{"id":26238,"date":"2026-09-21T16:08:47","date_gmt":"2026-09-22T00:08:47","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2026\/09\/21\/13m-emails-sent-in-tech-support-scam-targeting-users-organizations-in-japan\/"},"modified":"2026-09-21T16:08:47","modified_gmt":"2026-09-22T00:08:47","slug":"13m-emails-sent-in-tech-support-scam-targeting-users-organizations-in-japan","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2026\/09\/21\/13m-emails-sent-in-tech-support-scam-targeting-users-organizations-in-japan\/","title":{"rendered":"13M+ Emails Sent in Tech Support Scam Targeting Users, Organizations in Japan"},"content":{"rendered":"<div class=\"articleBodyNoHero aem-GridColumn aem-GridColumn--default--12\">\n<div class=\"research-layout article container\" role=\"contentinfo\">\n<article class=\"research-layout--wrapper row\" data-article-pageid=\"1645179682\">\n<div class=\"col-xs-12 col-md-12 one-column\">\n<div class=\"col-xs-12 col-md-12\">\n<div class=\"article-details\" role=\"heading\">\n<span class=\"article-details__bar\" role=\"img\"><\/span><\/p>\n<p class=\"article-details__display-tag\">Cyber Crime<\/p>\n<h1 class=\"article-details__title\">13M+ Emails Sent in Tech Support Scam Targeting Users, Organizations in Japan<\/h1>\n<p class=\"article-details__description\">We analyzed a sustained tech support scam campaign that sent more than 13 million emails to Japanese addresses, with workplace-themed lures suggesting a possible expansion toward enterprise targets. <\/p>\n<p class=\"article-details__author-by\">By: Takehiro Iwai<\/p>\n<p>\t\t\t<time class=\"article-details__date\">Jul 23, 2026<\/time><br \/>\n<span>Read time:\u00a0<\/span><span class=\"eta\"><\/span> (<span class=\"words\"><\/span> words)\n\t<\/p>\n<div class=\"article-details__icons\">\n<!--Add This--><\/p>\n<div class=\"a2a_kit a2a_default_style\" data-a2a-icon-color=\"#717172\">\n<a class=\"a2a_dd addthis_link\" href=\"https:\/\/www.addtoany.com\/share\"><br \/>\n<img decoding=\"async\" alt=\"Share\" class=\"svg-icon\" src=\"\/etc.clientlibs\/trendresearch\/clientlibs\/clientlib-trendresearch\/resources\/img\/share-more.svg\"\/><br \/>\n<\/a><br \/>\n<a class=\"a2a_button_print addthis_link\"><br \/>\n<img decoding=\"async\" alt=\"Print\" class=\"svg-icon\" src=\"\/etc.clientlibs\/trendresearch\/clientlibs\/clientlib-trendresearch\/resources\/img\/printer.svg\"\/><br \/>\n<\/a>\n<\/div>\n<p><!--Add to Folio--><\/p>\n<div class=\"add-to-folio tooltip\">\n<span class=\"icon-folio-thin\"><\/span><\/p>\n<div class=\"right\">\n<p>Save to Folio<\/p>\n<p><i><\/i>\n<\/div>\n<\/div>\n<p><!--Subscribe--><\/p>\n<div class=\"subscribe\">\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<hr class=\"research-layout-divider\"\/>\n<main class=\"main--content col-xs-12 col-lg-8 col-lg-push-2\"><\/p>\n<div>\n<\/div>\n<div class=\"richText\">\n<div>\n<ul>\n<li><span class=\"rte-red-bullet\">We uncovered a large-scale tech support scam campaign that has expanded beyond the more commonly observed use of malvertising to include sustained email distribution. The campaign used spoofed senders, rapidly rotating fake alert sites, globally distributed delivery infrastructure, and legitimate hosting and remote access services to move victims from deceptive emails to fraudulent support calls.<\/span><\/li>\n<li><span class=\"rte-red-bullet\">More than 13 million emails were observed over 165 days, with 94% sent to addresses using Japan\u2019s \u201c.jp\u201d top-level domain. The campaign involved more than 240,000 IP addresses and over 33,000 disposable landing sites.<\/span><\/li>\n<li><span class=\"rte-red-bullet\">The appearance of lures involving performance reviews, salary revisions, security audits, and other internal notices indicates a shift toward social engineering designed to attract individuals in workplace settings. This might reflect an effort to reach organizational accounts and pursue larger financial payouts.<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Users should avoid links and phone numbers presented in unsolicited messages, close fake warning screens without engaging, and verify alerts through official channels. Organizations should strengthen email authentication and filtering, restrict unauthorized remote-access software, monitor suspicious international calls, and train employees to recognize and report tech support scams.<\/span><\/li>\n<\/ul>\n<p>From mid-December 2025 through May 2026, we observed and analyzed a large-scale and sustained tech support scam campaign, luring victims to fake security alert websites via email. Over roughly five and a half months (165 days), we confirmed that more than 13 million emails were delivered from over 240,000 IP addresses, with more than 33,000 disposable fake alert sites serving as landing pages. Our analysis found that the campaign combined high-volume distribution, globally dispersed delivery infrastructure, rapidly rotating landing sites, and an expanding focus that appeared to include individuals within organizations:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">Of<b> <\/b>the more than 13 million emails we\u2019ve analyzed over 165 days, 94% were sent to emails using Japan\u2019s \u201c.jp\u201d top-level domain.<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Emails were sent or relayed from roughly 240,000 IP addresses distributed around the world.<\/span><\/li>\n<li><span class=\"rte-red-bullet\">The sites linked from the emails were built and discarded in quick succession, with more than 33,000 sites observed.<\/span><\/li>\n<li><span class=\"rte-red-bullet\">From May onward, we also observed emails that appear to target individuals within organizations.<\/span><\/li>\n<\/ul>\n<\/div>\n<\/div>\n<div class=\"image\">\n<figure class=\"image-figure\">\n<a href=\"\/content\/dam\/trendmicro\/global\/en\/research\/26\/g\/japan-tech-support-scams\/fig1.png\" id=\"4f4c6b\" rel=\"noopener noreferrer\" target=\"_blank\"><br \/>\n<img decoding=\"async\" alt=\"Figure 1. Example of an email observed in March 2026 that directed recipients to a fake site used in a tech support scam\" src=\"\/content\/dam\/trendmicro\/global\/en\/research\/26\/g\/japan-tech-support-scams\/fig1.png\"\/><br \/>\n<\/a><\/p>\n<div class=\"caption-image-container\"><figcaption>Figure 1. Example of an email observed in March 2026 that directed recipients to a fake site used in a tech support scam<\/figcaption><div class=\"download-anchor-wrapper\">\n<a class=\"download-anchor\" download=\"\" href=\"\/content\/dam\/trendmicro\/global\/en\/research\/26\/g\/japan-tech-support-scams\/fig1.png\"><br \/>\n<span class=\"material-symbols-outlined\">download<\/span><br \/>\n<\/a>\n<\/div>\n<\/div>\n<\/figure>\n<\/div>\n<div>\n<div class=\"richText\">\n<div>\n<h1><b><span class=\"body-subhead-title\">What is a tech support scam?<\/span><\/b><\/h1>\n<p>A tech support scam is a fraud scheme that displays fake security warnings on a PC or smartphone, such as \u201cyour device is infected\u201d and \u201cyour account has been compromised,\u201d to steer victims toward a bogus technical support line and \u00a0trick them into paying fraudulent support fees. Threat actors take the victims\u2019 money in three stages:<\/p>\n<ol>\n<li>Lure users to a fake security alert site.<\/li>\n<li>Remotely control the device while posing as tech support staff.<\/li>\n<li>Extract money through fraudulent support fees or wire transfers.<\/li>\n<\/ol>\n<p>Our <a href=\"https:\/\/www.trendmicro.com\/ja_jp\/about\/press-release\/2024\/pr-20240425-01.html\">previous research<\/a> identified tech support scams as one of the largest threats facing consumers in Japan. For example, in 2023, we detected and blocked more than 9 million visits to Japanese-language tech support scam sites among Windows users, a scale indicating that roughly 10% encountered such site in some form.<\/p>\n<p><a href=\"https:\/\/www.npa.go.jp\/bureau\/criminal\/souni\/tokusyusagi\/hurikomesagi_toukei2025.pdf\"><\/a>According to the <a href=\"https:\/\/www.npa.go.jp\/bureau\/criminal\/souni\/tokusyusagi\/hurikomesagi_toukei2025.pdf\">Japanese National Police Agency\u2019s report<\/a> on special fraud and social media-based (SNS) investment and romance scams (dated May 22, 2026, which covers data from 2025) \u201csupport-pretext\u201d billing fraud (the category corresponding to tech support scams) accounted for 1,048 reported cases (down 31.2% from 2024) and 1.49 billion yen in losses (up 48.1% from 2024). While reported cases are trending downward, the average loss per case has roughly doubled.<\/p>\n<p>In recent years, malvertising in web ads has been the dominant method of steering victims to fake alert sites. However, since mid-December 2025, we have observed a shift toward large-scale email distribution.<\/p>\n<p>This article lays out the full picture of this campaign, including how the threat actors abused legitimate tools and services. Their inclusion does not indicate that the products or services mentioned contain vulnerabilities or security flaws.<\/p>\n<h1><b><span class=\"body-subhead-title\">Scale and trend of the email campaign<\/span><\/b><\/h1>\n<p>The campaign has been observed continuously since mid-December 2025, with approximately 13.38 million emails (a daily average of about 81,000) observed over 165 days. About 94% of the emails we observed were addressed to .jp domains, that is, Japanese email addresses.<\/p>\n<p>As shown in Figure 2, email volume peaked in February 2026 (about 4.45 million emails, or a daily average of about 160,000) and has declined since, but as of May, an average of about 30,000 emails per day were still being delivered.<\/p>\n<\/div>\n<\/div>\n<div class=\"image\">\n<figure class=\"image-figure\">\n<a href=\"\/content\/dam\/trendmicro\/global\/en\/research\/26\/g\/japan-tech-support-scams\/fig2.png\" id=\"a2d36b\" rel=\"noopener noreferrer\" target=\"_blank\"><br \/>\n<img decoding=\"async\" alt=\"Figure 2. The volume of emails observed in the campaign\" src=\"\/content\/dam\/trendmicro\/global\/en\/research\/26\/g\/japan-tech-support-scams\/fig2.png\"\/><br \/>\n<\/a><\/p>\n<div class=\"caption-image-container\"><figcaption>Figure 2. The volume of emails observed in the campaign<\/figcaption><div class=\"download-anchor-wrapper\">\n<a class=\"download-anchor\" download=\"\" href=\"\/content\/dam\/trendmicro\/global\/en\/research\/26\/g\/japan-tech-support-scams\/fig2.png\"><br \/>\n<span class=\"material-symbols-outlined\">download<\/span><br \/>\n<\/a>\n<\/div>\n<\/div>\n<\/figure>\n<\/div>\n<div class=\"richText\">\n<div>\n<p>The emails\u2019 arrival times concentrate between 9:00 and 21:00 Japan Standard Time (JST), indicating that the delivery schedule is operated to match active hours in Japan.<\/p>\n<\/div>\n<\/div>\n<div class=\"image\">\n<figure class=\"image-figure\">\n<a href=\"\/content\/dam\/trendmicro\/global\/en\/research\/26\/g\/japan-tech-support-scams\/fig3.png\" id=\"3545b8\" rel=\"noopener noreferrer\" target=\"_blank\"><br \/>\n<img decoding=\"async\" alt=\"Figure 3. Email volume by hour of day (JST) Note: Figures are based on email gateway telemetry, because endpoint devices might not accurately record delivery times or relay\/source IP addresses.\" src=\"\/content\/dam\/trendmicro\/global\/en\/research\/26\/g\/japan-tech-support-scams\/fig3.png\"\/><br \/>\n<\/a><\/p>\n<div class=\"caption-image-container\"><figcaption>Figure 3. Email volume by hour of day (JST) Note: Figures are based on email gateway telemetry, because endpoint devices might not accurately record delivery times or relay\/source IP addresses.<\/figcaption><div class=\"download-anchor-wrapper\">\n<a class=\"download-anchor\" download=\"\" href=\"\/content\/dam\/trendmicro\/global\/en\/research\/26\/g\/japan-tech-support-scams\/fig3.png\"><br \/>\n<span class=\"material-symbols-outlined\">download<\/span><br \/>\n<\/a>\n<\/div>\n<\/div>\n<\/figure>\n<\/div>\n<div class=\"richText\">\n<div>\n<p>The fake security alert sites used as landing pages numbered more than 33,000 over the 165 days. More than 100 sites per day were observed from the campaign\u2019s early phase, and 400 \u2013 1,000 per day almost every day since January. By treating large numbers of websites (URLs) as disposable, the threat actors attempt to evade detection by security products. While email volume has declined since the February peak, the number of unique landing sites has remained largely unchanged.<\/p>\n<\/div>\n<\/div>\n<div class=\"image\">\n<figure class=\"image-figure\">\n<a href=\"\/content\/dam\/trendmicro\/global\/en\/research\/26\/g\/japan-tech-support-scams\/fig4.png\" id=\"138966\" rel=\"noopener noreferrer\" target=\"_blank\"><br \/>\n<img decoding=\"async\" alt=\"Figure 4. Daily count of fake security alert sites (unique hosts per day)\" src=\"\/content\/dam\/trendmicro\/global\/en\/research\/26\/g\/japan-tech-support-scams\/fig4.png\"\/><br \/>\n<\/a><\/p>\n<div class=\"caption-image-container\"><figcaption>Figure 4. Daily count of fake security alert sites (unique hosts per day)<\/figcaption><div class=\"download-anchor-wrapper\">\n<a class=\"download-anchor\" download=\"\" href=\"\/content\/dam\/trendmicro\/global\/en\/research\/26\/g\/japan-tech-support-scams\/fig4.png\"><br \/>\n<span class=\"material-symbols-outlined\">download<\/span><br \/>\n<\/a>\n<\/div>\n<\/div>\n<\/figure>\n<\/div>\n<div class=\"richText\">\n<div>\n<h1><b><span class=\"body-subhead-title\">The scam emails\u2019 characteristics<\/span><\/b><\/h1>\n<p>We categorized the emails into the following:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\"><b>Fake warnings<\/b>: Purporting to alert the recipient to a security or account problem<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Adult\/pornographic content<\/b>: Using sexually explicit text to draw interest<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Impersonation of specific organizations<\/b>: Posing as legitimate organizations, such as major e-commerce sites, public agencies, and security vendors<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Emails targeting individuals within organizations<\/b>: Disguised as internal corporate notices (e.g., performance reviews, salary revisions)<\/span><\/li>\n<\/ul>\n<p>The first two categories have been observed throughout the campaign since its early days and account for the majority of the emails.<\/p>\n<p>Impersonation emails began appearing in mid-April 2026 and include messages posing as major e-commerce sites, transportation and financial institutions, the National Tax Agency (using unpaid tax reminders as a lure), and job listings.<\/p>\n<p>The last category began appearing in May 2026. This included emails about \u201cperformance reviews,\u201d which were designed to lure individuals inside companies and other organizations to fake alert sites.<\/p>\n<p>While tech support scams primarily target individual users, organizations have also suffered losses. In confirmed cases, the victims were directed to access their online banking accounts while the threat actors remotely controlled their devices, resulting in substantial financial losses. This suggests that the threat actors might be pursuing larger payouts from businesses.<\/p>\n<p>Figure 5 shows the daily percentage of emails whose subject lines contain keywords such as \u201cperformance review\u201d (\u4eba\u4e8b\u8a55\u4fa1) and \u201csalary revision\u201d (\u7d66\u4e0e\u6539\u5b9a). Their appearance indicates a shift toward themes designed to attract individuals in workplace settings.<\/p>\n<\/div>\n<\/div>\n<div class=\"image\">\n<figure class=\"image-figure\">\n<a href=\"\/content\/dam\/trendmicro\/global\/en\/research\/26\/g\/japan-tech-support-scams\/fig5.png\" id=\"214a4c\" rel=\"noopener noreferrer\" target=\"_blank\"><br \/>\n<img decoding=\"async\" alt=\"Figure 5. Percentage of emails whose subject lines contain keywords targeting individuals within organizations\" src=\"\/content\/dam\/trendmicro\/global\/en\/research\/26\/g\/japan-tech-support-scams\/fig5.png\"\/><br \/>\n<\/a><\/p>\n<div class=\"caption-image-container\"><figcaption>Figure 5. Percentage of emails whose subject lines contain keywords targeting individuals within organizations<\/figcaption><div class=\"download-anchor-wrapper\">\n<a class=\"download-anchor\" download=\"\" href=\"\/content\/dam\/trendmicro\/global\/en\/research\/26\/g\/japan-tech-support-scams\/fig5.png\"><br \/>\n<span class=\"material-symbols-outlined\">download<\/span><br \/>\n<\/a>\n<\/div>\n<\/div>\n<\/figure>\n<\/div>\n<div class=\"richText\">\n<div>\n<p>Among the emails observed in May 2026 that target organizations, we observed the following subject lines (translated from Japanese):<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">[Urgent] Internal network security audit: Request to verify suspicious device activity and logs<\/span><\/li>\n<li><span class=\"rte-red-bullet\">[Confidential] Advance release of the H2 FY2026 performance evaluations and promotion candidate list<\/span><\/li>\n<li><span class=\"rte-red-bullet\">[Important \/ All employees] Confirmation of H2 FY2026 salary revisions and evaluation feedback (ID: HR-SYS-{number})<\/span><\/li>\n<li><span class=\"rte-red-bullet\">[Employee benefits] Notice: Digital Amazon gift cards for all employees to mark the company anniversary<\/span><\/li>\n<li><span class=\"rte-red-bullet\">[Important notice] Changes to commuting expense reimbursement rules and re-application procedures<\/span><\/li>\n<li><span class=\"rte-red-bullet\">[Advance release] Great work this term! Your evaluation and some good news (upcoming promotion list)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">[Notice] Fact-finding regarding a compliance violation (complaint) addressed to {company domain}<\/span><\/li>\n<li><span class=\"rte-red-bullet\">[Important] Re-registration of emergency contacts and the safety confirmation system<\/span><\/li>\n<li><span class=\"rte-red-bullet\">[Important] Request to test login and verify settings ahead of company-wide system maintenance<\/span><\/li>\n<li><span class=\"rte-red-bullet\">[Urgent] Request for confirmation regarding the flat-rate tax cut and refund procedures for overpaid taxes<\/span><\/li>\n<\/ul>\n<p>More than 90% of the sender addresses were spoofed to match the recipient\u2019s own address or the address of a legitimate service, with the intent of convincing recipients that the message came from their organization\u2019s system administrator or a genuine service. In emails posing as specific organizations, we also confirmed spoofing of the very addresses those organizations actually use to send email to their users.<\/p>\n<p>While sender address spoofing makes recipients easier to deceive, sender domain authentication standards, such as Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM), and Domain-based Message Authentication, Reporting, and Conformance (DMARC), can help detect many of these attacks.<\/p>\n<h1><b><span class=\"body-subhead-title\">Email delivery infrastructure<\/span><\/b><\/h1>\n<p>More than 240,000 IP addresses distributed around the world were observed sending or relaying the emails. Brazil accounted for the largest email volume, while China had the largest number of unique sending\/relaying IP addresses.<\/p>\n<p>One likely explanation for this enormous number of IP addresses is that legitimate internet-of-things (IoT) devices and similar equipment have been hijacked by the threat actors and abused as email delivery infrastructure. We have also observed telltale behaviors that appear to stem from the delivery infrastructure, such as consistent offsets between the timestamps recorded in email headers and the actual receipt times.<\/p>\n<\/div>\n<\/div>\n<div class=\"image\">\n<figure class=\"image-figure\">\n<a href=\"\/content\/dam\/trendmicro\/global\/en\/research\/26\/g\/japan-tech-support-scams\/fig6.png\" id=\"781372\" rel=\"noopener noreferrer\" target=\"_blank\"><br \/>\n<img decoding=\"async\" alt=\"Figure 6. Email count and unique source IP count by country (top 20 countries by email count from email gateway telemetry)\" src=\"\/content\/dam\/trendmicro\/global\/en\/research\/26\/g\/japan-tech-support-scams\/fig6.png\"\/><br \/>\n<\/a><\/p>\n<div class=\"caption-image-container\"><figcaption>Figure 6. Email count and unique source IP count by country (top 20 countries by email count from email gateway telemetry)<\/figcaption><div class=\"download-anchor-wrapper\">\n<a class=\"download-anchor\" download=\"\" href=\"\/content\/dam\/trendmicro\/global\/en\/research\/26\/g\/japan-tech-support-scams\/fig6.png\"><br \/>\n<span class=\"material-symbols-outlined\">download<\/span><br \/>\n<\/a>\n<\/div>\n<\/div>\n<\/figure>\n<\/div>\n<div class=\"richText\">\n<div>\n<p>We analyzed the top 10,000 sending IP addresses by send-event count against the information recorded in Shodan, a search engine for internet-connected systems and services. For 5,940 of them, no running service could be confirmed. For the remaining 4,060, some service was confirmed to be running.<\/p>\n<p>Of these, 3,231 IP addresses were running services that appear to operate on MikroTik devices, and on 2,657 of those IP addresses, TCP port 2000 was reachable from the internet. Many of these IP addresses have been observed as sources of attack-like traffic, such as port scanning and spam delivery, suggesting they are in a state where some form of malicious activity is possible. After MikroTik devices, the most common services running on these IP addresses were OpenSSH (284), nginx (184), and Apache (144), confirming that IoT devices, web servers, and similar systems were in operation.<\/p>\n<h1><b><span class=\"body-subhead-title\">Attack chain of the fake security alert sites<\/span><\/b><\/h1>\n<p>Clicking the link in the email opens a fake site that displays a bogus warning message. The fake warnings on these landing sites are nearly identical to those seen in tech support scams to date, falsely claiming that a security problem has occurred on the device.<\/p>\n<\/div>\n<\/div>\n<div class=\"image\">\n<figure class=\"image-figure\">\n<a href=\"\/content\/dam\/trendmicro\/global\/en\/research\/26\/g\/japan-tech-support-scams\/fig7.png\" id=\"b3de5f\" rel=\"noopener noreferrer\" target=\"_blank\"><br \/>\n<img decoding=\"async\" alt=\"Figure 7. An example of a fake security alert site that prompts users to click a malicious link\" src=\"\/content\/dam\/trendmicro\/global\/en\/research\/26\/g\/japan-tech-support-scams\/fig7.png\"\/><br \/>\n<\/a><\/p>\n<div class=\"caption-image-container\"><figcaption>Figure 7. An example of a fake security alert site that prompts users to click a malicious link<\/figcaption><div class=\"download-anchor-wrapper\">\n<a class=\"download-anchor\" download=\"\" href=\"\/content\/dam\/trendmicro\/global\/en\/research\/26\/g\/japan-tech-support-scams\/fig7.png\"><br \/>\n<span class=\"material-symbols-outlined\">download<\/span><br \/>\n<\/a>\n<\/div>\n<\/div>\n<\/figure>\n<\/div>\n<div class=\"richText\">\n<div>\n<p>The fake alert sites are built on the static website hosting feature of Microsoft Azure Blob Storage. Abusing legitimate hosting services in this way appears advantageous to threat actors because HTML\/JS files placed in storage can easily be published over HTTPS, which has become a standard tactic in tech support scams.<\/p>\n<p>Roughly 90% of the approximately 33,000 sites were used as email links for only a single day. The threat actors abuse cloud services to build and discard sites in a disposable fashion, attempting to evade detection by security products.<\/p>\n<\/div>\n<\/div>\n<div class=\"image\">\n<figure class=\"image-figure\">\n<a href=\"\/content\/dam\/trendmicro\/global\/en\/research\/26\/g\/japan-tech-support-scams\/fig8.png\" id=\"ee25f2\" rel=\"noopener noreferrer\" target=\"_blank\"><br \/>\n<img decoding=\"async\" alt=\"Figure 8. Observation period of the fake alert sites (days observed as links in emails, based on email gateway telemetry)\" src=\"\/content\/dam\/trendmicro\/global\/en\/research\/26\/g\/japan-tech-support-scams\/fig8.png\"\/><br \/>\n<\/a><\/p>\n<div class=\"caption-image-container\"><figcaption>Figure 8. Observation period of the fake alert sites (days observed as links in emails, based on email gateway telemetry)<\/figcaption><div class=\"download-anchor-wrapper\">\n<a class=\"download-anchor\" download=\"\" href=\"\/content\/dam\/trendmicro\/global\/en\/research\/26\/g\/japan-tech-support-scams\/fig8.png\"><br \/>\n<span class=\"material-symbols-outlined\">download<\/span><br \/>\n<\/a>\n<\/div>\n<\/div>\n<\/figure>\n<\/div>\n<div class=\"richText\">\n<div>\n<p>The fake alert sites employ techniques, such as content encryption, to evade analysis. Barracuda Networks has published a <a href=\"https:\/\/blog.barracuda.com\/2026\/05\/20\/threat-spotlight-cypherloc-scareware\">detailed analysis<\/a> of sites with the same structure.<\/p>\n<h1><b><span class=\"body-subhead-title\">Phone numbers used in the tech support scam<\/span><\/b><\/h1>\n<p>The fake alert pages that the emails lead to display phone numbers that connect to the scam\u2019s call centers.<\/p>\n<p>Figure 9 shows the daily count of phone numbers displayed on tech support scam sites, collected and verified since late February 2026. All of the observed numbers were international numbers used primarily in North America. While the fake alert sites are used for only about a day, most of the scam phone numbers remain in use for comparatively long periods of a week or more.<\/p>\n<\/div>\n<\/div>\n<div class=\"image\">\n<figure class=\"image-figure\">\n<a href=\"\/content\/dam\/trendmicro\/global\/en\/research\/26\/g\/japan-tech-support-scams\/fig9.png\" id=\"bb057a\" rel=\"noopener noreferrer\" target=\"_blank\"><br \/>\n<img decoding=\"async\" alt=\"Figure 9. Number of fake alert sites by scam phone number\" src=\"\/content\/dam\/trendmicro\/global\/en\/research\/26\/g\/japan-tech-support-scams\/fig9.png\"\/><br \/>\n<\/a><\/p>\n<div class=\"caption-image-container\"><figcaption>Figure 9. Number of fake alert sites by scam phone number<\/figcaption><div class=\"download-anchor-wrapper\">\n<a class=\"download-anchor\" download=\"\" href=\"\/content\/dam\/trendmicro\/global\/en\/research\/26\/g\/japan-tech-support-scams\/fig9.png\"><br \/>\n<span class=\"material-symbols-outlined\">download<\/span><br \/>\n<\/a>\n<\/div>\n<\/div>\n<\/figure>\n<\/div>\n<div class=\"richText\">\n<div>\n<p>Over roughly three months (February 26 \u2013 May 31, 2026), we confirmed 4,721 fake alert sites but only 11 distinct phone numbers displayed on them. A single number is reused across hundreds of sites. Blocking known scam phone numbers, or alerting users before a call is placed, can help disrupt the campaign by cutting off its primary path to victim engagement.<\/p>\n<h1><b><span class=\"body-subhead-title\">Conclusion and security best practices<\/span><\/b><\/h1>\n<p>Tech support scams work by stoking the victims\u2019 anxiety and fear to degrade their judgment, robbing them of time to think and opportunity to consult others. This campaign is no exception, combining multiple forms of psychological manipulation, including subject lines and warning screens engineered for urgency, disguising senders as legitimate services, and using fear like screen locking and alarm sounds.<\/p>\n<p>Once users understand how the scam works, it becomes much easier to respond appropriately Users and organizations should adopt the following security best practices to recognize the warning signs, avoid engagement, and reduce the risk of financial loss:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\"><b>Treat any message demanding an immediate decision as a likely scam.<\/b> Common to phishing as well as tech support scams, warnings that stoke urgency is a classic social engineering technique for robbing victims of their calm judgment.<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Separate a legitimate service\u2019s \u201cname\u201d from its \u201cactual contact channels\u201d.<\/b> Legitimate vendors as well as security products and platforms never display a phone number on a warning screen. Do not use phone numbers shown on screen or links inside emails, and always open the official website from your bookmarks to verify.<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Pause before taking action. <\/b>Alarm sounds, screen locks, and seemingly urgent messages are theatrics designed to strip victims of their composure. Even if the screen appears frozen, calmly closing the web browser (or terminating it from Task Manager if necessary) resolves most cases.<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Identify trusted contacts in advance. <\/b>Regularly discuss how tech support scams operate with family, colleagues, and trusted friends, and establish reliable points of contact, such as legitimate support desks, consumer affairs centers, or the organization\u2019s security team. For users who might be especially vulnerable, such as an elderly family member, share information that can help them recognize warning signs.<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Focus on response, not blame. <\/b>Scammers use highly convincing tactics\u00a0 and anyone can fall victim. If an incident occurs, the priority should be to contact the police, a consumer affairs center, or the relevant financial institution as soon as possible. Sharing the experience can also help prevent others from falling for the same tactics.<\/span><\/li>\n<\/ul>\n<p>Because tech support scams rely on several points of engagement, users and organizations can reduce risk by blocking malicious emails and sites, avoiding suspicious links, limiting unauthorized remote access, and preparing people to recognize and report scam activity.<\/p>\n<p>The following measures can help users:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\"><b>Use security products.<\/b> Deploy products with features that block scam emails, sites, and phone numbers, which shut off the entry points automatically.<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Do not click links in emails directly.<\/b> The more urgently an email presses users to take action, the more should they avoid clicking its links.<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Learn how to handle fake warning screens.<\/b> Know how to exit a browser\u2019s full-screen mode, such as long-pressing the Esc key or keying in Ctrl + Alt + Del.<\/span><\/li>\n<\/ul>\n<p>Organizations and system administrators should adopt the following:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\"><b>Enforce sender domain authentication.<\/b> SPF, DKIM, and DMARC can dramatically reduce the sender-address spoofing that is this campaign\u2019s primary technique.<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Strengthen the email security gateway.<\/b> Deploy security products that inspect message bodies, attachments, and URLs in multiple layers, and continuously update filters for brand-impersonation emails and phishing URLs.<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Restrict and monitor remote access software.<\/b> Threat actors abuse legitimate remote-access software such as LogMeIn, UltraViewer, ScreenConnect, RustDesk, AnyDesk, and TeamViewer. Restrain unnecessary use through application control and monitor with extended detection and response (XDR).<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Monitor outbound international calls.<\/b> Restricting or flagging outbound international calls at the private branch exchange (PBX) or similar telephone systems is an effective way to cut off the attack\u2019s final stage.<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Regularly conduct employee education and phishing drills.<\/b> Regularly share tech support scam tactics and real-world campaigns to help employees recognize and respond to threats. Build an open organizational culture where problems can be reported.<\/span><\/li>\n<\/ul>\n<p>We will continuously observe and detect the emails, landing sites, and phone-number lures associated with this campaign.<\/p>\n<h1><span class=\"body-subhead-title\">Solution recommendations<\/span><\/h1>\n<h2><b><span class=\"body-subhead-title\"><span class=\"rte-sub-menu-text\">For individuals<\/span><\/span><\/b><\/h2>\n<p>TrendLife<b> <a href=\"https:\/\/www.trendmicro.com\/en_us\/forHome\/products\/trend-micro-scam-check.html\" target=\"_blank\">ScamCheck<\/a>, <\/b>an anti<b>&#8211;<\/b>scam mobile app, combines AI technologies to protect users from increasingly sophisticated scam threats. Its web threat protection blocks access to malicious websites including scam sites, while its scam call protection displays warnings for \u2014 and blocks \u2014 incoming and outgoing scam calls and international calls.<\/p>\n<p>TrendLife <a href=\"https:\/\/www.trendmicro.com\/en_us\/forHome\/products\/maximum-security.html\"><b>Maximum Security<\/b><\/a> blocks scam emails with its anti-scam email protection and blocks access to malicious websites with its web threat protection.<\/p>\n<h2><b><span class=\"body-subhead-title\"><span class=\"rte-sub-menu-text\">For enterprises<\/span><\/span><\/b><\/h2>\n<p>For enterprises, two effective measures are blocking the inflow of these suspicious emails and restraining the execution of unnecessary applications. On the email side, the correlated intelligence capability of <a href=\"https:\/\/www.trendmicro.com\/en_us\/business\/products\/email-and-collaboration.html\"><b>TrendAI Vision One\u2122 Email and Collaboration Security<\/b><\/a> can reduce the inflow of malicious email through rules that weigh multiple conditions, such as how recently a URL\u2019s domain was created, how rarely it has been observed, and whether the message body is written in Japanese. To restrain application execution, the application control capability of <a href=\"https:\/\/www.trendmicro.com\/en_us\/business\/products\/endpoint-security.html\"><b>TrendAI Vision One\u2122 Endpoint Security<\/b><\/a> can suppress specific remote-access software by specifying the certificates that legitimate remote-access tools use.<\/p>\n<h1><b><span class=\"body-subhead-title\">Indicators of Compromise (IoCs)<\/span><\/b><\/h1>\n<p>The following is a list of phone numbers confirmed on tech support scam sites (as of June 12, 2026), with \u201c010\u201d as the international call prefix and also written as \u201c+\u201d. Note that the URLs for the sites are not included, as they are disposable and change frequently, making them of low value from a defensive standpoint:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">01014788127410<\/span><\/li>\n<li><span class=\"rte-red-bullet\">01015015011324<\/span><\/li>\n<li><span class=\"rte-red-bullet\">01014156258206<\/span><\/li>\n<li><span class=\"rte-red-bullet\">01013479067411<\/span><\/li>\n<li><span class=\"rte-red-bullet\">01012076149424<\/span><\/li>\n<li><span class=\"rte-red-bullet\">01018774704156<\/span><\/li>\n<li><span class=\"rte-red-bullet\">01012083617998<\/span><\/li>\n<li><span class=\"rte-red-bullet\">01015513872525<\/span><\/li>\n<li><span class=\"rte-red-bullet\">01018146214182<\/span><\/li>\n<li><span class=\"rte-red-bullet\">01018082580290<\/span><\/li>\n<li><span class=\"rte-red-bullet\">01016189348316<\/span><\/li>\n<li><span class=\"rte-red-bullet\">01018444862853<\/span><\/li>\n<\/ul>\n<\/div>\n<\/div>\n<div class=\"richText\">\n<div>\n<h2><b><span class=\"body-subhead-title\">Research Contributions<\/span><\/b><\/h2>\n<ul>\n<li><span class=\"rte-red-bullet\">Yuya Sato (Senior Incident Response Consultant, Advanced Cyber Defense Group)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Yoshiki Kawada (Principal Threat Researcher)<\/span><\/li>\n<\/ul>\n<\/div>\n<\/div>\n<\/div>\n<section class=\"tag--list\">\n<div class=\"tag--list-title\">Tags<\/div>\n<div class=\"tag--list-tags\">\n<a class=\"tag--list-anchor\" href=\"\/en_us\/research.html?category=trend-micro-research:threats\/cyber-crime\">Cyber Crime<\/a><br \/>\n<span class=\"tag--list-separator\" role=\"separator\">|<\/span><br \/>\n<a class=\"tag--list-anchor\" href=\"\/en_us\/research.html?category=trend-micro-research:article-type\/research\">Research<\/a><br \/>\n<span class=\"tag--list-separator\" role=\"separator\">|<\/span><br \/>\n<a class=\"tag--list-anchor\" href=\"\/en_us\/research.html?category=trend-micro-research:threats\/phishing\">Phishing<\/a><br \/>\n<span class=\"tag--list-separator\" role=\"separator\">|<\/span><br \/>\n<a class=\"tag--list-anchor\" href=\"\/en_us\/research.html?category=trend-micro-research:medium\/article\">Articles, News, Reports<\/a>\n<\/div>\n<\/section>\n<p><\/main><br \/>\n<sidebar class=\"sidebar--left col-xs-12 col-lg-2 col-lg-pull-8\"><\/p>\n<h3 class=\"article-authors__title\">\n<p>\t\tAuthors<\/p>\n<\/h3>\n<p><!-- \/* Show Trend Micro if we don't have any authors for this article *\/ --><\/p>\n<ul class=\"article-authors__list\">\n<li class=\"article-authors__list-items\">\n<div class=\"article-authors__wrapper\" role=\"contentinfo authors profile\">\n<p class=\"article-authors__list-items__name\">Takehiro Iwai<\/p>\n<p class=\"article-authors__list-items__position\">Sr. DevOps Platform Engineer<\/p>\n<\/div>\n<\/li>\n<\/ul>\n<div class=\"article-authors__btn-wrapper\" role=\"button\">\n<a class=\"article-authors__button\" href=\"mailto:tm_research@trendmicro.com\" id=\"article-authors-contact-us-button\" target=\"target\"><br \/>\n\t\tContact Us<br \/>\n\t<\/a>\n<\/div>\n<p><\/sidebar><br \/>\n<sidebar class=\"sidebar--right col-xs-12 col-lg-2\"><\/p>\n<div class=\"sidebar--wrapper\" role=\"contentinfo sidebar\">\n<div class=\"row-1\" role=\"contentinfo related articles\">\n<div class=\"related--articles\" role=\"contentinfo related articles\">\n<h3 class=\"related--articles-title\">Related Articles<\/h3>\n<ul class=\"related--articles-items\">\n<li class=\"related--articles-item\">\n<a class=\"related--articles-item-anchor\" href=\"\/en_us\/research\/24\/c\/unveiling-earth-kapre-aka-redcurls-cyberespionage-tactics-with-t.html\"><br \/>\n\t\t\t\t\tUnveiling Earth Kapre aka RedCurl\u2019s Cyberespionage Tactics With Trend Micro MDR, Threat Intelligence<br \/>\n\t\t\t\t<\/a>\n<\/li>\n<li class=\"related--articles-item\">\n<a class=\"related--articles-item-anchor\" href=\"\/en_us\/research\/22\/h\/secure-access-service-edge-sase-security-company.html\"><br \/>\n\t\t\t\t\tA Secure Access Service Edge (SASE) Guide for Leaders<br \/>\n\t\t\t\t<\/a>\n<\/li>\n<li class=\"related--articles-item\">\n<a class=\"related--articles-item-anchor\" href=\"\/en_us\/research\/26\/g\/open-secure-ai-alliance.html\"><br \/>\n\t\t\t\t\tWhy the Open Secure AI Alliance Matters: Open Frontier Models, Open Deployment Flexibility<br \/>\n\t\t\t\t<\/a>\n<\/li>\n<\/ul>\n<\/div>\n<div class=\"archived--link\">\n<div class=\"archived--link-text\">\n<a href=\"\/en_us\/research.html\"><br \/>\n\t\t\t\tSee all articles<br \/>\n\t\t\t<\/a>\n<\/div>\n<div class=\"archived--link-icon\">\n<a href=\"\/en_us\/research.html\"><br \/>\n<span class=\"icon-chevron-right\"><\/span><br \/>\n<\/a>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<p><\/sidebar><br \/>\n<\/article>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Cyber Crime13M+ Emails Sent in Tech Support Scam Targeting Users, Organizations in JapanWe analyzed a sustained tech support scam campaign that sent more than 13 million emails to Japanese addresses, with workplace-themed lures suggesting a possible expansion toward enterprise targets.By: Takehiro IwaiJul 23, 2026Read time:(words)Save to FolioWe uncovered a large-scale tech support scam campaign that has expanded beyond the more commonly observed use of malvertising to include sustained email di<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[32777],"tags":[],"class_list":["post-26238","post","type-post","status-publish","format-standard","hentry","category-trend-micro"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26238","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=26238"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26238\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=26238"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=26238"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=26238"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}