Seoul Metropolitan Police arrested nine people Tuesday for allegedly running Telegram “forex signal rooms” that recruited university investment clubs with fake internship certificates and drained student brokerage accounts through unregistered offshore MetaTrader servers, after Kookmin Bank and Woori Bank flagged mule flows tied to campus KakaoOpenChat invites ahead of Chuseok break.

What broke

According to an SMPA cybercrime unit briefing, organizers posed as licensed asset managers and offered “research internships” to economics and business societies at three capital-region universities. Students who joined were told to open domestic securities accounts, deposit seed capital, and install remote-desktop tools so “senior traders” could execute FX strategies on their behalf. Instead, operators wired funds through nested personal accounts to crypto on-ramps in Singapore and Lithuania, police said.

Investigators seized 214 smartphones, 41 laptops, and ledgers listing club presidents as “campus ambassadors” paid 300,000 won per successful recruit. Losses reported so far exceed 2.8 billion won across 126 victims, though police believe many students have not filed statements because parents paid off margin calls quietly.

What police confirmed

SMPA said the rooms rotated Telegram handles weekly and used voice-changer bots during live “market open” streams to mimic Wall Street trading floors. Promotional PDFs copied FSS disclosure fonts but cited fake registration numbers; FSS confirmed none of the organizers held investment adviser licenses. Woori’s anti-fraud unit linked 19 accounts to the same device fingerprint used in a March voice-phishing case in Incheon, suggesting infrastructure reuse across scam types.

Universities named in the briefing were not publicly identified to protect ongoing student interviews, but police said two club faculty advisers received warning letters for hosting sponsor fairs without verifying employer credentials—a administrative step, not criminal liability.

Who has the file

The Korea Financial Intelligence Unit received suspicious transaction reports from five banks and is tracing crypto wallets through exchange travel-rule messages. FSS opened a parallel administrative case against a domestic securities firm whose remote-trading waiver was allegedly abused by two defendants who worked as part-time customer service contractors—exposing gaps in maker-checker controls on high-risk account flags.

Consumer Agency officials said they will push app-store takedowns for cloned MT4 installers distributed in the Telegram rooms; Apple and Google compliance teams received hash lists Monday.

Prosecutors are expected to charge violations of the Financial Investment Services and Capital Markets Act, the Electronic Financial Transactions Act, and organized-crime statutes if leaders prove hierarchical roles. Student victims who knowingly lent accounts could face minor aiding charges, though SMPA said most cooperators are treated as witnesses if they report early.

Lawyers for investment clubs told InfoHandle societies should ban external “sponsored traders” from group chats and require compliance officers to vet any firm offering internships tied to live trading—a policy only two of the affected clubs had on paper.

What is still unknown

Police have not identified overseas wallet custodians beyond exchange correspondence. Total victim count may rise when universities reopen after Chuseok; SMPA set up anonymous reporting kiosks at two campuses. It is unclear whether faculty advisers knew trading was live rather than simulated; interviews continue.

What students and banks should do

FSS repeated that unregistered FX margin trading marketed through messaging apps is illegal regardless of promised returns. Banks must block remote-desktop sessions originating from known scam ASNs—a control Kookmin piloted in August after university mule spikes. Clubs should treat any offer requiring account credentials as disqualifying, not a résumé line.

Chuseok travel will slow depositions; SMPA expects indictments in October. For now, the file sits with Seoul cyber prosecutors, the FIU, and embarrassed campus treasurers who learned investment clubs can be front doors for Telegram forex rooms dressed as career development.

Near-term checkpoints

FSS will publish a targeted advisory to university registrars before midterm season, naming red flags from this case: internship badges without CRN numbers, MT4 installs sideloaded from chat links, and “profit sharing” contracts referencing offshore entities. Banks agreed to share hashed Telegram invite URLs through the joint fraud intel channel opened after the LS Securities email scandal—another sign campus scams are converging with capital-markets social engineering.