./Naver

Phishing emails impersonating government agencies such as Wetax, the Korean National Police Agency, the National Tax Service, and the Blue House have been found attempting to steal Naver user account information.

On the 24th, Naver said in a customer center notice that there have been cases recently where people are being lured to click L.I.N.C with attention-grabbing subjects like tax bills, police appearance requests, and guidance on livelihood recovery support funds. If you press buttons such as check the bill details for the day, view case materials in detail, or register a receiving account, you are consolidated to a fake Naver screen, which then prompts you to enter your password.

The phishing emails were elaborately crafted to look like real official documents, with logos, case numbers, legal provisions, and payment deadlines. Subjects and contents include phrases like "[Wetax] A tax bill has arrived in the local government tax e-document box," "[Final notice] Guidance on mandatory registration for the National Tax Service e-notification service," "Appearance request related to a case violating the Act on Promotion of Information and Communications Network Utilization and Information Protection," and "[Blue House] Guidance for recipients of livelihood recovery support funds."

Some emails also included main phone numbers of real government agencies or standard security guidance phrases. Even if information matches search results, that does not mean the email is safe. Attackers can make the on-screen logos and sender information look similar.

Naver explained that the phishing page may show the Naver logo and have the user's email address prefilled, but the address bar displays a domain other than the Naver login address "nid.naver.com." Even if a visited web page shows the Naver logo and your email address is prefilled, that does not mean it is a legitimate page. The attacker preinserted the email address into the L.I.N.C.

Naver advised that if account passwords are requested during tax, fine, or support fund verification, it is phishing. It added that you should not click the L.I.N.C in the email but instead access the agency's app or official site directly. In particular, even if the logo, legal provisions, and phone numbers are real, do not trust the email immediately; if you have already entered your password, change it right away and enable two-step verification.

Naver said, "There is no reason to reenter your Naver password to verify taxes or support funds," adding, "If you enter your password on this screen, account information could be sent to the attacker." It continued, "This case involves phishing emails made by an attacker who misused agency names and publicly available document formats," and said, "Even if the email looks urgent, do not press the L.I.N.C first; please check through the official app or site."

※ This article has been translated by AI. Share your feedback here.