Digital fraud is eroding the trust that made Korea an online-first society

Voice phishing, smishing and messenger impersonation cost South Koreans hundreds of billions of won a year, and the country's response — from liability-sharing rules for banks to delayed-transfer safeguards — has become a case study in defending a hyperconnected society.

South Korea digitised daily life earlier and more completely than almost anywhere else, and its criminals followed the same curve. Voice phishing — telephone fraud in which callers impersonate prosecutors, bank staff or family members — has been a fixture for nearly two decades, evolving from crude scripts into organised cross-border operations with call centres abroad, in-country cash runners, and malware that redirects a victim’s outgoing calls to the fraudsters themselves. Alongside it grew smishing, the delivery-notice text with a poisoned link, and messenger fraud that hijacks a familiar chat profile to ask a parent for an urgent transfer.

The sums involved run to hundreds of billions of won in reported losses in a typical year, by police and financial-regulator tallies — with the true figure higher, since shame suppresses reporting. The demographic pattern is consistent: schemes that impersonate authority land hardest on older victims, while job-seeking and investment lures catch the young. The common thread is that the attack targets trust rather than technology; the systems work exactly as designed, transferring money at the speed Korean banking is proud of.

That speed defined the first generation of countermeasures. Rules introduced over the past decade delay large first-time transfers to new accounts and hold ATM withdrawals of freshly deposited funds, buying hours in which a scam can unravel. A refund statute lets victims freeze and reclaim funds still sitting in a mule account. Telecom-side controls — sender-ID verification, mass blocking of spoofed numbers, warnings printed on international calls — pruned entire categories of attack.

The second generation shifted incentives inside the banks. Beginning in 2024, Korean banks adopted a liability-sharing framework under which a customer defrauded despite reasonable care can recover part of the loss from the bank, the share depending on both sides’ negligence. The logic is one regulators elsewhere have reached too: the institution that designs the channel is better placed than any individual to detect anomalous transfers, and money moves only when the institution’s systems move it. Banks responded with AI-based transaction monitoring that now interrupts a meaningful share of attempted transfers before they complete.

The contest is not being won so much as continuously refought. Each safeguard redirects the fraud toward the unprotected seam — from calls to messengers, from bank transfers to gift-card codes and coin exchanges — and generative tools that clone a child’s voice from seconds of audio are already part of the police warnings issued to households.

The stakes are larger than the losses. An online-first society runs on default trust — in the caller, the link, the payment screen — and every successful scam taxes that default for everyone. Korea’s experiment in engineering trust back into its channels, safeguard by safeguard, is one the rest of the connected world has reason to study.