13M Emails Push Japan Users Into Tech Support Scam

Trend Micro Simply Security · Medium sophistication
Last updated July 30, 2026

Researchers observed a long-running tech support scam that sent over 13 million emails, mostly to Japanese “.jp” addresses, pushing victims to fake security alert websites. The lures increasingly looked like workplace HR and internal IT notices, aiming to trick employees into clicking links, calling a bogus support line, and ultimately paying fees or moving money while attackers remotely controlled the device.

How the attack worked

This campaign combined mass email distribution with fake security warning websites and phone-based social engineering. Over a 165 day period, researchers observed more than 13 million emails, with 94% sent to addresses using Japan's .jp top-level domain. The emails used spoofed senders designed to look like the recipient's own address or a legitimate internal service, moving victims from a deceptive email to a fraudulent support call.

Clicking the link in these emails opened a fake site displaying a bogus security warning. That page pushed the victim to call a listed support number. Once on the phone, the attackers posed as technical support staff and often requested remote control of the victim's device. From there, the scheme moved through three stages: lure the user to the fake alert page, gain remote control while impersonating support staff, and then extract money through fraudulent support fees or wire transfers.

Why it succeeded

The lures increasingly mimicked ordinary workplace communications rather than generic security pop-ups. Starting in May 2026, subject lines referenced internal network security audits, confidential performance evaluations and promotion lists, and employee benefit notices like digital gift cards for a company anniversary. This shift toward workplace themed lures reflects an attempt to reach individuals inside companies and organizations, likely aiming for larger payouts than typical consumer targeting.

The combination of spoofed senders, rapidly rotating fake alert sites, and legitimate hosting and remote access services made the scam harder to filter and more convincing once a victim reached the fake warning page.

What to watch for

  • Urgent internal-sounding emails about security audits, performance reviews, salary changes, or employee benefits that include a link
  • Web pages that show alarming security warnings and push a phone call to an unfamiliar support number
  • Sender addresses that appear to match the recipient's own address or a familiar internal service
  • Requests during a support call to allow remote control of a device, followed by instructions to log into online banking

Building resistance

Organizations can reduce exposure by tightening sender authentication and building specific habits among employees:

  • Enforce SPF, DKIM, and DMARC to catch spoofed and self-spoofed sender patterns
  • Train employees to verify HR and IT notices through a known internal channel before clicking links
  • Instruct staff to close fake warning screens without calling any listed number and to verify alerts through official support contacts
  • Limit and monitor remote access tool usage, since scammers used remote control sessions to guide victims into banking actions that led to substantial financial losses

Because these lures now closely resemble routine workplace notices, awareness training should specifically cover HR and IT themed phishing, not just generic security alert scams.

Key findings

  • The campaign shifted from primarily malvertising to “sustained email distribution” that drove victims to fake security alert sites and then into fraudulent support calls.
  • Over 165 days, researchers observed “more than 13 million emails,” with “94%…sent to emails using Japan’s '.jp' top-level domain.”
  • The operation used “spoofed senders,” “rapidly rotating fake alert sites,” and “legitimate hosting and remote access services.”
  • Workplace-themed lures (performance reviews, salary revisions, security audits, internal notices) appeared from May 2026, suggesting a push toward organizational victims and larger payouts.
  • In confirmed cases, victims were coached, while attackers had remote control, to access online banking, leading to “substantial financial losses.”

Who’s being targeted

  • Commonly targeted roles: All employees, HR, IT/Helpdesk, Finance/Accounting, Executives.
  • Affected industries: Multiple industries (Japan-based organizations using .jp email), Consumers (individual users).
  • Attack channels: email, website, vishing.
  • Impersonated: Internal HR/IT / company system administrator (spoofed sender), HR department (internal notice) / internal corporate portal notifications, Company HR / employee benefits team.

Red flags to watch for

  • Sender address is spoofed to look like the recipient or an internal admin/service
  • Unexpected urgency tied to HR/IT processes with a link to an external site
  • Web page shows a scary warning and pushes a phone call to 'support'
  • Too-good-to-be-true/curiosity lure (promotion list) delivered by unsolicited email
  • Link leads to a security warning page unrelated to HR content
  • Pressure to call an unsolicited support number
  • Unsolicited 'benefits' email with a link and urgency
  • Mismatch between 'gift card' topic and a security warning web page
  • Request to pay fees or follow unusual payment/wire instructions
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did the tech support scam campaign work?

Attackers sent spoofed emails mimicking internal HR or IT notices with links to fake security alert sites, which pressured victims to call a bogus support line where scammers requested remote device access.

Why were Japanese users targeted?

According to the research, 94% of the more than 13 million emails observed over 165 days were sent to addresses using Japan's .jp top-level domain.

What happened after victims called the fake support number?

In confirmed cases, victims were coached to access their online banking accounts while attackers remotely controlled their devices, resulting in substantial financial losses.

How can organizations reduce risk from this type of scam?

Enforcing SPF, DKIM, and DMARC helps detect spoofed senders, and employees should avoid calling numbers shown in unsolicited security warning pop-ups, verifying alerts through official channels instead.

Read the video transcript

You get an email: "[Confidential] H2 performance evaluations and promotion list." Tempting, right? This is part of a 13‑million‑email tech support scam hitting .jp addresses. Click the link, and instead of HR, you land on a fake security alert page screaming that your device is infected and you must call support now. If you call, the "support" person walks you through installing a remote access tool, then calmly guides you into your online banking. That HR email just turned into a live money-transfer session under their control. Aha test: if an "internal" HR or IT email sends you to a scary security page with a phone number, stop. Close it, and contact HR or IT using your usual company channels, not that page.

Similar attacks

Hotel Wi‑Fi Lures and Entra Vishing Hit Users

Hotel Wi‑Fi Lures and Entra Vishing Hit Users

The article reports real-world social engineering operations, including a hotel Wi‑Fi campaign that pushed fake updates and device-code phishing to steal Microsoft 365 access. It also describes an alleged Microsoft Entra vishing campaign tied to data theft claims at Brinks Home, reinforcing the…

August 7, 2026
AI Browser Tricked into Spamming WhatsApp, Shopping

AI Browser Tricked into Spamming WhatsApp, Shopping

Researchers showed how a malicious web page could trick OpenAI’s Atlas AI-enabled browser into taking actions a user didn’t intend, like spamming WhatsApp contacts or modifying an Amazon account. The attacks used prompt-injection style instructions hidden in a seemingly legitimate “newsletter…

August 6, 2026
Greatness PhaaS Adds Device-Code MFA Bypass

Greatness PhaaS Adds Device-Code MFA Bypass

Criminals using the “Greatness” phishing-as-a-service kit are running real-world phishing campaigns that trick employees into approving a Microsoft device-code login flow, allowing attackers to bypass MFA and steal access tokens. Recent activity includes RingCentral “voicemail” lures and multi-step…

August 4, 2026
Phished npm Maintainer Led to Debug/Chalk Hijack

Phished npm Maintainer Led to Debug/Chalk Hijack

Amazon says North Korea-linked actors compromised widely used npm packages (including debug and chalk) by tricking a trusted maintainer into signing in through a lookalike npm domain. After gaining that trusted access, the attackers published malicious updates that altered crypto wallet…

July 30, 2026
Fake ChatGPT Billing Emails Steal Card Details

Fake ChatGPT Billing Emails Steal Card Details

Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented example used a fake “ChatGPT Plus payment failure” notice that sent victims to a fraudulent payment page designed to capture full credit…

July 28, 2026
Fake ChatGPT Billing Emails Steal Card Details

Fake ChatGPT Billing Emails Steal Card Details

Check Point reports that OpenAI’s ChatGPT became a top-10 most impersonated brand in Q2 2026 phishing. One observed example used a fake “ChatGPT Plus payment failed” billing email to drive victims to a credit-card theft page. The report also notes other brand-impersonation scams using cloned stores…

July 24, 2026