Taiwan's National Police Agency rolled out an in-app directory of verified official LINE accounts inside the 165 anti-fraud hotline app this week, after paid social placements impersonated hotline branding well enough to funnel victims into fake consultant chats. NPA cyber staff briefed carriers and platform reps in a session reviewed by InfoHandle; the feature does not block malicious ads at the network edge but gives users a single tap to compare promoted pages against government-maintained account IDs.
What broke in the ad stack
Investigators logged dozens of Meta and Google ads using 165 logos, Traditional Chinese hotline slogans, and look-alike business names that differed by one character from legitimate agency pages. Victims who searched "anti fraud Taiwan" sometimes clicked sponsored results above organic links to the real portal. Attackers did not need to compromise police infrastructure—they bought ads with stolen payment cards and rotated landing URLs faster than takedown forms processed.
MODA's digital fraud task force tallies are not fully public yet; NPA slides cited a September spike in reported losses tied to impersonation creatives compared with August, without naming dollar totals.
What the app change does
The updated 165 app surfaces an official-account carousel before external search opens in an in-app browser. Each entry shows the LINE ID string, last verification timestamp, and scope notes—tax help versus investment-scam reporting. Users can long-press to copy the ID into LINE's friend-add screen rather than trusting ad deep links.
Platform takedown APIs still require police case numbers; the directory is a consumer-side patch while MOU talks on advertiser KYC continue.
Who must patch and disclose
Banks and insurers that run their own fraud-awareness ads were urged to register creative hashes with NPA so impersonators cannot reuse identical artwork without triggering faster review. FSC consumer teams will publish parallel verified lists for major lenders' LINE customer-service accounts.
Sam Rivera's desk tracks attribution conservatively: no agency has tied the September wave to a single APT label—assume financially motivated scam rings until law-enforcement indictments say otherwise.
Limits
Verified directories do not stop SMS smishing or voice calls spoofing caller ID. iOS users who never install the 165 app still rely on search-engine hygiene. Overseas ad buyers targeting Traditional Chinese speakers in Taiwan may never touch local payment rails investigators can freeze quickly.
Timeline
NPA will refresh verification timestamps weekly and push app notifications when a major impersonation campaign is detected. Public service announcements on cable news will show side-by-side comparisons of fake versus real LINE headers before Lunar New Year gift-card scams peak.
What users should do now
Add official accounts only through the 165 app list or URLs typed manually from printed government materials—not sponsored links. Report impersonation ads through the in-app form so case numbers feed platform escalations. If you already sent money, preserve chat logs and ad screenshots for prosecutors.
The impersonation fight is asymmetric: police cannot outbid scammers for ad slots indefinitely. Surfacing verified LINE IDs inside the app closes the easiest click path while platforms slow-walk advertiser identity rules—a small win before the next holiday transfer rush sends families back to search results they should not trust.
Platform coordination
NPA representatives said Meta and Google Taiwan teams agreed to expedite takedowns when police supply ad creative hashes, though response times still stretch over weekends. MODA is weighing whether impersonating government hotline trademarks in ad copy should trigger automatic account suspension pending review—a policy change that needs legal sign-off before year-end.
Retail banks will embed deep links to the verified LINE list inside mobile banking help menus, reducing the odds customers start from a search box when panic strikes after a suspicious message.








