{"id":142097,"date":"2026-09-03T18:38:30","date_gmt":"2026-09-03T18:38:30","guid":{"rendered":"https:\/\/www.europesays.com\/korea\/142097\/"},"modified":"2026-09-03T18:38:30","modified_gmt":"2026-09-03T18:38:30","slug":"phishing-emails-impersonating-south-korean-government-agencies-target-naver-accounts-do-not-click-links-biggo-finance","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/korea\/142097\/","title":{"rendered":"Phishing Emails Impersonating South Korean Government Agencies Target Naver Accounts \u2014 &#8216;Do Not Click Links&#8217; \u2014 BigGo Finance"},"content":{"rendered":"<p>Naver has issued a warning after discovering phishing emails impersonating South Korean government agencies \u2014 including the Blue House, the National Tax Service, the Korean National Police Agency, and WETAX \u2014 in an attempt to steal users&#8217; account credentials. Attackers are luring victims into clicking links using urgent-sounding subjects such as tax notices, police summons, and livelihood recovery subsidy announcements.<\/p>\n<p>According to a notice posted on Naver&#8217;s customer center on the 24th, emails impersonating the Blue House used the subject line &#8220;Notice for Livelihood Recovery Subsidy Recipients&#8221; to entice users into registering a bank account for receiving funds. Emails posing as the National Tax Service and WETAX were disguised as &#8220;Mandatory Registration Notice for Electronic Notification Service&#8221; and &#8220;A Tax Bill Has Arrived in Your Local Tax Electronic Mailbox,&#8221; respectively.<\/p>\n<p>Emails impersonating the Korean National Police Agency were also identified. Titled &#8220;Request to Appear Regarding a Case Involving Violation of the Information and Communications Network Act,&#8221; the messages claimed that a case had been filed for cyber defamation and insult, demanding the recipient appear before police. These emails included the police agency&#8217;s logo, a case number, legal provisions, and an appearance deadline, making them look like authentic documents from an investigative authority.<\/p>\n<p>When users click buttons such as &#8220;View Notice Details,&#8221; &#8220;View Case Materials,&#8221; or &#8220;Register Receiving Account,&#8221; they are redirected to fake websites designed to closely resemble Naver&#8217;s login page. These phishing pages not only display the Naver logo but also pre-fill the user&#8217;s email address, making it easy to mistake them for legitimate login pages.<\/p>\n<p>However, the address bar shows a domain other than &#8220;nid.naver.com,&#8221; Naver&#8217;s official login URL. If a user enters their password on this screen, their account credentials can be transmitted directly to the attackers.<\/p>\n<p>Some phishing emails include the actual main phone numbers of the impersonated government agencies or legitimate-looking security notices. Even if the phone numbers or agency information match what appears in internet searches, users should not assume an email is genuine \u2014 attackers may have simply copied publicly available information.<\/p>\n<p>WETAX and Hometax do, in fact, send notification emails. Therefore, receiving a tax- or subsidy-related email alone does not automatically mean it is a phishing attempt. The key distinguishing factor is that legitimate government business never requests a Naver password or verification code through links embedded in emails.<\/p>\n<p>Naver explained that government systems were not breached; rather, attackers misappropriated agency names and publicly available document formats to craft the phishing emails. &#8220;These cases involve phishing emails created by attackers who misappropriated agency names and publicly available document formats,&#8221; the company stated. &#8220;Even if the email content appears urgent, do not click links first \u2014 verify through official apps or websites.&#8221;<\/p>\n<p>Recommended actions for users are as follows: Instead of clicking links in emails, access the relevant agency&#8217;s official app or website directly to verify the information. When contacting an agency, use the main phone number listed on the official website rather than any contact information provided in the email.<\/p>\n<p>If a user has already entered their password on a fake site, they should change it immediately. Passwords for other services using the same credentials should also be changed, and two-factor authentication should be enabled on the Naver account. If phishing damage is suspected, users can report it to the Korea Internet &amp; Security Agency (KISA) by calling the 118 helpline.<\/p>\n<p>Naver stressed that any request to enter a password under the pretext of verifying taxes, fines, or subsidies should be treated as phishing. &#8220;There is no reason to re-enter your Naver password to check taxes or subsidy information,&#8221; the company explained.<\/p>\n","protected":false},"excerpt":{"rendered":"Naver has issued a warning after discovering phishing emails impersonating South Korean government agencies \u2014 including the Blue&hellip;\n","protected":false},"author":2,"featured_media":142098,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[623],"tags":[5594,72299,1416,12040,657,72300,72297,72298],"class_list":["post-142097","post","type-post","status-publish","format-standard","has-post-thumbnail","category-naver","tag-blue-house","tag-korea-internet-u0026amp-security-agency","tag-korean-national-police-agency","tag-national-tax-service","tag-naver","tag-nid-naver-com","tag-phishing-email","tag-wetax"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/korea\/wp-json\/wp\/v2\/posts\/142097","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/korea\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/korea\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/korea\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/korea\/wp-json\/wp\/v2\/comments?post=142097"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/korea\/wp-json\/wp\/v2\/posts\/142097\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/korea\/wp-json\/wp\/v2\/media\/142098"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/korea\/wp-json\/wp\/v2\/media?parent=142097"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/korea\/wp-json\/wp\/v2\/categories?post=142097"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/korea\/wp-json\/wp\/v2\/tags?post=142097"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}