Voice Phishing
Overview
Voice phishing is a neologism combining "voice" with "phishing," which means to fish for personal information. It refers to a telecommunications financial fraud crime in which perpetrators use phone calls, text messages, messengers, and similar channels to impersonate financial institutions, investigative agencies, family members, or acquaintances in order to extract personal information or fraudulently obtain money. In Korea it became a serious problem in earnest from the mid-2000s, and as communication technology and financial transaction methods have advanced, the techniques have grown increasingly sophisticated and organized. It has evolved beyond a simple individual fraud crime into an organized and international crime, establishing itself as a representative social problem that causes hundreds of billions of won in damage each year.
Key Details
Concept and Terminology
Voice phishing is classified academically as a type of "telecommunications financial fraud." The Act on Special Cases Concerning the Prevention of Damage from Telecommunications Financial Fraud and the Refund of Damages (abbreviated as the Telecommunications Fraud Damage Refund Act) regulates acts of using telecommunications to impersonate financial companies or provide false information in order to obtain pecuniary benefits from users. Cases using text messages are categorized as "smishing," cases that lure users to fake sites through malicious code as "pharming," cases conducted via messengers as "messenger phishing," and cases using artificial intelligence voice synthesis as "deep voice phishing."
Main Types
1. Impersonating institutions — Impersonating the prosecution, police, the Financial Supervisory Service, the National Tax Service, and others, demanding fund transfers by claiming that the victim is "involved in a crime" or that their "account was used for a crime."
2. Loan fraud — Luring victims into sending money under the pretext of fees or deposits, using low-interest loan conversions or repayment of existing loans as bait.
3. Impersonating family members or acquaintances (messenger phishing) — Stealing messenger accounts such as KakaoTalk and pretending to be an acquaintance in order to demand emergency money.
4. Smishing and pharming — Inducing installation of malicious apps through links disguised as delivery tracking, wedding invitations, obituary notices, and the like.
5. Remote-control apps and memory hacking — Inducing installation of remote-control apps under the guise of a consultation, then directly manipulating accounts.
6. Romance scams and investment-leading-room fraud — Impersonating a romantic partner or investment expert to build trust over a long period, then recommending virtual asset or overseas futures investments.
7. Mollcam phishing (sextortion) — Recording private footage during a video call and then blackmailing the victim to extort money.
Criminal Structure and Stages
Voice phishing organizations generally divide roles among a call center (consultation and luring), suppliers of borrowed-name bank accounts and burner phones, couriers (cash collectors), and money launderers. The crime proceeds through: ① purchasing leaked personal information on the dark web or obtaining it through hacking; ② disguising the caller ID as a genuine institution's number using number-spoofing technology; ③ creating a sense of crisis in the victim to cloud their judgment; ④ inducing transfers or cash withdrawals; and ⑤ laundering the funds through virtual assets, currency exchange, and similar means. Recently, the share of "face-to-face fraud," in which the victim withdraws cash themselves and delivers it to a collector, has increased greatly.
Scale and Characteristics of the Damage
According to data from the National Police Agency and the Financial Supervisory Service, voice phishing damage in Korea is estimated at anywhere from hundreds of billions of won to as much as 1 trillion won annually, with reported cases numbering in the tens of thousands. Victims range from those in their 20s to their 60s, but recently a dual strategy targeting both those new to the workforce and the elderly has emerged. Because the organization swiftly disperses and withdraws the funds, the refund rate tends to be low, and funds that are not recovered are often taken overseas.
Response and Prevention
- Investigative agencies and financial institutions will never demand a "safe account" or instruct you to withdraw or hand over cash.
- Hang up the phone and call the institution's official representative number directly to verify whether the claim is true.
- Do not click links in text messages of unknown origin, and immediately refuse any request to install a remote-control app.
- If damage occurs, report it promptly to 112 (police), 1332 (Financial Supervisory Service), 1394 (cybercrime report), and others, and apply to the transaction bank for a payment suspension.
- After a payment suspension, applying for the bond extinction procedure by attaching a police confirmation certificate can increase the likelihood of a refund of the damaged funds.
Legal Punishment
Voice phishing acts are punishable under the Criminal Act as fraud (Article 347), extortion, and violations of the Telecommunications Financial Fraud Act. In the case of organized crimes, aggravated punishment for criminal organizations and groups under the Act on Punishment of Violent Acts, etc. may apply, and criminal proceeds are confiscated and collected. Cash couriers and holders of borrowed-name bank accounts are also punished as accomplices, and a claim of merely having been deceived while doing part-time work is difficult to accept as grounds for exemption. Recently, through amendments to the Telecommunications Fraud Damage Refund Act, the system is being reorganized in the direction of strengthening financial companies' refund liability and their obligation to detect abnormal transactions.
Latest Trends
The biggest change in voice phishing in 2024–2025 is the exploitation of artificial intelligence. "Deep voice phishing," in which a family member's or acquaintance's voice is cloned from as little as 3–5 seconds of audio using generative AI to place a call, has emerged, and cases of even synthesizing faces during video calls have been reported. In response, the Financial Services Commission and the Financial Security Institute are pursuing the advancement of AI-based abnormal transaction detection systems (FDS) and the introduction of voice forgery detection technology. In addition, as money laundering routes diversify from borrowed-name bank accounts to virtual asset wallets, prepaid cards, and overseas currency exchange, tracking is becoming more difficult. As face-to-face fraud has come to account for a substantial portion of all cases, the police are concentrating investigative resources on arresting cash collectors and tracking down the masterminds of the organizations. In 2024, a public-private consultative body in which financial companies, telecommunications carriers, and platforms respond jointly was operated, and procedures for prompt payment suspension of suspicious transaction accounts were expanded. Alongside this, amendments to the Telecommunications Fraud Damage Refund Act, discussions on strengthening financial companies' compensation liability, and measures to strengthen the recovery of criminal proceeds are being continuously discussed in the National Assembly in order to support victims. On the prevention side, technological responses such as telecommunications carriers' blocking of caller ID spoofing, delays on large transfers in bank apps (24-hour delayed withdrawal), and blocking of overseas IPs are on an expanding trend.
Related Topics
- [[Telecommunications Financial Fraud]]
- [[Smishing]]
- [[Phishing]]
- [[Deepfake]]
- [[Borrowed-Name Bank Account]]
- [[Financial Fraud]]