En.Bloomingbit Phishing Attack Targets South Korean Online Shoppers, Stealing Credit Card Data
Article Content
- •Over 5,700 cases of credit card data theft reported in South Korea.
- •Phishing pages mimicked legitimate payment screens to steal sensitive information.
- •Consumers are advised to report suspicious requests for excessive personal information.
On July 5, 2026, the Financial Supervisory Service (FSS) of South Korea issued a consumer alert regarding a phishing scheme that has compromised credit card information on domestic online shopping sites. The Financial Security Institute reported 5,707 cases of stolen credit card data as of June 29, 2026. Attackers exploited weak security in online shopping malls to insert fake payment pages into the checkout process. These phishing pages prompted users to enter excessive personal information, including full resident registration numbers and all four digits of their card passwords. Victims were misled into thinking their transactions were legitimate due to misleading error messages. The FSS is collaborating with credit card companies to mitigate further losses and has urged consumers to be vigilant and report any suspicious activity. Immediate actions recommended include card suspension and password changes for affected users.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…