The Korea Internet & Security Agency issued a Chuseok banking smishing alert Wednesday describing a wave of text messages that mimic family gift transfers and bank fraud desks, asking recipients to tap links or share one-time passwords while holiday travel disrupts normal verification habits.
What KISA confirmed
Agency bulletins list message templates referencing “Chuseok gift money,” “cousin arriving early,” and “security upgrade before long weekend,” none tied to named suspects or individual arrest warrants. KISA treats the activity as an organized campaign rotating domains and sender IDs, not accusations against any specific cardholder or small business.
Financial Supervisory Service parallel notices remind banks not to request full PINs or transfer passwords via SMS—legitimate issuers use in-app prompts with signed certificates. National Police Agency cyber units said report volume rose through Tuesday but did not release suspect identities, citing open investigations.
How the lures work
Smishing texts often arrive after public social posts about travel plans, suggesting criminals scrape open holiday check-ins rather than breached bank databases. Links lead to cloned mobile banking pages that harvest credentials before two-factor codes expire. Some messages instruct victims to forward “verification deposits” to mule accounts disguised as family members.
KISA emphasized that genuine holiday gifts arrive through known contacts and established bank apps, not urgent links sent minutes before highway departures. Dongwook Han’s security lens: confirmed facts stop at agency warnings and report trends—anything about masterminds or overseas syndicate names remains unverified chatter unless prosecutors file charges.
What households should do
Call family members on voice lines to confirm gift requests, use official app store downloads only, and report phishing numbers to 118 (KISA) or 1332 (financial fraud). Freeze cards through issuer apps if a link was tapped, even when no charge yet appears.
Elderly relatives receiving Chuseok allowances should get a printed checklist: no OTP sharing, no remote-screen “help desk” installs, and no rush transfers while driving. Community centers in several provinces distributed Korean-language flyers coordinated with KISA’s holiday task force.
Institutional response
Major banks pushed in-app banners before outbound travel peaks, and mobile carriers blocked known phishing sender ranges in batches. KISA said takedown requests hit offshore hosts with mixed speed; the advisory focuses on consumer hygiene because technical blocks lag copycat campaigns.
Prosecutors may later name defendants if cases mature; until then, KISA’s public line is prevention, not pursuit narratives. For returning commuters reopening laptops Thursday, the operational lesson is unchanged: treat holiday generosity links like strangers at a rest-stop QR—pause, verify offline, then pay through signed apps.
Carrier and bank coordination
Mobile operators said they blocked 1,200 spoofed sender IDs in the 48 hours before the advisory, a batch figure KISA cited without linking to individual defendants. Banks rotated fraud-education splash screens in mobile apps to appear before login, when users are most likely to chase fake security alerts.
Consumer groups asked KISA to publish anonymized message templates after the holiday so antivirus vendors can tune filters; the agency said it would release redacted samples once campaigns cool, avoiding copycat phrasing in the interim.
After the advisory
KISA’s holiday task force remains staffed through Sunday night, when return traffic peaks again. Loss statistics will be aggregated nationally without naming victims, a practice victim advocates requested after prior advisories led to social-media pile-ons against people who clicked links in haste.
For enterprises, the reminder is to warn employees returning to inboxes Thursday that payroll and gift-reimbursement scams spike when finance teams are short-staffed. IT desks should keep 118 reporting bookmarks pinned—not because every text is criminal, but because early reports shorten takedown cycles for everyone else.
KISA’s English-language bulletin mirrored the Korean advisory for foreign residents receiving Korean-language smishing after local number porting, a growing niche where criminals assume expats will panic-click translation links.
Police cyber units asked messaging apps to flag forwarded smishing chains in family group chats, where relatives unknowingly amplify fake gift links alongside genuine holiday photos.
Banks reminded customers that legitimate Chuseok cash gifts never require installing unknown remote-access apps to “unlock” transfers.
