Tokyo Metropolitan Police arrested six men and women this week for running a network of fake Mobile Suica recharge websites that mimicked JR East’s green branding closely enough to fool automated fraud filters, stealing credit-card and PayPay credentials from more than 2,400 users since January. Detectives said the ring netted roughly ¥186 million before banks flagged velocity spikes tied to Silver Week advance ticket purchases.

How the sites mimicked JR East

Investigators said suspects registered domains one character off official Mobile Suica URLs and copied cascading style sheets from archived JR East pages so mobile browsers displayed familiar typography even after the railway company updated its real portal. Victims arrived via search-engine ads bidding on keywords like “Suica charge failed” and “Pasmo balance error,” phrases that spike when commuters retry payments on crowded platforms.

Unlike crude phishing, the fake flows asked for three-yen test charges—a figure JR East sometimes uses for card verification—then stored primary account numbers on offshore VPS hosts rotated every seventy-two hours. Police seized ledgers showing JSON webhooks forwarding tokens to accomplices in Osaka who laundered proceeds through cryptocurrency ATMs in Shinjuku and Yokohama.

Victim profile and harm

More than sixty percent of identified victims were over sixty-five, according to briefing materials shared with ward offices. Many clicked links embedded in SMS messages claiming their IC balances were too low for Reserved Seat Smart EX renewals ahead of Respect for the Aged Day travel. Consumer Affairs Agency counselors said several retirees lost entire monthly pension deposits before family members noticed duplicate withdrawals.

JR East confirmed it never requests full card re-entry on third-party domains and reiterated that legitimate Mobile Suica top-ups occur only inside its official app or registered e-commerce partners listed on jreast.co.jp. The railway filed a trademark infringement complaint that helped police obtain hosting takedowns, but mirrored sites reappeared within hours until Tuesday’s arrests.

Police operation

The Cybercrime Division II unit traced payment acquirers after a Meguro ward bank shared anonymized fraud typologies in July. Undercover officers purchased decoy ad clicks, capturing TLS certificates that linked four suspects who rented a Shibuya coworking mail drop. Search warrants executed Monday in Tokyo, Saitama, and Fukuoka recovered laptops running automated site generators and chat logs negotiating ad spend on foreign platforms.

Charges include fraud, violation of the Unfair Competition Prevention Act through trademark misuse, and organizing prohibited electronic transfers. Police did not allege JR East system breaches; the crime stayed entirely on cloned customer-facing pages.

Platform and regulator response

Search providers told InfoHandle they removed several thousand ad creatives after police notices, but keyword auctions resume quickly when new accounts appear. The National Police Agency plans to add Suica-themed lures to its autumn phishing alert bulletin distributed through convenience-store receipt printers—a channel that reached elderly users effectively in 2025 lottery scams.

PayPay said it tightened device fingerprinting for repeat three-yen authorizations and will push in-app warnings when users copy-paste card numbers after visiting non-allowlisted domains. Mobile carriers agreed to delay delivering SMS links that contain freshly registered domains less than forty-eight hours old, a stopgap until real-name ad registry rules expand in 2027.

What commuters should verify

Detectives urged users to open the official Mobile Suica app from the home screen icon rather than search results, and to confirm publisher certificates displaying “East Japan Railway Company” on iOS or the packaged Android signature listed by JR East. Ward offices will host Silver Week clinics where staff demonstrate the difference between legitimate receipt emails and phishing copies missing randomized transaction IDs present on real JR East messages.

Broader IC card fraud trend

Transit card phishing remained rare compared with bank transfer scams, but Tokyo police statistics show a fourfold rise in IC-themed reports since contactless spending limits increased last year. Criminals pivot as EMV three-domain secure flows block simple clone sites; transit top-ups remain emotionally urgent when gates beep at rush hour.

For Tokyo commuters, the bust underscores a seasonal pattern: travel holidays bring legitimate balance anxiety, and fake Suica pages exploit that urgency faster than platform moderation can keep up—making offline verification habits as important as any backend fraud score.