Consumer Rights · Scam Alert · September 24, 2026
East Security Unveils New Types of Holiday Scams Families Urged to Establish Secret Verification Codes Confirm Requests for Money Using Known Phone Numbers Caution is advised regarding holiday scams that use artificial intelligence (AI) to mimic the voices of family members or to skillfully impersonate individuals using personal information.
Executive Briefing · Key Facts.
- asiae.co.kr issued a new alert: “Don’t Trust Faces or Voices”… AI Scam Alert Issued for Chuseok Holiday.
- Delivery channel shown in the reconstruction below: SMS.
- Pressure tactics matched: Unsolicited contact from someone you don’t know.
The Story So Far
Four New Types of Holiday Scams Revealed by ESTsecurity on the 25th. View original imageEast Security, a cybersecurity subsidiary of ESTsoft, issued a warning on the 25th by unveiling four new types of holiday scams that exploit AI technology.[1]
According to East Security, the new types include: ▲ Deep voice and deepfake video call scams that can be completed in just a few seconds using a voice sample ▲ AI-generated, customized phishing messages with correct grammar ▲ 'All-in-one account theft,' which targets banking, messenger, and social media accounts simultaneously ▲ And ultra-precise impersonation scams combined with a series of recent personal data leaks.[1]
East Security specifically warned that this technology, which can synthesize the voice and face of an acquaintance using a short audio clip, may be abused to contact people while impersonating a family member or relative. The company recommended that families set up a verification method using a secret code known only among them, and that in cases where there is an urgent request for money, they should call back using the number they already have to confirm.[1]
With advances in generative AI, the awkward or unnatural expressions that once characterized phishing texts have disappeared. Caution is also necessary when receiving customized scam messages made to appear real, using leaked personal information such as the recipient's name and affiliation.[1]
Every tactic above beats a specific human default. None of them beat a phone number you looked up yourself.
How to Spot & Avoid This Scam
This is what the approach actually looks like — study it before the list below:
How to Protect Yourself
- Verify any unexpected contact through a phone number or website you already know is real — never one the message itself provides.
If You Already Clicked or Replied
Responding to one of these is not the end of the story, and the first hour matters more than the mistake does. Work down this list in order:
- Stop communicating with the sender. Do not send a final message explaining that you know it is a scam — that only confirms the number or address is live.
- If you shared a password, change it everywhere you reused it, starting with email and banking. Reused passwords are how one disclosure becomes several.
- If you shared card or bank details, call the number printed on your card and ask for the account to be flagged and reissued.
- If you sent money by gift card, call the card issuer immediately — some balances can be frozen if the cards have not been drained yet.
- Turn on two-factor authentication where it is offered, so a stolen password alone is not enough to get in.
- Report it (see below). Reports are what let investigators connect one message to a wider campaign.
Where to Report It
- Federal Trade Commission — reportfraud.ftc.gov is the FTC’s own intake for fraud reports.[2]
- FBI Internet Crime Complaint Center — ic3.gov handles internet-enabled crime, including losses already incurred.[3]
- The impersonated organization — most banks and large platforms run their own abuse address; reporting there is what gets a fraudulent number or domain taken down.
What’s Disputed or Unconfirmed
This post reports what asiae.co.kr published and what a fixed detector matched in that text. It does not independently confirm the scale of the campaign, attribute it to anyone, or verify any figure the source reports. The example below the fold is a reconstruction built from the same reporting, not a captured message — so treat its wording as illustrative of the pattern, not as evidence of a specific message anyone received.
Consumer Protection & Settlement Resources
How to Verify This Yourself
Read the original alert directly at asiae.co.kr[1] — that page is the primary source for everything above. For the recovery steps, the FTC publishes its own guidance on what to do after a scam.[4]
Kemetic Minds Analysis
Scam reporting tends to arrive as a list of things not to do, which puts the burden entirely on the person being targeted. The more useful read is structural: every tactic in the table above exists because it reliably beats a specific human default — trusting a familiar logo, acting fast under a deadline, believing a stranger who already seems to know something about you.
None of those defaults are failures of intelligence. They are the same instincts that make ordinary transactions possible. That is why “just be careful” does not work as advice, and why the one habit worth building is mechanical rather than judgmental: when a message asks for money, credentials, or speed, verify it through a channel you chose yourself. That single rule defeats every tactic listed above, without requiring you to spot which one you are looking at.
References
- asiae.co.kr. “Don’t Trust Faces or Voices”… AI Scam Alert Issued for Chuseok Holiday. — primary source for this alert. ↩
- Federal Trade Commission. Report Fraud. — primary (U.S. government agency). ↩
- FBI Internet Crime Complaint Center (IC3). — primary (U.S. government agency). ↩
- Federal Trade Commission. What To Do if You Were Scammed. — primary (U.S. government agency). ↩
Related Reading
- More Consumer Rights coverage — the running Scam & Cybersecurity Watch archive.
- FTC: What To Do if You Were Scammed — the full official recovery guide.
Investigative methodology: this update was produced by scripts/scam_monitor.py from a real asiae.co.kr alert — not a language model. The quoted text above is verbatim from the source; the mockup, where shown, is a reconstructed illustration built from the same text (see its own caption), not a captured real message. Protection tips, red-flag explanations, and recovery steps are matched from fixed curated tables, not generated per story. The “Kemetic Minds Analysis” section is standing editorial commentary about how these tactics work in general — it is identical on every Scam Watch post and is not reporting about this particular alert.

