Problem

After a large data breach hit the news, you received a text: “You are eligible for breach compensation” or “Check whether your data was affected”. It contains your real name or address, and the link supposedly lets you claim money.

The days after a big breach are when scam texts peak. The breach is real, so the story is believable, and because the scammers use the leaked data itself, even your name matches. This is precision smishing.

Symptoms

  • It names a company that really had a breach.
  • It uses words like “compensation”, “refund”, “check your damage” or “eligible” to make you tap.
  • Part of your name, address or phone number is correct.
  • It says the deadline is today.
  • The link asks for card numbers, account numbers or a verification code “to confirm your identity”, or asks you to install an app.

Four checks that separate real from fake

1. Who sent it. Be wary of “official” notices from personal mobile numbers or numbers you have never seen. Sender IDs can be spoofed, so a familiar-looking number is not proof either.

2. The link. The strongest clue. A company name inside an address that is not the company’s official domain is fake: company-refund.com, company.co-kr.xyz, or a one-letter misspelling. A short link hides the destination entirely.

3. What it asks for. Full card numbers, account passwords or verification codes “for compensation” mean scam. An app install request makes it certain.

4. Does it match the official notice? Breached companies normally announce through their official app, website and email. Open the official app yourself — not via the link — and see whether the same notice exists.

How to check whether you were really affected

Never through the link in the text. Instead:

  • Read the company’s official app or website notice and any email it sent.
  • In Korea, the 털린 내 정보 찾기 service (kidc.eprivacy.go.kr) checks whether your account credentials were leaked.

Diagnose with DechoNet

  • Paste the message into the phishing link check. It shows, with reasons, whether the link reaches the official domain or a newly registered imitation, and how old that domain is.
  • The brand impersonation check shows how many lookalike domains and risky subdomains imitate the company.
  • Domain registration lookup shows when the link’s domain was created. A domain registered after the breach news is very likely a scam.

Resolution Checklist

  • Do not tap the link; check the notice in the company’s official app or website.
  • Confirm with the link checker whether the real destination is the company’s official domain.
  • If it asks for card numbers, account passwords or verification codes for “compensation”, stop.
  • Screenshot it, report it (Korea: 118) and delete it.
  • If you really were affected, change your passwords and consider registering with the FSS exposure-prevention system (pd.fss.or.kr).
  • Tell family members — especially parents — to check compensation news only in the official app.

When to Escalate

  • If you already typed details into the link, follow what to do after clicking a smishing link.
  • If money was taken, contact the police and your bank immediately.
  • For the company’s real compensation process, call the support number printed in its official app or website.

Paste the message and check it now

Paste the whole message or just the link. The text is not stored; each link is followed to where it really goes.