NHIS phishing scam exposes gaps in South Korea fraud insurance

A phishing scam that moves through impersonation, a malicious download and then a fraudulent transfer can cross three different coverage definitions in a single event

NHIS phishing scam exposes gaps in South Korea fraud insurance

Cyber

By Mav Rodriguez

A phishing campaign impersonating South Korea’s national health insurer is providing a real-world test for a developing corner of the insurance market, as insurers expand protection against financial scams that increasingly combine impersonation, malicious software and fraudulent transfers.

The National Health Insurance Service warned that fraudulent text messages were circulating under its name, telling recipients to check a bill before directing them to a fake website.

The messages use the agency’s branding to appear legitimate and tell recipients that they need to install a separate program to view the document. The download instead installs a malicious application.

The NHIS said its electronic notices and text messages covering bills for South Korea’s four major social insurance programs do not contain URLs: “If you receive such a message, delete it immediately or check with a branch office or the customer service center.”

The warning follows a sharp rise in financial fraud losses in South Korea last year. Voice-phishing losses reached 1.2578 trillion won in 2025, up 47.2% from 854.5 billion won a year earlier and exceeding 1 trillion won for the first time, according to National Police Agency figures.

The picture has improved considerably this year. Police data for the first half of 2026 showed reported voice-phishing cases falling 43% from the same period a year earlier, while losses declined 49.7%. Even with that reversal, the size of the underlying exposure is helping create a market for insurance products designed specifically around financial fraud.

South Korean insurers including Hyundai Marine & Fire Insurance, KakaoPay Insurance and Lotte Insurance have been expanding protection against voice phishing and other online financial crimes.

Hyundai Marine’s Digital Accident Safety Insurance, for example, provides up to 5 million won for cyber financial crime losses. NH NongHyup Bank has taken a different approach, offering people aged 60 and older free insurance that compensates up to 70% of certain voice-phishing losses, capped at 10 million won.

Those differences are significant because the category of “phishing” can cover very different events.

The NHIS scam begins with an impersonation text, moves through a fraudulent website and then relies on the victim installing malicious software. Other schemes may persuade victims to transfer money themselves without malware ever being involved.

For insurance products built around named types of financial fraud, the route by which the money disappears can therefore be as important as the eventual loss. Coverage limits, definitions and the circumstances under which a transaction was made can determine whether two victims of apparently similar scams receive the same response.

The issue is becoming more relevant across the region as organized fraud puts pressure on Asia-Pacific cyber insurance. Criminal networks defrauded people across Asia-Pacific of an estimated US$88.3 billion to US$114.1 billion in 2025, according to the United Nations Office on Drugs and Crime.

The threat has also become harder to separate neatly into conventional cybercrime categories, with criminal networks combining social engineering, compromised data and increasingly sophisticated digital tools.

South Korean regulators are responding alongside the insurance market. The Financial Services Commission has introduced a framework allowing financial companies, telecommunications providers and investigators to share information used to identify and block suspected phishing activity more quickly.

The government is also widening the system for recovering losses. Changes due to take effect on October 1 will extend South Korea’s telecommunications financial-fraud framework to virtual asset exchanges and allow certain cryptocurrency assets linked to phishing scams to be frozen and returned to victims.

That could reduce the portion of some fraud losses ultimately borne by insurers, while also changing how claims are assessed when funds can be recovered through other channels. The NHIS case shows how a single scam can move from impersonation to malware and financial theft, making the scope of cover more important as these products become more common.

Related Stories

Keep up with the latest news and events

Join our mailing list, it’s free!