Security

Coupon Scams and Travel Booking Impersonation Surge During Chuseok Holiday Period... Beware of Texts From Unclear Sources

IT DAILY ·

AI-generated image

✦ AI Summary

Smishing and phishing impersonating parcel delivery and travel reservations are spreading ahead of the Chuseok holiday.

KISA advised caution about texts using bait such as "Chuseok special giveaway," "delivery tracking," and "traffic law violation," and urged people not to click links from unclear sources and to delete them immediately.

ESTsecurity and Kaspersky warned about scams using AI voice and video synthesis, impersonation of travel brands, inducement to install malicious apps, and theft of account and financial information.

The industry said on the 24th that cyber fraud is spreading by exploiting the increase in parcel delivery and travel booking-related contact during the Chuseok holiday period. Criminals are using text messages and messengers to lure users to fake sites.

The resulting damage from these tactics includes theft of personal information and inducement to install malicious apps. Phishing takes the form of a social engineering attack that exploits user psychology, and it targets periods when vigilance tends to ease.

Cases using AI-generated voices have also recently emerged. Authorities also warned that people should not send money based only on a familiar-sounding voice when contacted by someone impersonating a family member.

Against this backdrop, the Korea Internet & Security Agency (KISA) recently issued guidance on Smishing and Phishing during the Chuseok holiday period. KISA also provided examples of Smishing phrases distributed around the holiday. The article image was generated with AI, and the photo credit is the Korea Internet & Security Agency.

Smishing impersonating parcel delivery has been on the rise before and after the Chuseok holiday. KISA warned that bait keywords such as "Chuseok special giveaway," "delivery tracking," and "traffic law violation" are being used. KISA also said that when Smishing texts spread, there are concerns over personal information leaks and money-transfer losses. In fact, there have been cases of luring users to event pages for giveaway campaigns impersonating large corporations or approaching them for the purpose of stealing personal information, and there have also been confirmed cases of non-face-to-face direct transaction scams and fake shopping-mall redirection under the pretext of delivery delays and inventory shortages.

During the Lunar New Year holiday, cases also appeared that exploited increased vehicle movement between regions. Texts impersonating the government and public institutions were sent, and impersonation messages citing traffic law violations or fines for improper trash separation were used. Links in these texts served as entry points for additional attacks.

When users respond to a text link, they may be connected to a phishing site that mimics a legitimate site or redirected to a fake shopping mall. If a malicious app is then installed, there are also cases in which the smartphone is taken over. During this process, personal information can be stolen, and as KISA warned, it can lead to personal information leaks and money-transfer losses.

In recent years, malicious app attacks have stood out. This trend has emerged in line with the fact that there are many smartphone users. If users install an app and grant permissions, text-message leaks and contact list leaks can occur. In addition, it becomes possible to spoof the other party in outgoing calls.

Eberspin analyzed 1,381 pieces of detection data at risk levels from the 1st to the 21st, and found that cases involving impersonation of public institutions and financial institutions, along with inducement to install additional malicious apps, accounted for 903 cases, or 65.4%, the largest share. Personal information theft accounted for 428 cases, or 31.0%, and call hijacking accounted for 50 cases, or 3.6%. The largest category was malicious apps based on impersonation of institutions and inducement of follow-up damage through additional app installation.

This type of attack involves impersonating public institutions or financial institutions to induce users to enter personal information or make transfers, while continuing the attack by encouraging the installation of other malicious apps.

Accordingly, KISA urged people not to click site addresses from unclear sources when receiving texts and to delete them immediately. KISA also advised verifying whether suspicious addresses match legitimate sites, entering personal information only on trusted sites, and never sharing identity verification codes with others. It also emphasized that government agencies and financial companies never ask users to install remote-control apps over the phone or by text.

ESTsecurity said it analyzed four major types of AI-driven scams for the 2026 Chuseok holiday period and highlighted the risk of AI-based fraud targeting increased contact among family members during the holiday. It explained that greetings between family and relatives increase during the holiday season, and that criminals exploit this characteristic of holiday communication.

ESTsecurity said that with advances in AI technology, real-time synthesis of voices and faces is now possible with only a few seconds of voice samples, and that this synthesis technology is being abused for crime. It also stressed caution regarding phishing messages that AI creates in a natural manner.

ESTsecurity also emphasized caution against impersonation attempts that exploit voice and video synthesis. It said there have been cases of requests for urgent money through calls impersonating a family member's voice, and that as AI technology becomes more advanced, it has become difficult in some cases to identify the other party by voice alone, raising the difficulty of responding to such attacks.

ESTsecurity said that calls impersonating acquaintances can be linked to Smishing and can also be linked to malicious app installation. It added that calls impersonating acquaintances, when combined with Smishing and malicious app installation, increase the severity of the damage.

Accordingly, ESTsecurity suggested setting up a prearranged verification method known only to family members. It also recommended calling back using a number already known when receiving a request for urgent money to confirm it again.

ESTsecurity warned that AI is undermining the way people intuitively distinguish scams. A company official said that even natural-sounding sentences and familiar voices, which are key elements in existing scam-detection methods, are now being targeted by AI. The official urged a complete overhaul of verification procedures ahead of this year's Chuseok.

ESTsecurity recommended taking preventive steps before the holiday, such as checking whether one's personal information has been leaked and updating passwords. It also said scam texts are spreading in forms tailored with recipients' names and affiliations based on leaked personal information.

It explained that with the influence of generative AI, even the grammar errors that used to characterize phishing texts have disappeared, making phishing texts harder to identify. Accordingly, if a suspicious text is received, users can check it through the Smishing and Phishing verification service on the BohoNara KakaoTalk channel, and KISA counseling is also available for suspicious texts.

It also recommended reporting immediately to the National Police Agency's 112 or the Financial Supervisory Service's 1332 if suspicious signs are detected, in order to prevent further damage. If an app has already been installed or financial damage is suspected, users should report through another phone to 112 and others, and they should also check their financial and mobile payment records.

With a phishing page impersonating the Irish airline Ryanair confirmed, phishing attacks impersonating travel transportation and lodging reservations are also on the rise as use of overseas flights increases during the Chuseok holiday. There have been cases impersonating airline compensation payments and cases impersonating lodging reservations, and caution was urged before making payments.

As dependence on digital platforms has risen across every stage of travel preparation, booking, and local activities, cyberattacks targeting travel users are also expanding. As the entire travel process has become more dependent on digital platforms, the attack surface has expanded.

Kaspersky said it detected about 270,000 attack attempts over the past year using its solutions, all impersonating popular travel brands. Among them, attacks impersonating Emirates accounted for 61% of detections related to transportation brands, while attacks impersonating Uber accounted for 37%.

Most of the observed attack activity used the images of the two brands, Emirates and Uber. The photo shows a phishing page impersonating the Irish airline Ryanair, and the source is Kaspersky.

Kaspersky said it discovered a case impersonating the Irish airline Ryanair. In this case, the criminal lured victims with a message saying they could receive compensation, then induced them to enter account information and demanded a small payment under the pretext of a fee to receive the compensation. It also confirmed a tactic that pressured victims to make quick decisions by saying the offer would expire within seconds.

Kaspersky's comparison of detected threats involving transportation brand-related files showed that Trojan accounted for 30.5% and Trojan-Banker for 22.5%. Trojan-Banker is malware designed to steal bank account information and payment information. Kaspersky explained that cybercriminals are targeting not only travelers' reservation information but also bank accounts and financial information.

Kaspersky said that when it investigated cyber threats disguised as travel and lodging services, the number of attack attempts detected by Kaspersky solutions from the second quarter of 2025 through the first quarter of 2026 totaled 5,414. Of these, Trojan accounted for the largest share at 54.6%. Travel service accounts can include payment information, personal information, booking history, and conversations with lodging providers, making them attractive targets for cybercriminals.

Lee Hyo-eun, head of Kaspersky Korea, explained that digital security risks exist throughout both travel preparation and the stay at the destination. Lee said cybercriminals exploit users' hasty decisions during travel planning and booking, and that they mimic well-known travel brands to induce users to enter payment information. She added that there can be risks when connecting to public Wi-Fi locally, and there can also be risks when accessing unverified QR codes.

Lee said many travelers overlook digital threats compared with physical safety. She stressed the need to pay attention to security throughout the entire travel process and recommended not accessing links or sites from unclear sources. She also urged travelers to use digital protection applications to protect their personal information while traveling.

Source: IT DAILY · Kim Ho-jun
Original: https://www.itdaily.kr/news/articleView.html?idxno=241812

References

This article was produced with the help of an automated content generation algorithm.


Source: IT DAILY

View original

This article was summarized and organized by BizCrush based on the original article from IT DAILY. For exact quotations and full details, please refer to the original article.