Back Finance.Biggo "I Paid for It Myself, So It's a Legitimate Transaction"
Voice phishing in South Korea is expanding beyond bank account transfers into credit card payments. Instead of demanding that victims transfer money, scammers now make them directly pay by card for items that are easy to convert into cash, such as gift certificates or membership rights. The scheme exploits the fact that these transactions are recorded as having gone through normal identity verification, making it difficult for victims to receive compensation from card companies even after being defrauded.
The Financial Supervisory Service (FSS) and the South Korean card industry are moving to comprehensively overhaul their joint fraud detection system in response to this new type of card phishing, and to introduce a process where card payments by people aged 70 and older for highly convertible goods undergo in-depth counseling before approval is decided. Investigations into damage complaints involving illegal merchants such as card kkang will also be expanded.
According to damage cases released by the FSS, scammers impersonated financial company employees, employers, loan providers, and romantic partners to induce victims into making card payments. The common thread is that victims are made to directly enter their own card information or complete identity verification before making the payment. This turns the formal legitimacy of the transaction into a shield for the scammer and a wall blocking relief for the victim.
The Trap of High-Income Side Jobs: 63 Million Won in Damages
Ms. B, a woman in her 20s, started a side job she found on a job site where she would order items on behalf of someone else and pay by card, with the promise that the cost of goods plus profit would be returned to her. In the beginning, the payment amounts and profits arrived as promised. Once trust was established, the scammer increased the payment scale by citing high-value orders, team missions, and membership tier upgrades.
She eventually paid for multiple items by card and even took out loans. Once the payment amounts grew, the scammer abruptly stopped the refunds. Total damages reached 63 million won (approximately $47,000). The card company refused to compensate her on the grounds that Ms. B had made the card payments and taken out the loans herself.
A legitimate employer would never ask an employee to pay for company items using a personal credit card in the employee's own name. Paying small profits first to build trust and then demanding more money under the pretext of high-value orders or team missions is a classic side-job scam tactic.
Gift Certificates, Memberships, and Romance Scams
A scheme involving low-interest loan offers as bait to induce gift certificate purchases, which are then converted to cash, has also been confirmed. Ms. C, a woman in her 40s, received a call from a company called "OO Financial" saying she could get a low-interest loan. The company demanded that she first pay a loan brokerage fee by purchasing gift certificates with her credit card, converting them to cash, and sending the money. Ms. C paid 800,000 won (approximately $590), but the loan was never disbursed. She later filed a complaint with the card company but received no compensation because it was a transaction she had paid for directly.
Legitimate financial companies and loan brokers do not demand brokerage fees from consumers as a condition for loans. If someone demands gift certificate purchases, card payments, or cash transfers before a loan is disbursed, it should be treated as a likely scam.
Romance scams have also emerged, where scammers build intimacy through random chat apps and then demand gift certificate payments. Mr. D, a man in his 30s, purchased gift certificates with his credit card after a woman he met online appealed to him with an urgent situation. Following the scammer's instructions, he then sent the gift certificate PIN numbers to a specific company and transferred the cashed-out amount to another account. Damages totaled 4.5 million won (approximately $3,300).
Under current rules, individual credit card members can purchase up to 1 million won (approximately $740) per month in combined gift certificates, prepaid electronic payment instruments, and prepaid cards. If someone asks you to split purchases across multiple cards or sends a separate payment link to buy more than 1 million won in gift certificates per month, there is a high likelihood that an illegal merchant is involved.
When Card Kkang Is Involved: Investigating Even Delivery Status
Intelligent crimes where scammers first obtain the victim's membership information before approaching them have also been detected. Mr. E, a man in his 50s, received a call from a scammer impersonating a condominium company employee, telling him that his membership purchase had been confirmed. Believing the scammer, Mr. E provided his card number and expiration date over the phone, and a total of 6 million won (approximately $4,400) was charged.
The actual merchant was not the condominium company but a large restaurant. The restaurant owner had also been deceived by the scammer's claim that "sales records are needed to get a loan," and had generated fake card sales, then handed over the settlement funds received from the card company to the scammer. This is the so-called card kkang structure.
Although Mr. E voluntarily provided his card information, the merchant's fake sales were confirmed and the payment was canceled. Instead, the restaurant owner who sent the settlement funds to the scammer bore the financial loss.
Non-authenticated payments made with just a card number, CVC, and expiration date are vulnerable to financial fraud. If someone calls impersonating a membership contract company and demands fee payment, you should hang up and verify directly with the company's official customer service center. If you have already given out your card information, you should immediately freeze the card and request a reissue.
Stronger Detection Network, But Compensation Walls Remain
The FSS and the card industry have decided to revamp the joint fraud detection system shared by card companies to respond to new phishing schemes that exploit direct payments by the cardholder. The joint detection rules established in November 2024 were focused on preventing fraudulent payments by third parties, such as hacking or card information theft. Going forward, detection criteria will be strengthened to also capture transactions where victims were deceived into making direct payments, incorporating payment patterns and merchant characteristics. Excellent detection criteria operated by individual card companies will also be incorporated into the joint rules.
Particularly strengthened protection measures will be applied to people aged 70 and older. According to the Korean National Police Agency, voice phishing damage among those aged 70 and older increased from 777 cases in 2023 to 1,047 cases in 2024 and 1,493 cases in 2025. The 2025 figure represents a 42.6% increase from the year and nearly doubled in just two years.
Going forward, when a user aged 70 or older makes a payment for easily convertible items such as gift certificates and the transaction is flagged as suspicious, the card company will conduct in-depth counseling. The process involves confirming whether the purchase reflects the person's genuine intent or whether they are acting under a scammer's instructions, providing a cooling-off opportunity, and then approving the payment. The FSS plans to review the effectiveness of the measure and gradually expand the target age range and the scope of highly convertible products.
Investigations into phishing damage involving illegal merchants such as card kkang or fake sales will also be strengthened. When a complaint is filed, card companies will verify whether the actual goods were delivered and whether the transaction was conducted normally, examining the payment process and whether the merchant engaged in illegal activity. The intent is to avoid closing off the possibility of damage relief simply because the transaction was paid directly by the cardholder, and to look into whether the merchant was involved in fake sales or card kkang. Financial companies' management responsibilities will also be strengthened in the card merchant registration and dispute complaint handling processes.
However, even with a stronger detection system, transactions where the victim completed normal identity verification and made the payment remain difficult to compensate. Unlike transfer-based voice phishing, card payments offer limited damage relief through immediate account payment freezes.
This gap is precisely why scammers demand gift certificates, membership rights, and proxy purchases instead of bank transfers. The formal legitimacy of card payments — "I paid for it myself, so it's a legitimate transaction" — serves as a shield for scammers and a wall blocking relief for victims. This is the backdrop for growing calls to refine the standards of responsibility and compensation for damages from direct cardholder payments, beyond just fraud detection.
The FSS urged: "Legitimate financial companies do not demand gift certificate purchases or fee payments as a condition for loans. If someone impersonates a financial company employee and demands card payments in an unusual manner, you should first hang up and verify directly through the card company's customer service center."
Once added, BigGo Finance appears first in Google Top Stories, so you get the broadest, most up-to-the-minute, and most comprehensive global financial news first.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
