Security News

Cybersecurity news aggregator

HIGH Attacks Trend Micro Research

13M+ Emails Sent in Tech Support Scam Targeting Users, Organizations in Japan

A large-scale tech support scam campaign targeting Japanese users and organizations delivered over 13 million emails using spoofed senders and rapidly rotating, disposable fake alert sites to lure victims into fraudulent support calls. The attack vector involves social engineering via email with workplace-themed lures, leveraging globally distributed infrastructure and legitimate remote access services. Organizations should strengthen email authentication and filtering, restrict unauthorized remote-access software, and train employees to recognize and report such scams, while users should avoid engaging with unsolicited messages and verify alerts through official channels.
Read Full Article →

Cyber Crime 13M+ Emails Sent in Tech Support Scam Targeting Users, Organizations in Japan We analyzed a sustained tech support scam campaign that sent more than 13 million emails to Japanese addresses, with workplace-themed lures suggesting a possible expansion toward enterprise targets. By: Takehiro Iwai Jul 23, 2026 Read time: ( words) Save to Folio We uncovered a large-scale tech support scam campaign that has expanded beyond the more commonly observed use of malvertising to include sustained email distribution. The campaign used spoofed senders, rapidly rotating fake alert sites, globally distributed delivery infrastructure, and legitimate hosting and remote access services to move victims from deceptive emails to fraudulent support calls. More than 13 million emails were observed over 165 days, with 94% sent to addresses using Japan’s “.jp” top-level domain. The campaign involved more than 240,000 IP addresses and over 33,000 disposable landing sites. The appearance of lures involving performance reviews, salary revisions, security audits, and other internal notices indicates a shift toward social engineering designed to attract individuals in workplace settings. This might reflect an effort to reach organizational accounts and pursue larger financial payouts. Users should avoid links and phone numbers presented in unsolicited messages, close fake warning screens without engaging, and verify alerts through official channels. Organizations should strengthen email authentication and filtering, restrict unauthorized remote-access software, monitor suspicious international calls, and train employees to recognize and report tech support scams. From mid-December 2025 through May 2026, we observed and analyzed a large-scale and sustained tech support scam campaign, luring victims to fake security alert websites via email. Over roughly five and a half months (165 days), we confirmed that more than 13 million emails were delivered from over 240,000 IP addresses, with more than 33,000 disposable fake alert sites serving as landing pages. Our analysis found that the campaign combined high-volume distribution, globally dispersed delivery infrastructure, rapidly rotating landing sites, and an expanding focus that appeared to include individuals within organizations: Of the more than 13 million emails we’ve analyzed over 165 days, 94% were sent to emails using Japan’s “.jp” top-level domain. Emails were sent or relayed from roughly 240,000 IP addresses distributed around the world. The sites linked from the emails were built and discarded in quick succession, with more than 33,000 sites observed. From May onward, we also observed emails that appear to target individuals within organizations. Figure 1. Example of an email observed in March 2026 that directed recipients to a fake site used in a tech support scam download What is a tech support scam? A tech support scam is a fraud scheme that displays fake security warnings on a PC or smartphone, such as “your device is infected” and “your account has been compromised,” to steer victims toward a bogus technical support line and trick them into paying fraudulent support fees. Threat actors take the victims’ money in three stages: Lure users to a fake security alert site. Remotely control the device while posing as tech support staff. Extract money through fraudulent support fees or wire transfers. Our previous research identified tech support scams as one of the largest threats facing consumers in Japan. For example, in 2023, we detected and blocked more than 9 million visits to Japanese-language tech support scam sites among Windows users, a scale indicating that roughly 10% encountered such site in some form. According to the Japanese National Police Agency’s report on special fraud and social media-based (SNS) investment and romance scams (dated May 22, 2026, which covers data from 2025) “support-pretext” billing fraud (the category corresponding to tech support scams) accounted for 1,048 reported cases (down 31.2% from 2024) and 1.49 billion yen in losses (up 48.1% from 2024). While reported cases are trending downward, the average loss per case has roughly doubled. In recent years, malvertising in web ads has been the dominant method of steering victims to fake alert sites. However, since mid-December 2025, we have observed a shift toward large-scale email distribution. This article lays out the full picture of this campaign, including how the threat actors abused legitimate tools and services. Their inclusion does not indicate that the products or services mentioned contain vulnerabilities or security flaws. Scale and trend of the email campaign The campaign has been observed continuously since mid-December 2025, with approximately 13.38 million emails (a daily average of about 81,000) observed over 165 days. About 94% of the emails we observed were addressed to .jp domains, that is, Japanese email addresses. As shown in Figure 2, email volume peaked in February 2026 (about 4.45 million emails, or a daily average of about 160,000) and has declined since, but as of May, an average of about 30,000 emails per day were still being delivered. Figure 2. The volume of emails observed in the campaign download The emails’ arrival times concentrate between 9:00 and 21:00 Japan Standard Time (JST), indicating that the delivery schedule is operated to match active hours in Japan. Figure 3. Email volume by hour of day (JST) Note: Figures are based on email gateway telemetry, because endpoint devices might not accurately record delivery times or relay/source IP addresses. download The fake security alert sites used as landing pages numbered more than 33,000 over the 165 days. More than 100 sites per day were observed from the campaign’s early phase, and 400 – 1,000 per day almost every day since January. By treating large numbers of websites (URLs) as disposable, the threat actors attempt to evade detection by security products. While email volume has declined since the February peak, the number of unique landing sites has remained largely unchanged. Figure 4. Daily count of fake security alert sites (unique hosts per day) download The scam emails’ characteristics We categorized the emails into the following: Fake warnings : Purporting to alert the recipient to a security or account problem Adult/pornographic content : Using sexually explicit text to draw interest Impersonation of specific organizations : Posing as legitimate organizations, such as major e-commerce sites, public agencies, and security vendors Emails targeting individuals within organizations : Disguised as internal corporate notices (e.g., performance reviews, salary revisions) The first two categories have been observed throughout the campaign since its early days and account for the majority of the emails. Impersonation emails began appearing in mid-April 2026 and include messages posing as major e-commerce sites, transportation and financial institutions, the National Tax Agency (using unpaid tax reminders as a lure), and job listings. The last category began appearing in May 2026. This included emails about “performance reviews,” which were designed to lure individuals inside companies and other organizations to fake alert sites. While tech support scams primarily target individual users, organizations have also suffered losses. In confirmed cases, the victims were directed to access their online banking accounts while the threat actors remotely controlled their devices, resulting in substantial financial losses. This suggests that the threat actors might be pursuing larger payouts from businesses. Figure 5 shows the daily percentage of emails whose subject lines contain keywords such as “performance review” (人事評価) and “salary revision” (給与改定). Their appearance indicates a shift toward themes designed to attract individuals in workplace settings. Figure 5. Percentage of emails whose subject lines contain keywords targeting individuals within organizations download Among the emails observed in May 2026 that target organizations, we observed the following subject lines (translated from Japanese): [Urgent] Internal network security audit: Request to verify suspicious device activity and logs [Confidential] Advance release of the H2 FY2026 performance evaluations and promotion candidate list [Important / All employees] Confirmation of H2 FY2026 salary revisions and evaluation feedback (ID: HR-SYS-{number}) [Employee benefits] Notice: Digital Amazon gift cards for all employees to mark the company anniversary [Important notice] Changes to commuting expense reimbursement rules and re-application procedures [Advance release] Great work this term! Your evaluation and some good news (upcoming promotion list) [Notice] Fact-finding regarding a compliance violation (complaint) addressed to {company domain} [Important] Re-registration of emergency contacts and the safety confirmation system [Important] Request to test login and verify settings ahead of company-wide system maintenance [Urgent] Request for confirmation regarding the flat-rate tax cut and refund procedures for overpaid taxes More than 90% of the sender addresses were spoofed to match the recipient’s own address or the address of a legitimate service, with the intent of convincing recipients that the message came from their organization’s system administrator or a genuine service. In emails posing as specific organizations, we also confirmed spoofing of the very addresses those organizations actually use to send email to their users. While sender address spoofing makes recipients easier to deceive, sender domain authentication standards, such as Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM), and Domain-based Message Authentication, Reporting, and Conformance (DMARC), can help detect many of these attacks. Email delivery infrastructure More than 240,000 IP addresses distributed around the world were observed sending or relaying the emails. B

Share this article