Loan Phishing Scams Surge 162% in Second Quarter - 조선일보
조선일보Archived Jul 15, 2026✓ Full text saved
Loan Phishing Scams Surge 162% in Second Quarter 조선일보
Full text archived locally
✦ AI Summary· Claude Sonnet
Phishing texts for "loan scams" that lure users into messenger chat rooms using low-interest, high-limit loans as bait surged by 162% compared to the previous quarter, and fraudulent messages impersonating airline ticket and accommodation bookings targeting the summer vacation season are also expected to rise, requiring heightened caution from users.
AhnLab announced on the 15th that it had published the "2026 Second Quarter Phishing Text Message Trend Report," which analyzed phishing texts detected through "AhnLab AI Plus" from April to June 2026.
According to the report, the most common type of phishing text in the second quarter was "loan scams," accounting for 62.68% of all cases. This was followed by Telegram impersonation (17.38%), financial institution impersonation (8.97%), and government/public institution impersonation (6.60%). Job recruitment scams, parcel service impersonation, family impersonation, and disguised public offering subscription schemes followed.
Loan scams and Telegram impersonation phishing increased by 162% and 71%, respectively, compared to the previous quarter. Conversely, family impersonation and wedding invitation disguise phishing decreased by 31% and 96%, respectively. Analysis suggests attackers are increasingly favoring tactics that use financial gains or messenger account verification as bait to elicit immediate responses from users, rather than impersonating family or acquaintances, which requires prior research and trust-building.
Loan scam texts typically attract attention with phrases like "emergency support fund approval," "low interest," "high limit," and "available for delinquents," then direct users to one-on-one chat rooms via messenger IDs such as Telegram. During subsequent consultations, they demand personal information or payments under the guise of loan processing fees or deposits.
The most frequently impersonated industry in phishing texts was financial institutions, accounting for 52.92% of cases. Government/public institutions followed at 38.96%, and logistics companies at 8.12%. Many schemes involved impersonating banks, credit card companies, or securities firms to falsely claim issues like loans, withdrawals, card usage, or suspicious transactions, pressuring users to act urgently.
Phishing methods are also diversifying. In the second quarter, mobile messenger lures were the most common at 43.89%, followed by URL insertion (40.33%), phone call inducement (14.86%), and text message lures (0.92%). While URL insertion dominated at 98.99% and 81.36% in the fourth quarter of 2025 and the first quarter of 2026, respectively, recent trends show a shift toward combining multiple channels like messengers, URLs, and phone calls.
To prevent damage, AhnLab advised users not to click on URLs from unknown senders, verify the reputation of suspicious phone numbers, block international text messages if unnecessary, and install smartphone security software.
AhnLab stated, "The loan scams and Telegram impersonation phishing identified as major threats in the second quarter are not entirely new attack types but have resurged as existing methods became more sophisticated." It added, "As phishing disguised as airline tickets, accommodation bookings, and vacation events typically increases every summer, users must verify the authenticity of any unverified messages."
원문보기 (View Original Korean Article)
AhnLab
smishing
phishing text messages