Fake Security Viewer App Installation Scam

Do Not Click on URLs in Messages; Delete Them Immediately

Official Notifications Are Sent as "National Health Insurance Service Notice"

Phishing messages impersonating the National Health Insurance Service (NHIS) are being circulated, luring users to access fake websites and install malicious apps. Users are urged to exercise particular caution.

Image generated by artificial intelligence (AI) to aid in understanding the article. ChatGPT

Image generated by artificial intelligence (AI) to aid in understanding the article. ChatGPT

View original image

According to the NHIS on the 25th, there has been a continuous flow of scam messages titled “Check the notice sent by the National Health Insurance Service,” which include an internet address (URL) of a website pretending to be the NHIS.


In particular, the scam induces users to install malicious apps by making the message appear as if it is an official NHIS notification, even including the NHIS’s corporate identity (CI). It deceives users into believing they must install a separate ‘secure document viewer’ to open the document.


There will never be any URL included in electronic notifications or messages regarding the four major social insurances actually sent by the NHIS via SMS, KakaoTalk notification, or similar services.


Kakao notification messages sent by the NHIS are clearly labeled as “National Health Insurance Service Notice.” Even if the sender name appears authentic, users should not open unfamiliar links or install files, as this can compromise security.


The NHIS has posted precautionary notices on its official website and mobile app, stating, “If you receive such messages, delete them immediately or verify with your local NHIS branch or customer center (1577-1000).”


Meanwhile, there have been repeated cases of forged documents impersonating public institutions being circulated with the intent to commit financial fraud. Each institution continues to request vigilance to prevent such damages.

Phishing email released by the National Health Insurance Service last March. Photo by National Health Insurance Service

Phishing email released by the National Health Insurance Service last March. Photo by National Health Insurance Service

View original image

Last March, a phishing email impersonating the NHIS was sent out under the subject “Notice on Insurance Premium Exemption and Suspension of Benefits.” The fraudulent email was sent from a fake address (mailer@nhishost.club) rather than the NHIS’s official domain (nhis.or.kr).


In response, the NHIS emphasized, “We do not provide individual guidance on premium exemptions or suspension of benefits via email.” The agency clarified that when such notifications are necessary, the initial notice is sent through mobile channels (Naver Electronic Document, KT PASS, KakaoTalk). If these are not received, a paper mail notice is subsequently provided.



If you suffer damages such as infection from malicious code after accessing a fake URL, or if you suspect a scam, you may report it to the Korea Internet & Security Agency (KISA) Cyber Incident Response Center (dial 118 without an area code) for assistance.


This content was produced with the assistance of AI translation services.

© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.

Today’s Briefing