NewsMacroSmishing Scammers Exploit Leaked Data to Target Older Koreans with Real Family Names, Report Finds

Smishing Scammers Exploit Leaked Data to Target Older Koreans with Real Family Names, Report Finds

Author: The Korea Times Business·

Key Takeaways

  • Infinigru's seven-month investigation identified 1,856 smishing victims who collectively received 40,876 messages, with approximately 94% of victims aged 50 or older.
  • Scammers achieved a 95.3% accuracy rate in correctly addressing older victims as "Mom" or "Dad," using personal data obtained from major data breaches.
  • When scammers used the actual names of victims' children, engagement increased dramatically, with 29 of 30 victims exchanging multiple messages and 11 ultimately installing malicious apps.
  • The median time from the first text to a demand for money or personal information was only 26 minutes, and over 70% of reviewed exchanges lasted more than an hour.
  • Of the 1,160 phone numbers used by scammers, 818 were active for only a single day before being discarded, significantly complicating law enforcement efforts.
Smishing Scammers Exploit Leaked Data to Target Older Koreans with Real Family Names, Report Finds

Text message phishing scams, widely known as smishing, are evolving into highly personalized attacks that leverage stolen personal data to deceive older victims in South Korea, according to a new report by fraud-prevention technology firm Infinigru Corp.

Scammers are now addressing older victims as "Mom" or "Dad" with near-perfect accuracy and, in some cases, using the actual names of victims' children. The schemes typically involve claims of a broken phone screen or a changed contact number, ultimately aiming to steal banking credentials or trick victims into installing malicious applications that grant remote access to their devices.

Authorities suspect the fraud relies on personal information exposed during recent large-scale data breaches. South Korea has experienced multiple major data leak incidents in recent years — including breaches at telecom operators, e-commerce platforms, and financial institutions — that have collectively exposed the personal details of tens of millions of residents, providing fraudsters with rich datasets of names, phone numbers, ages, and family relationships.

Scope of the Problem

Infinigru's report, covering the seven-month period from Dec. 8, 2025, to July 14, 2026, identified 1,856 victims who received demands for money or personal information, or whose phones were remotely accessed after installing a malicious app. These victims collectively received 40,876 messages.

The victims were overwhelmingly older individuals. Those aged 50 and above accounted for approximately 94 percent of the total, or 1,743 people. This concentration aligns with South Korea's demographic trajectory: the country has one of the world's fastest-aging populations, and older adults have rapidly adopted smartphones, making them reachable targets while often having less familiarity with evolving phishing tactics.

Title Accuracy and Age Correlation

Among 1,801 victims aged 40 and older, scammers correctly addressed 1,718 as "Mom" or "Dad," achieving a 95.3 percent accuracy rate. Title accuracy rose steadily with age: 79.2 percent for victims in their 40s, 93.2 percent for those in their 50s, 96 percent for those in their 60s, 97 percent for those in their 70s, and 96.2 percent for those aged 80 and older.

"Messages from a single scamming number was heavily concentrated on recipients in their 50s and older, and the title accuracy such as 'Mom' and 'Dad' approaches 100 percent," Infinigru said in its report. "Rather than sending messages randomly, this is suspected to be targeted smishing using age and gender information secured through recent personal data leaks."

Use of Children's Real Names

In 30 cases, scammers sent messages incorporating the actual names of victims' children, which proved highly effective at lowering victims' defenses. Of those 30 victims, 29 exchanged two or more messages with the scammers, and the median number of messages exchanged was 34 — more than three times the overall sample median of 10. Eleven of those 30 victims ultimately installed a malicious app via a link, giving scammers remote access to their phones.

"When the real names of children were mentioned, it was not a case of scammers stealing personal information in real-time, but rather scammers repeatedly exploiting contact lists already leaked through past malicious app infections," Infinigru said.

Senders also used self-identifying labels such as "I'm your firstborn" or "I'm your eldest son" — terms commonly used by Korean parents — which were presumably copied directly from contact names stored on victims' phones.

Timing and Volume Trends

Smishing messages surged beginning in March 2026. Monthly text volume climbed from 1,291 in December, 2,410 in January, and 2,137 in February to 10,162 in March and 10,791 in April, before dipping to 6,300 in May and 7,566 in June.

Scammers concentrated their initial outreach between 10 a.m. and 2 p.m. "Scammers appear to target times when children are at work or school to make the situation of a broken phone sound plausible," the report noted.

Speed and Duration of Attacks

Victims often suffered losses before recognizing the scam. The median time from the first text message to a request for money or personal information was just 26 minutes. Scammers built trust through extended conversations, with 1,994 of 2,525 reviewed exchanges lasting more than an hour.

Evasion Through Disposable Numbers

Apprehending the perpetrators remains a significant challenge. Of the 1,160 phone numbers used to send messages, 818 were active for only a single day before being discarded. Scammers operated a rotating pool of phone numbers registered under stolen identities. South Korean authorities have required实名 (real-name) verification for mobile number registration, but fraudsters have circumvented these rules by obtaining SIM cards through identity theft or illicit channels, a persistent issue the country's telecom regulator has sought to address through tighter activation controls.

Expert Commentary

Lee Woong-hyuk, a professor of police science at Konkuk University, said a series of massive data breaches has increased the likelihood that scammers will exploit detailed personal information.

"People must not immediately trust texts or phone calls that mention personal details, and the government and corporations must strengthen security measures to solve the underlying problem," Lee said.

The findings underscore the compounding risk created when breached personal data flows into organized fraud operations — a challenge that South Korea's police cybercrime units, the Korea Communications Commission, and financial regulators have flagged as a growing priority, particularly as the pool of older, digitally active residents continues to expand.

This article from the Hankook Ilbo, the sister publication of The Korea Times, is translated by a generative AI system and edited by The Korea Times.