Japan’s mega-banks should stop sending vague “beware of fake sites” bonus alerts and start publishing the exact spoofed deposit domains they see each week—because generic warnings train customers to trust sender names when payroll SMS traffic peaks. The Japan Bankers Association’s boilerplate is legally safe and practically useless: it tells people to check URLs without showing which URLs are hunting them today.
Generic alerts fail when timing is precise
Every September, MUFG, SMBC, and Mizuho blast customers about fraudulent bonus-deposit pages. The messages rightly note that real banks never ask for full passwords by email. What they omit is the homoglyph domains registered forty-eight hours earlier—domains police later list in aggregate statistics months after money moves to Laos mule accounts.
JPCERT’s phishing summaries show financial lures spike the week employers file bonus payment files. Attackers know which kanji appear in legitimate notices; they copy layout and swap one character in the hostname. A customer who memorized “look for the green lock” still taps a link when the SMS arrives between train stops.
What banks already collect
Institutions operate takedown desks that feed domain abuse tickets to registrars within hours. That data rarely reaches account holders. Compliance teams fear naming domains could defame innocent similar strings—a reasonable objection if lists were static. They are not; they rotate daily. Publishing a rolling seven-day roster of confirmed spoofs, with registration timestamps, would arm customers without pretending the internet is safe.
The National Police Agency’s English cyber pages document the same pattern: victims report “it looked like my bank’s bonus page.” Investigators then scrape domains from seized phones. By then, balances are gone.
Strongest objection
Banks argue that listing domains educates criminals to iterate faster. That objection assumes criminals lack DNS tools—they do not. Secrecy only preserves the advantage for scammers who already A/B test faster than compliance committees meet. Transparency shifts the contest toward customer habit: compare the domain on the SMS to the list on the bank’s official app homepage, not to memory.
Another objection: elderly users will be confused. Confusion is worse when alerts speak in abstract nouns. A named domain with a screenshot of the fake login box is concrete; “phishing risk” is not.
What we are not saying
This editorial does not demand banks reimburse every fooled customer—liability rules belong to regulators and courts. We are not calling SMS bonuses obsolete; they are too embedded in payroll culture. We are saying the largest banks, which already spend billions on SOC staff, owe a specific public feed as basic as FX rate boards in branches.
Concrete steps
The Japan Bankers Association should require members to post weekly spoof-domain CSVs through a shared portal mirrored on each bank’s app. FSA should treat publication as a positive factor in cyber examinations, not a nice-to-have press release. Employers filing bonus data should link to that portal in payslip footers—one line, no marketing adjectives.
Until then, customers should ignore every bonus-deposit link and log in only through bookmarks saved before September. Mega-banks have the domain intelligence to make that habit easier; withholding it protects pride, not accounts.








