Taiwan’s Criminal Investigation Bureau is warning shoppers to verify refund notices inside official Momo and Shopee apps rather than clicking links in text messages, after a wave of phishing cases in August that cost victims NT$54.51 million and used impersonation of the two e-commerce platforms. The advisory lands as Mid-Autumn Festival shopping, travel and barbecue spending peaks, giving fraud crews a familiar hook: an order problem that needs an urgent fix.

The confirmed numbers are stark. Taipei Times reported that August 2026 brought 505 phishing cases and NT$54.51 million in losses, with scammers impersonating Momo and Shopee. The CIB press conference on Sept. 15 focused on the same message: do not click unknown links. CIB’s English advisory also describes a LINE phishing campaign tied to a “Help Me Vote” lure, a reminder that account takeover remains a core objective even as police report progress against it.

What broke

The scam is not a sophisticated hack of Momo or Shopee. It is a social-engineering play that borrows their names. A shopper receives an SMS or messaging-app note saying a refund, delivery, or payment failed. The message asks the recipient to click a link and re-enter account details, bank information, or a one-time password. The page may look like a mobile login screen. Once credentials are captured, the attacker can drain a payment account, open a mule route, or pivot to LINE.

LINE takeover is the second stage. If the attacker obtains a verification code or tricks the user into approving a login, the stolen account becomes a trusted voice. Contacts then receive messages asking for a loan, a vote, or a small transfer. The CIB’s “Help Me Vote” advisory points to that pattern: a seemingly harmless request that gets the victim to click, authenticate, or share a code. The result is not just one lost account; it is a fraud network operating through the victim’s social graph.

Who has the file

The Criminal Investigation Bureau, under the National Police Agency, is the central agency handling the phishing pattern and public advisories. Local police stations take individual fraud reports, and cases can reach prosecutors if suspects are identified. The CIB’s public materials are the clearest official record of the August case count, the NT$54.51 million loss figure, and the Momo and Shopee impersonation warning.

That matters for liability. Under Taiwan’s Criminal Code, fraud and unauthorized access offenses carry criminal exposure for the people running the scam. Money laundering controls can also apply to accounts used to receive or move proceeds. But the CIB has not accused Momo or Shopee of wrongdoing. The platforms are being impersonated, not identified as the source of a breach. Any civil or regulatory question about platform liability would turn on facts not yet in the public record: whether there was a data leak, how quickly suspicious pages were reported, and what notices customers received. The same caution applies to banks and payment providers. A refund scam can involve their rails without proving they failed a legal duty.

What shoppers should do

CIB’s advice is direct: do not click links from unknown senders. For refunds, open the official Momo or Shopee app and check the order status there. Do not use a link in the message, even if it displays the platform’s name. Do not share SMS one-time passwords or LINE verification codes. If a caller claims to be customer service and asks for account details, hang up and call the number listed on the platform’s official site.

For LINE, enable two-step verification and review logged-in devices. If an account is taken over, tell contacts through another channel and report the account to LINE. For bank transfers, contact the bank immediately; Taiwan’s fraud-reporting process can flag accounts quickly if the victim has transaction details. The earlier the report, the better the chance of freezing funds before they move through multiple accounts.

What is still unknown

It is not yet clear whether the current Mid-Autumn period has produced a measurable spike, or whether the August wave was driven by one group or several. The CIB has published totals and tactics, not a platform-by-platform breakdown for September. Momo and Shopee have not been accused of a security failure. There is also no public confirmation of how many of the August cases involved LINE takeovers versus card theft or direct transfers.

Those gaps matter because the policy response depends on the answer. If the problem is mainly consumer behavior, public warnings and app-based verification are the first line. If the problem includes credential leaks or weak recovery flows, regulators may need to look at platform and telecom safeguards. For now, the confirmed fact is narrower but urgent: fraud crews are using refund anxiety during a holiday shopping season, and the CIB wants users to slow down before they click.