Problem

“[International] Overseas payment approved: 1,280,000 KRW on your ○○ card. If this was not you, call 02-XXXX-XXXX.” You did not buy anything, so you are about to call.

Payment-alert impersonation is usually after a phone call, not a click. Shaken by the amount, people call the number; a fake card agent says their identity was stolen, hands them to fake police or prosecutors, and eventually gets them to move money to a “safe account” or install a remote-control app. If there is a link, it leads to a fake “cancel payment” page that harvests card details.

Symptoms

  • An approval alert for a large or overseas purchase you never made.
  • A phone number or link “if this was not you”.
  • It starts with [International] / [국외발신].
  • Calling it passes you from “card company” to police, prosecutors or regulators.
  • Phrases like “safe account”, “protect your assets” or “install the security app”.

Three checks against a real alert

1. You choose the number. Never use the number or link in the text. Call only the number on the back of your card or one you find in the card company’s official app or website.

2. Check approvals in the official app. Log in yourself. If the charge is not there, it did not happen.

3. No agency moves your money. Police, prosecutors and the financial regulator never direct you to a “safe account” or ask you to install an app by phone. The moment you hear it, it is a scam.

Diagnose with DechoNet

  • If the text contains a link, paste it into the phishing link check. It shows, with reasons, whether it is the card company’s official domain or a new imitation. A text with only a phone number gives the checker no link to judge — rely on the three rules above.
  • The brand impersonation check shows lookalike domains imitating the card company.
  • Domain registration lookup shows when the link’s domain was created.

Resolution Checklist

  • Do not call the number in the text; do not tap the link.
  • Check approvals in the card company’s official app.
  • If worried, call the number on the back of your card.
  • Hang up the moment “safe account” or “security app” comes up.
  • Turn on the card app’s push alerts rather than trusting texts.
  • Screenshot the text, report it (Korea: 118) and delete it.

When to Escalate

  • If you transferred money, ask the police (Korea: 112) and your bank for a payment stop now. In Korea, payinfo.or.kr can also freeze your other accounts at once.
  • If you installed a remote-control app, follow the “you installed an app” steps in what to do after clicking a smishing link.
  • In Korea, the Financial Supervisory Service (1332) advises on recovery.

Paste the message and check it now

Paste the whole message or just the link. The text is not stored; each link is followed to where it really goes.