As Typhoon Dujuan pushed nearly two million people under evacuation orders and advisories across eastern Japan, Tokyo Metropolitan Police warned that scammers are piggybacking on disaster anxiety with text messages that look like urgent evacuation instructions. The advisory, amplified through ward-level crime-prevention networks on Sept 21, does not describe a new storm—it describes a familiar impersonation playbook retimed for a five-day holiday when families are moving between trains, hotels, and hometowns.

What the fake messages claim

Police said reported variants use urgent Japanese phrasing borrowed from real disaster communications: instructions to “evacuate immediately,” references to landslide or flood risk, and links that pretend to show shelter maps or municipal registration pages. Some texts spoof sender labels associated with weather or city services; others arrive after phones briefly drop signal in dense urban areas—a pattern the Ministry of Internal Affairs and Communications has linked to illegal “fake base station” interference in Tokyo and other cities.

Real evacuation information during Dujuan has flowed through municipal websites, disaster radio, and official apps keyed to prefecture and ward boundaries. Japan Meteorological Agency bulletins and J-Alert warnings are authoritative; they do not ask residents to log into unfamiliar URLs sent from anonymous mobile numbers.

What legitimate alerts do not ask for

Metropolitan police repeated baseline rules that typhoon season makes more consequential: officers do not demand bank transfers by SMS, and disaster agencies do not require credit-card verification to “confirm” an evacuation zone assignment. If a message pressures immediate payment, credential entry, or installation of an unknown app, treat it as fraud even when the Japanese looks polished.

The National Police Agency’s broader special-fraud statistics show government impersonation remains a major loss category; typhoon weeks add plausible urgency that overrides ordinary skepticism. Travelers checking on elderly relatives in Chiba or Kanagawa—prefectures already reporting landslide damage—are prime targets for “confirm your safety registration” lures.

Technical overlap with phishing SMS waves

MIC’s public warning on fake-base-station interference notes sudden loss of service followed by suspicious SMS, often phishing for banking or payment credentials. Police did not assert that every fraudulent evacuation text originates from IMSI-catcher gear, but they told travelers not to assume a message is genuine simply because it arrived during an outage.

Carrier advisories from NTT Docomo, KDDI, SoftBank, and Rakuten Mobile repeat the same countermeasure: do not tap links; open official apps or bookmarked municipal pages manually. The Tokyo advisory adds a storm-specific line—cross-check any evacuation order against your ward’s published list before changing travel plans based on a single text.

What travelers should do instead

Use the Metropolitan Government’s disaster portal and prefectural sites for shelter status; enable official push alerts where available. If a message cites a ward name, call the ward office on a number you look up yourself, not a callback number embedded in the SMS.

Victims who entered credentials should contact their bank immediately, preserve screenshots with timestamps, and report to local police or the consumer hotline. Sharing screenshots in group chats helps family members more than forwarding the link itself.

Silver Week mobility already collides with JR East suspensions on several Chiba lines and widespread flight delays at Haneda. Fake evacuation texts exploit that friction—they do not create new hydrological risk, but they can scatter households away from real shelters or drain accounts when people act before verifying. The knowable defense is procedural: treat SMS evacuation orders as untrusted until a second official channel confirms them.