South Korean snipers stand guard while US

South Korean snipers stand guard while the US president visits an observation post in the Demilitarized Zone June 30, 2019, in Panmunjom, Korea.
BRENDAN SMIALOWSKI/AFP via Getty Images

South Korea launched a new military counterintelligence structure on Monday, formally dissolving the Defense Counterintelligence Command (DCC) — an agency that twice helped prop up authoritarian coups — and replacing it with three separate bodies whose explicit first mandate is to protect artificial intelligence systems and satellite infrastructure from foreign espionage. The institutional overhaul is the most consequential restructuring of South Korean military intelligence in nearly five decades — and it arrives at the precise moment the country’s satellite reconnaissance network has become genuinely worth stealing.

Same Name, Same Building, New Rules — and a Changed Mission

The launch ceremony took place Monday at the former DCC’s headquarters in Gwacheon, Gyeonggi Province, about 12 miles (19 km) south of Seoul. Defense Minister Ahn Gyu-back attended and presented the unit flag to Maj. Gen. Pyun Moo-sam, the agency’s inaugural director, who had served as acting commander of the now-defunct command during its wind-down.

The new centerpiece organization, the Defense Counterintelligence Agency (DCA), identifies and assesses threats — collecting and analyzing intelligence on suspected espionage, foreign intelligence activity, and threats targeting defense companies and military technology. The DCC’s two other former functions, now separated out to prevent any recurrence of political misuse, go to a new Defense Security Support Group (internal security audits of corps-level and higher units) and to a dedicated security investigation unit inside the existing Criminal Investigation Command (arrests, searches and seizures, prosecution of suspected espionage and National Security Act violations). The Korea Herald’s reporting on the three-body structure confirms that all three functions were formerly housed under a single command.

Under the old system, one agency controlled all three functions. The government’s stated rationale for splitting them: no single organization should ever again be able to gather intelligence on political opponents, investigate them, and pursue criminal charges — all without meaningful civilian oversight.

The ministry also named three specific technology domains the DCA is responsible for protecting: artificial intelligence systems, satellite infrastructure, and defense industry secrets. That last mandate includes security coverage for US Navy maintenance, repair, and overhaul programs the South Korean military is jointly pursuing with American counterparts.

What the DCA Is Now Guarding

The satellite piece of that mandate is not abstract. South Korea’s Project 425, a military space reconnaissance program funded at approximately ₩1.3 trillion (approximately $900 million USD), reached full operational status in November 2025 when the fifth and final satellite entered orbit aboard a SpaceX Falcon 9 rocket from Cape Canaveral.

The constellation comprises one electro-optical and infrared (EO/IR) satellite and four synthetic aperture radar (SAR) satellites. SAR imaging — which uses radio pulses rather than visible light — works through clouds and in complete darkness, giving the constellation all-weather, around-the-clock surveillance capability over the Korean Peninsula. Each SAR satellite carries a Thales Alenia Space payload built around a 5-meter deployable antenna folded into 24 petals that opens in orbit to form a parabolic dish, achieving a resolution of roughly 30 centimeters per pixel (about 12 inches) — sufficient to distinguish individual vehicles at North Korean missile facilities.

Before Project 425, South Korea had no independent satellite imagery of North Korean military activity; it depended entirely on U.S. intelligence-sharing for real-time surveillance. The five-satellite constellation changed that equation — and in doing so, created a high-value intelligence target that North Korean and Chinese intelligence services have strong incentives to penetrate.

The current constellation allows revisit coverage of any point on the Korean Peninsula approximately every two hours. South Korea is already planning a follow-on program of 19 additional small and ultra-small reconnaissance satellites intended to compress that interval to 30 minutes, closing a window wide enough for a road-mobile ballistic missile launcher to move and hide.

Protecting AI in a Space the Law Cannot Reach

The DCA’s AI protection mandate has a structural twist that matters to anyone tracking South Korean defense policy. South Korea’s Framework Act on Artificial Intelligence Development and Establishment of Trust — the AI Basic Act, which took effect January 22, 2026, and made South Korea the first Asia-Pacific country to enact comprehensive AI legislation — explicitly exempts AI systems developed and deployed exclusively for national defense or security purposes from its regulatory framework.

The Enforcement Decree goes further: it specifically names counterintelligence affairs as excluded from the act’s scope.

The practical effect is that the DCA’s AI counterintelligence tools — the systems it uses to detect foreign infiltration of South Korean defense AI programs — are governed by no civilian regulatory body. The only oversight mechanism is parliamentary accountability, which the reform’s critics acknowledge remains underdeveloped. That is not a criticism unique to South Korea; most democracies that have separated CI collection from prosecution have also struggled with the question of who watches the watchers once the watching is split across three agencies that all report to the same minister.

How South Korea Got Here: Three Generations of the Same Problem

The DCC’s lineage stretches back to 1977, when it was established as the Military Security Command under the authoritarian government of Park Chung-hee. The institution’s darkest chapter came quickly: in December 1979, following Park’s assassination, then-Major General Chun Doo-hwan, commanding the Defense Security Command (the precursor organization), used his intelligence authority to arrest the Army chief of staff on fabricated charges and seize control of the military — triggering a coup that led to seven more years of dictatorship. Chun’s ally in that operation, Roh Tae-woo, would also later become president. Both had commanded the institution that the DCA now replaces.

Reform efforts followed that 1979 episode, and again in 2018, when a martial law contingency document surfaced that the then-command had reportedly prepared. Each time, the organization was renamed — from Military Security Command to Defense Security Command (1991) to Defense Security Support Command (2018) to Defense Counterintelligence Command (2022) — but the concentration of authority under a single chain of command survived every reorganization.

On December 3, 2024, that pattern repeated itself. Then-President Yoon Suk Yeol declared emergency martial law in a televised address; DCC personnel were among the forces deployed to the National Assembly and the National Election Commission; court proceedings have alleged that the agency helped plan operations targeting opposition lawmakers for potential detention. More than 190 lawmakers reached the chamber and voted to lift the decree within hours.

Lt. Gen. Yeo In-hyung, the DCC’s commander, was arrested within two weeks and has since been indicted on treason-related charges. Yoon himself faces insurrection charges for which prosecutors have sought the death penalty.

The DCC was formally dissolved July 31, 2026. Monday’s ceremony completed the transition.

Can Three Agencies Do What One Did — Faster?

The government’s structural logic for the three-way split is straightforward and defensible: preventing any single agency from controlling intelligence gathering, security oversight, and criminal investigation simultaneously is how every advanced democracy that has solved this problem solved it. The UK’s domestic counterintelligence service (MI5) does not have arrest powers; it relies on police for that. The U.S. separates the FBI (domestic CI and arrest authority), the CIA (offensive CI), and the Diplomatic Security Service (personnel and facility protection). Canada explicitly separates defensive counterintelligence from law-enforcement intelligence into separate mandates.

South Korea’s three-way split follows this pattern. The design challenge it faces is the same one those countries face: what happens when a case begins with fragmentary signals that cannot yet justify a formal criminal investigation? In CI work, the standard sequence runs from suspicious indicator to monitored contact to intelligence case to criminal case — and each handoff is a moment when a tip-off can occur or evidence can disappear. Under the old DCC, all three functions were housed in the same building; under the new structure, they require interagency coordination that has to be built deliberately.

Seok Jae-wang, a professor in the Department of Disaster and Security Management at Konkuk University, said a formal standing body bridging the three organizations would be essential. Seok told the Korea Herald that the most desirable approach would be to establish a standing intelligence and investigation consultative body involving the National Intelligence Service, the Criminal Investigation Command and the police, modeled on systems used in other advanced countries.

The ministry said it plans to establish formal guidelines governing when intelligence should be transferred between agencies and will operate consultative mechanisms to bridge the gap. A Defense Ministry official, speaking without attribution, acknowledged the structural tension: while operational authority has been divided, the defense minister still holds ultimate control over all three organizations.

Does South Korea’s New Espionage Law Help?

The DCA’s launch coincides with a significant expansion of South Korea’s legal toolkit for handling exactly the threats it is now charged with detecting. In February 2026, the National Assembly passed an amendment to Article 98 of the Criminal Act that, for the first time in 73 years, expands the definition of espionage from acts committed for an “enemy country” — which South Korean courts had interpreted narrowly to mean North Korea — to acts committed for any foreign country or equivalent organization.

The amendment, which will take effect September 13, means that when the DCA detects a suspected defense technology leak to China — the source of an estimated 110 documented industrial technology theft cases from 2020 through the first half of 2025, causing an estimated ₩23.27 trillion (approximately $16.1 billion USD) in industrial damage per government data — the Criminal Investigation Command’s new security unit can pursue espionage charges rather than the lesser offense of technology theft. The previous framework had made it nearly impossible to bring espionage charges for leaks to any state except North Korea.

The practical effect: the DCA is the initial detection agency; the CIC unit is the prosecution mechanism; and the expanded espionage law is the legal authority that now connects them for cases involving any foreign adversary, not just Pyongyang.

What Does This Mean for South Korean Defense Technology Security?

The reform’s advocates have a credible structural argument. The DCA cannot arrest anyone; it can only detect and assess. The Defense Security Support Group cannot prosecute anyone; it can only audit. The CIC unit can prosecute — but only once the other two have passed a case to it. This three-way dependency is not a bug; it is the feature, explicitly designed so that no defense minister can again direct a single agency to simultaneously identify political opponents, gather evidence against them, and throw them in a detention facility.

What critics cannot yet resolve is whether that structural clarity will survive the operational tempo of real-world counterintelligence. Technology theft cases, in particular, move fast: a defense industry employee with access to Project 425’s SAR architecture data who contacts a suspected foreign intelligence operative needs to be caught before the data leaves the building. Under the old DCC, that detection-to-interdiction cycle happened inside a single command. Under the new structure, it requires a handoff between at least two of the three agencies — and if that handoff protocol is not yet established, the window for a suspect to disappear evidence is exactly as wide as the gap between agencies.

The DCA’s explicit mandate to protect AI systems that South Korea’s own civilian AI law is not permitted to oversee, combined with a satellite constellation that represents roughly $900 million USD in intelligence infrastructure, means that the coordination protocol the defense ministry has promised to build is not a bureaucratic detail. It is the mechanism by which Project 425’s investment either pays off in operational security or gets walked out the door to a competitor.

Exchange rate as of August 3, 2026; conversions are approximate.

Frequently Asked QuestionsWhy was the Defense Counterintelligence Command dissolved after 49 years?

The immediate trigger was the agency’s role in former President Yoon Suk Yeol’s December 3, 2024 martial law declaration, when its personnel were deployed to the National Assembly and National Election Commission in an alleged plan to detain opposition legislators. Investigations and court proceedings confirmed the command was used as an instrument of political power — a pattern that had repeated itself since the same institution’s predecessor helped Chun Doo-hwan execute the December 12, 1979 coup. After each prior scandal, the agency was renamed but its concentrated authority remained intact. This time, the government chose to split the authority structurally rather than rename it again.

What is the Defense Counterintelligence Agency now explicitly tasked with protecting?

The DCA’s stated mandate covers three technology domains: artificial intelligence systems used in defense applications, satellite infrastructure (specifically South Korea’s Project 425 SAR reconnaissance constellation), and defense industry secrets. It also covers security support for joint U.S.-South Korean Navy maintenance and overhaul programs. The DCA can detect and assess threats in these domains but no longer controls the investigative or prosecutorial machinery to pursue criminal cases — that now belongs to the Criminal Investigation Command’s dedicated security unit.

Why does South Korea’s AI law not cover the DCA’s AI tools?

South Korea’s AI Basic Act — the first comprehensive AI legislation in Asia-Pacific, which took effect January 22, 2026 — explicitly exempts AI systems developed and deployed exclusively for national defense or security purposes from its regulatory framework. The Enforcement Decree specifically names counterintelligence affairs as an excluded function. The DCA therefore operates in a regulatory space that South Korea’s own civilian AI governance structure cannot reach, making parliamentary oversight the only external accountability mechanism. Experts and reform critics note this oversight mechanism has not yet been fully developed.

Can the three-way split of counterintelligence functions stop a fast-moving technology theft?

That is the core operational question the reform leaves open. The split is designed to prevent political abuse — and on that metric, its structural logic is sound and mirrors models used by the UK, U.S., and Canada. The concern raised by experts including Konkuk University’s Seok Jae-wang is that counterintelligence cases typically begin with fragmentary signals, not hard evidence, and the handoff between the detection agency (DCA), the audit agency (Defense Security Support Group), and the prosecution unit (Criminal Investigation Command) requires coordination protocols that must be deliberately built. The Ministry of National Defense has said it plans to establish formal transfer guidelines and operate consultative mechanisms between the agencies; those mechanisms are not yet in place.