39db4d9dc175f44d3d640?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f03bca99acfafded0c4fa1b01dee8839b10f831ccba39db4d9dc175f44d3d640?s=96&d=mm&r=g\",\"caption\":\"\ubc95\ubb34\ubc95\uc778 \uc544\ud2c0\ub77c\uc2a4\"},\"sameAs\":[\"https:\\\/\\\/atlaw.kr\"],\"url\":\"https:\\\/\\\/atlaw.kr\\\/en-blog\\\/author\\\/prinz001\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Voice Phishing Bank Liability in South Korea | Atlas Legal","description":"When a deceived customer transfers the money themselves, how far does a Korean bank's liability go? A KRW 2 billion claim dismissed, and when a bank is liable.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/atlaw.kr\/en-blog\/voice-phishing-bank-liability-south-korea\/","og_locale":"en_US","og_type":"article","og_title":"Voice Phishing Bank Liability in South Korea | Atlas Legal","og_description":"When a deceived customer transfers the money themselves, how far does a Korean bank's liability go? A KRW 2 billion claim dismissed, and when a bank is liable.","og_url":"https:\/\/atlaw.kr\/en-blog\/voice-phishing-bank-liability-south-korea\/","og_site_name":"Atlas Legal Blog","article_published_time":"2026-09-02T08:08:38+00:00","article_modified_time":"2026-09-02T08:09:20+00:00","author":"\ubc95\ubb34\ubc95\uc778 \uc544\ud2c0\ub77c\uc2a4","twitter_card":"summary_large_image","twitter_misc":{"Written by":"\ubc95\ubb34\ubc95\uc778 \uc544\ud2c0\ub77c\uc2a4","Est. reading time":"28 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/atlaw.kr\/en-blog\/voice-phishing-bank-liability-south-korea\/#article","isPartOf":{"@id":"https:\/\/atlaw.kr\/en-blog\/voice-phishing-bank-liability-south-korea\/"},"author":{"name":"\ubc95\ubb34\ubc95\uc778 \uc544\ud2c0\ub77c\uc2a4","@id":"https:\/\/atlaw.kr\/en-blog\/#\/schema\/person\/184bcdecc06f89fd6c36b29781165b55"},"headline":"KRW 2.1 Billion Left in Five Days \u2014 Why the Bank Owed Nothing","datePublished":"2026-09-02T08:08:38+00:00","dateModified":"2026-09-02T08:09:20+00:00","mainEntityOfPage":{"@id":"https:\/\/atlaw.kr\/en-blog\/voice-phishing-bank-liability-south-korea\/"},"wordCount":5665,"publisher":{"@id":"https:\/\/atlaw.kr\/en-blog\/#organization"},"keywords":["Bank Liability Korea","Electronic Financial Transactions Act","Fraud Detection System","Telecommunications Fraud Refund Act","Voice Phishing South Korea"],"articleSection":["Civil\/Administrative"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/atlaw.kr\/en-blog\/voice-phishing-bank-liability-south-korea\/","url":"https:\/\/atlaw.kr\/en-blog\/voice-phishing-bank-liability-south-korea\/","name":"Voice Phishing Bank Liability in South Korea | Atlas Legal","isPartOf":{"@id":"https:\/\/atlaw.kr\/en-blog\/#website"},"datePublished":"2026-09-02T08:08:38+00:00","dateModified":"2026-09-02T08:09:20+00:00","description":"When a deceived customer transfers the money themselves, how far does a Korean bank's liability go? A KRW 2 billion claim dismissed, and when a bank is liable.","breadcrumb":{"@id":"https:\/\/atlaw.kr\/en-blog\/voice-phishing-bank-liability-south-korea\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/atlaw.kr\/en-blog\/voice-phishing-bank-liability-south-korea\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/atlaw.kr\/en-blog\/voice-phishing-bank-liability-south-korea\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\ud648","item":"https:\/\/atlaw.kr\/en-blog\/"},{"@type":"ListItem","position":2,"name":"KRW 2.1 Billion Left in Five Days \u2014 Why the Bank Owed Nothing"}]},{"@type":"WebSite","@id":"https:\/\/atlaw.kr\/en-blog\/#website","url":"https:\/\/atlaw.kr\/en-blog\/","name":"Atlas Legal English Blog","description":"","publisher":{"@id":"https:\/\/atlaw.kr\/en-blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/atlaw.kr\/en-blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/atlaw.kr\/en-blog\/#organization","name":"Atlas Legal English Blog","url":"https:\/\/atlaw.kr\/en-blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/atlaw.kr\/en-blog\/#\/schema\/logo\/image\/","url":"https:\/\/atlaw.kr\/en-blog\/wp-content\/uploads\/sites\/3\/2025\/09\/\ud3f4\ub354-\uc0c1\ub2e8-\uc9c1\uc0ac\uac01\ud615.png","contentUrl":"https:\/\/atlaw.kr\/en-blog\/wp-content\/uploads\/sites\/3\/2025\/09\/\ud3f4\ub354-\uc0c1\ub2e8-\uc9c1\uc0ac\uac01\ud615.png","width":540,"height":485,"caption":"Atlas Legal English Blog"},"image":{"@id":"https:\/\/atlaw.kr\/en-blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/atlaw.kr\/en-blog\/#\/schema\/person\/184bcdecc06f89fd6c36b29781165b55","name":"\ubc95\ubb34\ubc95\uc778 \uc544\ud2c0\ub77c\uc2a4","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f03bca99acfafded0c4fa1b01dee8839b10f831ccba39db4d9dc175f44d3d640?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f03bca99acfafded0c4fa1b01dee8839b10f831ccba39db4d9dc175f44d3d640?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f03bca99acfafded0c4fa1b01dee8839b10f831ccba39db4d9dc175f44d3d640?s=96&d=mm&r=g","caption":"\ubc95\ubb34\ubc95\uc778 \uc544\ud2c0\ub77c\uc2a4"},"sameAs":["https:\/\/atlaw.kr"],"url":"https:\/\/atlaw.kr\/en-blog\/author\/prinz001\/"}]}},"_links":{"self":[{"href":"https:\/\/atlaw.kr\/en-blog\/wp-json\/wp\/v2\/posts\/1953","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/atlaw.kr\/en-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/atlaw.kr\/en-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/atlaw.kr\/en-blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/atlaw.kr\/en-blog\/wp-json\/wp\/v2\/comments?post=1953"}],"version-history":[{"count":1,"href":"https:\/\/atlaw.kr\/en-blog\/wp-json\/wp\/v2\/posts\/1953\/revisions"}],"predecessor-version":[{"id":1954,"href":"https:\/\/atlaw.kr\/en-blog\/wp-json\/wp\/v2\/posts\/1953\/revisions\/1954"}],"wp:attachment":[{"href":"https:\/\/atlaw.kr\/en-blog\/wp-json\/wp\/v2\/media?parent=1953"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/atlaw.kr\/en-blog\/wp-json\/wp\/v2\/categories?post=1953"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/atlaw.kr\/en-blog\/wp-json\/wp\/v2\/tags?post=1953"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}