"Your Chuseok support payment has arrived"—AI makes 'holiday phishing' more sophisticated
- Input
- 2026-09-22 13:58:32
- Updated
- 2026-09-22 13:58:32

[Financial News] Ahead of Chuseok, phishing text messages offering "holiday funds" and "Chuseok support payments" are proliferating. As attacks exploit holiday-related demand for everything from package deliveries, gift certificates and loans to airline tickets and accommodation bookings, concerns are growing that scammers could make their tactics even more sophisticated by using artificial intelligence (AI) to imitate the writing styles of real institutions or create personalized messages. Experts urged people to be wary not only of internet addresses (URLs) and QR codes in text messages, but also of requests to switch to messenger consultations or provide personal information. They also advised strengthening security measures, including two-factor authentication (2FA) for key accounts.
On the 22nd, Financial News asked AhnLab's AI Development Lab to analyze various text messages over one month, from August 15 to September 15, using the agentic AI security platform AhnLab AI PLUS. The analysis confirmed numerous phishing cases exploiting demand for holiday funds, support payments and prize events.
Typical scams promote low-interest, high-value loans under the pretext of Chuseok holiday funds or urge recipients to visit a URL by claiming that a "Chuseok support payment has arrived." Loan scam messages may tout high approval rates and non-face-to-face consultations before directing victims to one-on-one conversations on a messenger app, where they may be asked for personal or financial information, advance payments or fees.
Cases involving expensive prizes were also detected. Scammers impersonated a "special Chuseok social contribution event," claiming that participants were "100% guaranteed to win just by taking part" and offering stocks, the latest smartphones and discount coupons while repeatedly directing recipients to a URL.

The subjects used in attacks are expected to diversify as the Chuseok holiday approaches. In addition to package delivery tracking, holiday gifts and gift certificates, government support payments and low-interest loans, scammers may also send fake payment or reservation confirmation messages exploiting airline tickets, accommodation bookings and online shopping.
Concerns have also been raised that generative AI could be abused to make phishing attacks more sophisticated. It can naturally imitate the communication styles of financial institutions and public agencies, while combining publicly available or leaked personal information makes it possible to create personalized messages incorporating a recipient's name, occupation and interests.
An official from AhnLab's AI Development Lab explained, "By combining publicly available or leaked personal information, attackers can create personalized messages that reflect the recipient's name, occupation and interests. There is also likely to be an increase in attacks that create phishing pages closely imitating the websites of real companies and institutions, or generate various forms of text messages and webpages to evade detection."
AhnLab urged people not to immediately trust links or instructions contained in text messages. Even if a delivery company, financial institution or public agency is displayed as the sender, recipients should verify the information through the organization's official website or main telephone number instead of using the URL or QR code in the message. Requests for personal or financial information, authentication codes, advance payments or fees during a messenger consultation were also identified as signs of possible phishing. AhnLab recommended installing apps only through official app markets.
The appropriate response differs depending on whether personal information was entered or an app was installed after accessing a suspicious link. If neither occurred, users should close the page and conduct a security scan. If they entered financial information or transferred money, they should report the incident to their financial institution and investigative authorities and request follow-up measures, such as suspending payments from the account.
An official from AhnLab's AI Development Lab emphasized, "It is also important to keep the operating systems and programs on smartphones and PCs, as well as mobile antivirus software, up to date, and to set up device locks and two-factor authentication (2FA) for key accounts. Avoid conducting financial transactions or entering personal information when using free Wi-Fi whose provider is unclear."
[email protected] Choi Hye-rim Reporter