posts / Economics

Why "Please Pay by Card" Is More Frightening Than Voice Phishing

phoue

14 min read --

An elderly woman looking worried while holding a credit card while on the phone
An elderly woman looking worried while holding a credit card while on the phone

Earlier this year, Ms. A, a woman in her 70s, received a call from a man claiming to be a financial company employee.

“There is an illegal card transaction from a long time ago; if you don’t cancel it, you’ll face credit disadvantages and won’t be able to use your card,” he said, his voice calm. He explained convincingly that to cancel the transaction, she first had to make a re-payment to the guarantee insurance company, which would then be refunded. Ms. A did as she was told, giving him her card number, expiration date, and the first few digits of her PIN. In an instant, 3.23 million won was gone. Later, she discovered that the money hadn’t gone to an insurance company, but to an unfamiliar, illegal merchant.

There is something strange here. When we think of voice phishing, we usually think of instructions to “send money to a bank account.” However, recent cases show that scammers are insisting on having victims “pay by card.” While bank transfers are processed at once through a bank branch or app, card payments involve merchants and have more steps, from authorization to settlement. Why would they insist on such a cumbersome method?

  • If you look at the consumer alert issued by the Financial Supervisory Service (FSS) on September 16, 2026, it’s clear that this isn’t just a simple change in tactics, but a calculated choice.*

The Real Reason Scammers Demand Card Payments Over Wire Transfers

Fraud detection systems operated by credit card companies were originally designed to catch situations where a third party secretly attempts a payment, such as through hacking or identity theft.

  • If a payment comes through an unfamiliar device, in an unfamiliar region, or with an unusual pattern, the system immediately triggers a warning. *
    
  • However, in voice phishing card payment scams, the scenario is the exact opposite. *
    
  • The cardholder themselves makes the payment using their own phone or computer, following standard identity verification procedures. *
    

*** From the system’s perspective, it looks like a flawless, legitimate transaction.****

The Financial Supervisory Service announced that it would significantly strengthen the rules in the shared fraud detection standards used by card companies to catch cases where victims are tricked into making payments themselves.

This announcement itself proves that there has been a loophole until now.

It means that existing detection rules were unable to filter out this type of payment.

For scammers, wire transfers are much simpler, but they are also a channel where banks can easily detect suspicious transfers in real-time and place payment blocks.

On the other hand, card payments pass through merchants and payment gateways (PGs), which disperses the flow of funds, and a record remains that the payment was processed normally under the cardholder’s name. They have chosen card payments as a channel to avoid tracking, even at the cost of added inconvenience.

When wire-transfer-based voice phishing was at its peak, the banking sector implemented tight measures like delayed withdrawal systems and limits on withdrawals after deposits. As a result, fraudulent attempts caught at bank branches or ATMs increased, making it harder for scammers to extract money solely through wire transfers.

Inducing card payments is essentially a tactic that exploits that gap.

While payment authorization systems are sophisticated at preventing unauthorized use, ‘payments that the cardholder was tricked into authorizing themselves’ were originally outside the design scope.

Why Gift Cards Appear So Frequently

Looking at the cases, items like gift cards and prepaid cards appear quite often.

Ms. B, a woman in her 20s, started a “part-time job” she found on a recruitment site that involved ordering goods and paying for them, with the promise that she would be refunded the cost plus a profit. After receiving the initial refund as promised, she used her card to buy multiple items and even took out a loan. Then, the refunds suddenly stopped, and her losses climbed to 63 million won.

Mr. D, a man in his 30s, had a similar experience.

After building intimacy with someone he met on a random chat app, the person claimed they urgently needed money and asked him to buy gift cards with his card and send the PIN numbers to a specific company. Mr. D watched as those PIN numbers were sold, and the proceeds briefly appeared in his account before being moved to another one, ultimately losing 4.5 million won.

Even though the money only briefly passed through his account, there is a risk that Mr. D himself could be implicated in money laundering.

In both cases, the final destination was gift cards. The money that actually moved from start to finish went through legitimate card companies and merchants, but at the end of the flow, a merchant designated by the scammer was waiting.

The reason is simple. With gift cards, there is a time gap and anonymity between the moment the card payment is made and the moment it is converted into cash. Unlike wire transfers, it isn’t immediately obvious who sent how much to whom, and the ownership is effectively transferred simply by handing over a PIN number.

Of course, there are some restrictions.

Individual credit card holders can only purchase up to 1 million won worth of gift cards or prepaid electronic payment methods per month.

If someone asks you to buy gift cards in bulk using multiple cards, or sends you a payment link to pay more than 1 million won, that in itself is a red flag.

Legitimate registered gift card sellers have systems that automatically block individual purchases exceeding 1 million won per month. In other words, if they are mobilizing multiple cards to bypass that limit, the person on the other end is 9 out of 10 times not a legitimate registered merchant.

The “Card Cashing” Structure Hidden Behind Condo Membership Scams

One of the most notable cases involves Mr. E, a man in his 50s.

A scammer impersonating a condo company employee demanded payment, claiming “your membership purchase has been confirmed.” Mr. E gave his card number and expiration date over the phone, and 6 million won was charged. Later, he discovered that the transaction was actually made at a large restaurant, not a condo company.

The owner of this restaurant was also a victim.

Tricked by a scammer’s claim that they needed sales records to get a loan, the owner processed card numbers provided by the scammer through their own terminal. The settlement funds received from the card company then flowed directly into the scammer’s account.

In this structure, known as “card cashing,” two people are caught in a single transaction: the consumer who provided their card details and the small business owner who processed the payment, blinded by the promise of sales records.

FSS data points out that condo membership scams are not the first of their kind.

Similar cases involving resort memberships, funeral service products, and cruise tickets have already been identified.

It’s a method where a company’s customer list is leaked, and the scammer approaches the target with precise information about their actual contracts. When the other party already knows your membership sign-up date or the expected payment amount, trust is established before you even have a chance to be suspicious—that is the terrifying aspect of this tactic.

A small business restaurant owner looking troubled while holding a card payment receipt
A small business restaurant owner looking troubled while holding a card payment receipt

This flow is summarized in the image below.

Why Is It So Hard to Get Compensated for Legitimate Card Payments?

This is where the most cruel part of this fraud type is revealed.

Ms. A’s case was cancelled because the merchant’s fraudulent sales were confirmed, but this is an exception.

Ms. B, who was tricked into a part-time job, Mr. C, who paid for gift cards under the guise of low-interest loan fees, and Mr. D, who fell for a romance scam, all failed to receive compensation from their card companies.

The reason is simple: There is a record that the cardholder authorized the payment themselves, following standard identity verification procedures.

Security measures that usually protect us—namely, identity verification—become the scammer’s alibi in these cases.

The fact that it is a “transaction authorized by the cardholder” becomes a barrier to victim relief.

Mr. C filed a complaint with his card company after paying 800,000 won in gift cards for a low-interest loan fee, but he was denied compensation because he authorized the payment himself. Even though demanding loan brokerage fees is illegal under the Loan Business Act, that fact does not lead to compensation once the payment is finalized.

This is the critical point where this differs from wire-transfer-based fraud.

With wire-transfer fraud, there is room for banks to attempt some level of relief through payment holds or victim refund procedures. In fact, under the Telecommunications Fraud Damage Refund Act, systems for account freezes and refunds are in operation.

On the other hand, since card payments are processed as if the merchant has been settled and the goods or services have been provided (even if they don’t actually exist), cancellation is much more difficult. The act of payment itself functions as a legal basis that ‘a contract was entered into based on my own will.’

Summary of Five Types of Voice Phishing Card Payment Scams

The voice phishing card payment types identified so far, categorized by the “bait” used, are as follows:

Type Bait Actual Payment Method Scale of Damage
Illegal Card Sale Cancellation Warning of credit disadvantage Re-payment impersonating insurance 3.23M KRW
Part-time Payment Job High-profit side gig Proxy card payment for goods 63M KRW
Low-interest Loan Fee Loan brokerage Pre-payment for gift cards 0.8M KRW
Random Chat Romance Scam Building intimacy Buying gift cards, then cashing out 4.5M KRW
Membership Impersonation Condo/Resort membership Providing card info via phone 6M KRW

Even just looking at the numbers, the scale of damage varies.

However, if you lay the five types side-by-side, you can see a common framework. They start with a request that seems like a small amount or a normal procedure, and only after trust is built do they make the real demand.

This structure is particularly clear in the proxy payment part-time job case.

When the initial cost of goods and profits are refunded as promised, the victim feels relieved, thinking, “It was real after all.”

That relief makes them accept demands to increase payment amounts under pretexts like “large orders,” “team missions,” or “tier upgrades.”

There are even cases where victims are put into group chat rooms and pressured with claims that “the entire team must complete the mission to get settled.” This is designed to exploit group psychology rather than individual judgment.

Condo membership scams and low-interest loan scams share the same bones.

They lower the intensity of suspicion at the start by having the other party already know some of your information, or by using names that carry public trust, such as government agencies, financial companies, or membership-based businesses. With suspicion lowered, the act of payment itself takes only seconds.

What Changes With the FSS’s Enhanced Fraud Detection?

According to National Police Agency data, the number of voice phishing victims aged 70 and older increased from 777 in 2023 to 1,047 in 2024 and 1,493 in 2025. That is a 42.6% increase from the previous year.

The reason the elderly are particularly vulnerable is clear:

They tend to trust financial information delivered via phone or text, and because they are not familiar with the digital financial environment, it is difficult for them to navigate payment cancellation or verification procedures on their own.

In response, the FSS is pursuing three types of countermeasures.

First, they are revising the joint standards for fraud detection.

Until now, the focus was on preventing unauthorized payments by third parties, such as hacking. Now, they are supplementing the rules to catch cases where the victim was tricked into making the payment themselves.

Second, when a person aged 70 or older is flagged for suspicious transactions while paying for high-liquidity items like gift cards, the payment will not be approved immediately. Instead, a “cooling-off” period will be introduced, where a counselor will conduct an in-depth consultation to verify the person’s actual intent.

For example, the moment someone like Ms. A tries to pay for a 3-million-won gift card after receiving a sudden call, a card company counselor will call first to ask, “Are you sure this is a payment you truly intend to make?” That one question from a third party during those few minutes of clouded judgment provides a chance to reconsider the fraud. The financial authorities stated they plan to gradually expand the target age range and the scope of high-liquidity products after monitoring the effectiveness of this method.

Third, they are strengthening civil complaint investigations for cases suspected of involving illegal merchants, such as card cashing, by looking more closely at the payment process, including whether goods were actually delivered.

The damage experienced by the restaurant owner in Mr. E’s case is exactly what this third measure targets. The core is to induce card companies to more carefully examine potential illegal activities from the stage of registering new merchants or handling dispute complaints.

All three measures have one thing in common:

They aim to move the point of fraud prevention from ‘reporting after damage occurs’ to ‘just before the payment is authorized.’

Until now, the flow was to file a complaint with the card company only after the money was already gone, only to be rejected in most cases because it was a self-authorized payment. Once the refined fraud detection rules and in-depth counseling for the elderly are established, there will be at least a chance for a brake to be applied at the final gateway of payment authorization.

What to Check Immediately If You Suspect Card Payment Fraud

If you receive a request to provide card information over the phone, the first thing to do is hang up, no matter who the person claims to be.

Remembering that cancelling an online card transaction does not require re-payment, and that unauthorized transactions do not affect your credit status, will filter out most traps.

It is also good to remember that non-authenticated payment methods—where a payment is made just by providing the card number, expiration date, and CVC without a separate certificate, biometric info, or PIN—are inherently vulnerable to fraud and accidents.

The same applies to methods where you enter card information directly into a payment link. If you don’t know the merchant well, the safest path is to not engage at all.

If you have already provided your card information or made a suspicious payment, follow these steps:

  • Immediately contact your card company’s customer service to request a card suspension and re-issuance.
  • If the payment has already gone through, request an order cancellation from the merchant.
  • If you received a call about a loan, first check if it is a legitimate financial company or a registered lender on the Financial Consumer Information Portal FINE (fine.fss.or.kr). If it’s a loan recruiter, you can check them separately under ‘Search for Financial Product Sales Agents.’ Legitimate loans do not require fees from the consumer.
  • If you are curious about legitimate low-interest loan products, you can receive free consultation from the Korea Inclusive Finance Agency’s ‘Inclusive Finance Itda’ (call 1397).
  • If money has been withdrawn from your bank account, request a payment hold with the bank immediately.
  • Do not delete evidence such as job postings, conversation logs, or payment/refund history. Capture them as screenshots and submit them when reporting to the police. For safety, request a suspension of the card used for the proxy payment due to concerns about information leakage.

Ultimately, the most important thing is this:

If someone asks for an unusual payment method, especially for gift cards or prepaid cards, you must be suspicious from the start, no matter how much trust they have built.

If you have parents or grandparents, it would be a good idea to mention this to them.

No legitimate card company employee, condo employee, or loan counselor will ever ask for your card number, expiration date, or PIN over the phone. Remembering that one principle alone could stop most of the five types of fraud mentioned above during the very first call.

Keep the card company customer service numbers handy for when you need to hang up on a suspicious call:

KB Kookmin Card: 1588-1688,

Shinhan Card: 1544-7000,

Samsung Card: 1588-8700,

Hyundai Card: 1577-6000,

Lotte Card: 1588-8100,

Woori Card: 1588-9955,

Hana Card: 1800-1111,

BC Card: 1588-4000,

NH Nonghyup Card: 1644-4000 are the major ones.

Since these are numbers for moments when you might not have the time to search, sharing them in a family group chat is a good idea.

References
  1. Warning on 'Proxy Payment Part-time Jobs' and 'Condo Payment Requests'... FSS Strengthens Card Fraud Detection
  2. Preventing Voice Phishing That Induces 'Direct Payments'... Strengthening Card Fraud Detection
  3. Catching Voice Phishing Even When Victims Are Tricked into Making Direct Card Payments
  4. "Re-pay to Keep Using Your Card" Scam Steals 3.23 Million Won... New Voice Phishing Warning
  5. We Will Strengthen Prevention and Relief for Card Payment Damage Caused by Voice Phishing.
  6. [Press Release] "We Will Strengthen Prevention and Relief for Card Payment Damage Caused by Voice Phishing"
#voice-phishing-card-payment#card-cashing-fraud#fss-fraud-detection#gift-card-scam-korea#romance-scam-korea#senior-citizen-fraud#fraudulent-merchant#card-refund-dispute#financial-supervisory-service#non-face-to-face-payment

Recommended for You

Why Bonuses Vanish in an Instant: The Reality of Mental Accounting

Why Bonuses Vanish in an Instant: The Reality of Mental Accounting

7 min read --
Can the Yuan Surpass the Dollar with CIPS?

Can the Yuan Surpass the Dollar with CIPS?

13 min read --
China's Unhidden Dual Economy: The Hidden Side of 'New Quality Productive Forces'

China's Unhidden Dual Economy: The Hidden Side of 'New Quality Productive Forces'

13 min read --
The Shadows of the Chinese Economy Revealed by 35 Months of Negative PPI

The Shadows of the Chinese Economy Revealed by 35 Months of Negative PPI

14 min read --
Why China is Planting Quantum Tech in its Banking Networks

Why China is Planting Quantum Tech in its Banking Networks

7 min read --
Why China is Releasing Top-Tier AI Models as Open-Weights

Why China is Releasing Top-Tier AI Models as Open-Weights

12 min read --

Advertisement

Comments