Electronic Financial Transactions Act Violation Lawyer | Understanding the charge by the role you actually played
Summary
The Electronic Financial Transactions Act prohibits lending, borrowing, buying, selling, or storing access devices such as bank account passbooks, cards, certificates, and passwords for use by someone other than the account holder (전자금융거래법 제6조의3, 제49조 제4항). In practice, most cases arise when an account ends up being used as a "junk bankbook" (대포통장) in a voice phishing scheme. Because prosecutors and courts treat account sellers, renters, buyers and phishing organizers very differently, the very first step is correctly identifying which role the client is alleged to have played — this determines whether the case is a simple access-device offense or a fraud accomplice case carrying far heavier exposure.
Electronic Financial Transactions Act Violation | How the charge is structured
This is not a single offense — it covers several distinct acts, and which one is charged changes the available defenses.
What counts as an 'access device'
An access device includes bankbooks, cards, electronic certificates, PINs, and any credential used to access an account remotely. Lending, borrowing, transferring, storing, or advertising the transfer of these items is prohibited even if no fraud ultimately occurs (전자금융거래법 제6조의3).
Standalone violation vs. fraud accomplice
If a person merely sold or rented an account without knowing it would be used for phishing, they may face only the access-device violation under Article 49(4). But if investigators find evidence the person knew, or should have known, that the account would be used for a crime, prosecutors often add fraud or fraud-aiding charges under the Criminal Act, which carry substantially higher penalties.
Why intent and knowledge dominate the case
Because the statute itself does not require proof that a crime actually occurred with the account, the real battleground is usually the surrounding facts — how the account was advertised or offered for sale, what was said in chat logs, and how much money the person received for it. These facts are what separates a minor access-device case from a phishing-related fraud indictment.
Electronic Financial Transactions Act Violation | Seller, renter, buyer, or courier — the roles differ completely
Voice phishing organizations recruit people at every stage of the money-laundering chain, and the courts assess culpability differently for each.
Account seller / renter
Selling or renting out one's own account for cash is the most common charge under this Act and is treated as the core offense (전자금융거래법 제6조의3, 제49조 제4항). The key defense questions are whether the person understood the buyer's purpose and how many accounts or transactions were involved, since repeat conduct is treated more seriously than a single isolated transfer.
Account buyer / distributor
Buying up multiple accounts to resupply a phishing operation is treated as more organized conduct and frequently draws additional charges for aiding fraud, since the buyer's role is directly tied to enabling the withdrawal of victim funds.
Cash courier ('runner')
People recruited to withdraw cash from ATMs or collect money in person are often the ones actually arrested, even though they may have had limited knowledge of the larger scheme. Whether the courier is treated as a simple offender or an accomplice to fraud usually turns on what they were told about the job and whether warning signs were ignored.
Unwitting victims of a phishing scheme themselves
Some defendants were themselves deceived into believing they were doing legitimate part-time work (delivery, 'financial errand' jobs) and had no real understanding that the funds were criminal proceeds. Establishing this lack of intent, supported by messaging records and job postings, is often the single most important line of defense.
Electronic Financial Transactions Act Violation | Penalties and how related charges stack
Sentencing outcomes vary widely because this offense is frequently charged alongside other crimes.
Statutory penalty for the access-device offense
A person who violates the access-device provisions faces imprisonment of up to three years or a fine of up to 20 million won (전자금융거래법 제49조 제4항). Courts weigh the number of accounts involved, whether payment was received, and prior record.
Fraud and organized fraud exposure
If the account was used in an actual phishing withdrawal, additional liability can attach under the Criminal Act's fraud provisions, or under the Act on Aggravated Punishment for organized fraud groups, both of which carry heavier sentencing ranges than the access-device offense alone. This is where the seller-vs-accomplice distinction becomes critical.
Civil liability and joint compensation risk
Separately from criminal punishment, victims of the underlying phishing scheme can pursue civil claims against everyone in the money-laundering chain, including account sellers, as joint tortfeasors. This civil exposure can exist even in cases where criminal penalties are relatively light.
Electronic Financial Transactions Act Violation | From the first police contact to case resolution
1
Initial contact / summons Most clients first learn of the case through a phone call or written summons from a police financial crime unit, often referencing a bank account that received suspicious funds. Responding calmly and reviewing the notice before attending is the first priority.
2
Role and evidence review Before any interview, we review bank transaction records, messaging history, and how the account came to be used, to determine which role — seller, courier, or unwitting participant — the evidence actually supports.
3
Police and prosecutorial interview strategy Statements given at the police stage are frequently the basis for how prosecutors classify the case later, so preparing a consistent, accurate account of what the client knew and did not know at the time is central to the interview strategy.
4
Charge classification and negotiation We assess whether the case can realistically be limited to the access-device offense, or whether prosecutors are likely to add fraud-related charges, and adjust the defense — including restitution or settlement discussions with victims where appropriate — accordingly.
5
Trial or summary proceeding Depending on the number of accounts involved and prior record, the case may proceed by summary order (약식명령), or go to a formal trial where sentencing factors such as knowledge, profit received, and cooperation with the investigation are argued.
Electronic Financial Transactions Act Violation | How fees are structured for this type of case
Retainer fee Base fee is generally set according to the stage at which representation begins (police interview, prosecutorial investigation, or trial) and the complexity of the role-classification issue, since cases with a potential fraud-accomplice charge require substantially more evidence review than a straightforward access-device case.
Success fee Where applicable, a conditional fee may be agreed upon in advance, tied to a defined outcome such as a reduced charge, non-indictment, or a more favorable sentencing result, rather than any guaranteed result.
Victim restitution / settlement costs Separate from legal fees, some cases benefit from voluntary restitution or settlement with the victim of the underlying phishing scheme, which is budgeted and discussed separately as it affects sentencing outcomes.
Disbursements Costs such as record requests, transcription, and expert review of transaction data are billed separately based on actual usage.
※ Costs vary depending on case complexity and specific circumstances; exact fees will be provided during consultation. No specific outcome is guaranteed.
Electronic Financial Transactions Act Violation | Self-Check by Role
1️⃣ Account Seller / Renter Self-Check
Did you advertise or offer your account for transfer to someone else in exchange for money?
Do you have chat or call records showing what you were told the account would be used for?
How many accounts or repeat transactions were involved?
Did you receive any portion of the funds that later moved through the account?
2️⃣ Cash Courier ('Runner') Self-Check
Were you told this was a legitimate job (delivery, part-time financial work, etc.)?
Do you have a job posting, messaging app conversation, or recruiter contact that shows how you were recruited?
Did you personally withdraw or hand over cash, and if so, how much and how many times?
Were you aware of any red flags you may have ignored at the time?
3️⃣ First Contact From Police Self-Check
Has a formal summons been issued, or was this an informal phone call?
Have you already given any statement, written or verbal, before consulting a lawyer?
Do you know which specific account and transaction the investigation concerns?
Have you preserved your own bank and messaging records relevant to the account in question?
4️⃣ Facing Possible Fraud-Related Charges
Has a victim identified you specifically as connected to a phishing withdrawal?
Have you been asked about your knowledge of a broader organization or scheme?
Is restitution or settlement with a victim realistic in your case?
Do you have a prior record involving similar access-device or fraud offenses?
Frequently Asked Questions
Q. I only lent my account once for a small fee — can I still be charged?
A. Yes. The access-device provision does not require repeat conduct or a minimum amount; a single transfer of an account for payment can be enough to constitute a violation (전자금융거래법 제6조의3, 제49조 제4항). The number of accounts and amounts involved mainly affect sentencing, not whether a charge can be brought.
Q. I didn't know my account would be used for voice phishing. Does that matter?
A. It matters a great deal. Lack of knowledge that the account would be used for fraud is the central line of defense against being charged as a fraud accomplice, though it does not by itself remove liability for the access-device offense if you still transferred or sold the account improperly.
Q. What is the difference between this charge and being charged with fraud itself?
A. An Electronic Financial Transactions Act violation concerns the act of trading or lending an access device itself. Fraud charges under the Criminal Act require proof that the person knowingly participated in deceiving a victim to obtain money. Prosecutors add fraud charges only when evidence suggests the person knew, or should reasonably have known, the account's criminal purpose.
Q. I was recruited online for 'easy part-time work' and just withdrew cash from ATMs. Am I a criminal or a victim?
A. This is one of the most common and difficult situations in these cases. Investigators will look at your messaging history with the recruiter, how the job was described, and how much you were paid, to decide whether you are treated as an unwitting participant or as someone who ignored obvious warning signs.
Q. Can I avoid indictment if I return the money I received?
A. Returning proceeds and cooperating with the investigation can be considered favorably in a prosecutor's charging decision or in sentencing, but it does not guarantee non-indictment, since the number of accounts, prior record, and the presence of a related fraud victim are also weighed.
Q. Will I go to jail for this?
A. Outcomes vary widely. First-time offenders involved in a single account transfer with no resulting fraud loss are frequently handled through a summary fine order (약식명령), while repeat account sellers or those connected to organized phishing rings face a materially higher risk of imprisonment.
Q. Is this charge separate from any administrative penalty on my bank account?
A. Yes. Independently of the criminal case, banks and financial authorities can freeze the account or restrict the account holder from opening new accounts for a period of time, which is an administrative measure separate from criminal punishment.
Q. The police only contacted me by phone. Should I go in immediately?
A. You are generally not required to respond to an informal phone inquiry the same way you would to a formal summons, but ignoring repeated contact can lead to a warrant being sought. It is best to review the situation with a lawyer before making a statement, since early statements are difficult to walk back later.
Q. Can a settlement with the phishing victim help my case?
A. Where a case involves an identifiable victim's financial loss, voluntary restitution or a settlement can be a meaningful sentencing factor, though its effect depends on the victim's willingness to settle and the overall facts of the case.
법무법인 프런티어(이하 “사무소”)는 개인정보보호법에 따라 정보주체의 개인정보 및 권익을 보호하고 개인정보와 관련된 정보주체의 고충을 신속하고 원활하게 처리하기 위하여 본 개인정보 처리방침을 수립·공개합니다.
제 1 조 수집하는 개인정보의 항목, 목적, 방법
제 2 조 개인정보의 처리 및 보유기간
제 3 조 개인정보의 제3자 제공
제 4 조 개인정보 처리업무의 위탁
제 5 조 정보주체의 권리·의무 및 그 행사방법
제 6 조 개인정보의 파기
제 7 조 의견수렴 및 불만처리
제 8 조 개인정보 처리방침의 변경
제 9 조 개인정보의 안전성 확보 조치
제 1 조 (수집하는 개인정보의 항목, 목적, 방법)
① 게시판 글 작성 시 필수 항목에 대한 수집목적은 ‘별도의 구체적 상담을 위하여’이며 수집항목은 ‘이름, 이메일, 연락처’입니다.
② 전항 외에 고객의 서비스 이용 과정이나 요청 사항 처리 과정에서 ‘IP주소, 접속로그, 단말기 및 환경정보, 서비스 이용기록, 쿠키’와 같은 정보들이 자동으로 수집 및 저장될 수 있으며, 이 때의 수집목적은 ‘사용자 홈페이지 이용, 사이트 이용에 대한 문의 민원 등 고객 고충 처리’입니다.
③ 사무소는 ‘홈페이지 고객 문의/고충 처리 시 전화 또는 인터넷을 통한 상담’과 같은 방법으로 개인정보를 수집합니다
제 2 조 (개인정보의 처리 및 보유기간)
관계법령의 규정에 따라 개인정보를 보존하여야 하는 의무가 있는 경우가 아닌 한, 정보주체의 개인정보는 원칙적으로 해당 개인정보의 처리목적이 달성될 때까지 보유 및 이용되며, 그 목적이 달성되면 지체 없이 파기됩니다.
제 3 조 (개인정보의 제3자 제공)
사무소는 정보주체의 개인정보를 본 처리방침에서 명시한 목적에 한해서만 처리하며 정보주체의 사전동의가 있는 경우 또는 개인정보보호법 등 관계법령의 규정에 의거한 경우에만 개인정보를 제3자에게 제공합니다. 사무소는 현재 개인정보를 제3자에게 제공하지 않고 있습니다.
제 4 조 (개인정보 처리업무의 위탁)
사무소는 현재 귀하의 개인정보 보호를 위해 귀하의 개인정보를 직접 취급 관리하고 있습니다. 단, 향후 보다 전문적인 서비스를 제공하기 위하여 제3의 전문기관에 귀하의 정보를 위탁할 필요가 있다고 판단되는 경우, 귀하의 사전 동의 하에 개인정보에 대한 취급을 위탁할 수 있습니다.
제 5 조 (정보주체의 권리·의무 및 그 행사방법)
① 정보주체는 개인정보보호법 등 관계법령이 정하는 바에 따라 사무소에 대해 개인정보의 열람, 정정 및 삭제, 처리정지 요구 등 개인정보 보호 관련 권리를 행사할 수 있습니다.
② 제1항에 따른 권리행사는 정보주체의 법정대리인이나 위임을 받은 사람을 통해서도 할 수 있습니다. 다만, 이 경우에는 개인정보보호법 시행규칙에 따른 위임장을 사무소에 제출하여야 합니다.
③ 사무소는 정보주체의 권리행사에 대하여 개인정보보호법 등 관계법령이 정하는 바에 따라 지체 없이 조치하겠습니다.
제 6 조 (개인정보의 파기)
① 사무소는 원칙적으로 개인정보의 처리목적이 달성된 경우 등 그 개인정보가 불필요하게 되었을 때에는 지체 없이 해당 개인정보를 파기합니다.
② 사무소가 관계법령의 규정에 따라 개인정보를 파기하지 아니하고 보존하여야 하는 경우에는 해당 개인정보 또는 개인정보파일을 다른 개인정보와 분리해서 저장·관리 합니다.
③ 사무소는 파기사유가 발생한 개인정보를 선정하여 개인정보 보호책임자의 승인을 받아 해당 개인정보를 파기합니다.
④ 사무소는 파기하여야 할 개인정보가 전자적 파일 형태인 경우 복원이 불가능한 방법으로 영구 삭제하며, 이외의 기록물, 인쇄물, 서면, 그 밖의 기록매체인 경우 파쇄 또는 소각합니다.
제 7 조 (의견수렴 및 불만처리)
정보주체는 개인정보 보호 관련 문의, 불만처리, 피해구제 등에 관한 사항을 아래 개인정보 보호책임자 또는 담당부서에 문의하실 수 있습니다. 사무소는 정보주체의 문의에 대하여 신속하고 충분한 답변을 드릴 것입니다.
개인정보 보호 책임자 : 변호사
연락처 : 02.
제 8 조 (개인정보 처리방침의 변경)
사무소의 개인정보 처리방침은 관련 법령, 지침 및 사무소 내부규정에 따라 변경될 수 있으며, 개인정보 처리방침이 변경되는 경우 관련 법령이 정하는 방법에 따라 공개합니다.
제 9 조 (개인정보의 안전성 확보 조치)
사무소는 개인정보의 안전성 확보를 위해 다음과 같은 조치를 취하고 있습니다.
관리적 조치 : 내부관리계획의 수립 및 시행, 구성원에 대한 정기적인 개인정보 보호교육 등
기술적 조치 : 개인정보처리시스템 등의 접근권한 관리, 접근통제시스템 설치, 고유식별정보 등의 암호화, 보안프로그램의 설치 등
물리적 조치 : 전산실, 자료보관실 등 개인정보 보관장소에 대한 접근통제