Safety Report/Automated Detection

Automated DetectionKakao shares data on User Protection Measures implemented through automated detection.

Menu selection

Preventing Phishing

KakaoTalk offers the "Globe Signal", "Stranger Signal" and "Fake Signal" functions (hereinafter referred to as "Talk Siren") to help protect users from phishing crimes. The Talk Siren function alerts users to potential phishing attempts.

Users can check the warning signs, then block or report accounts that are suspected of phishing. However, not every blocked or reported account is necessarily malicious or involved in phishing. The reported accounts will be reviewed by expert reviewers for any patterns of fraud and will be immediately and permanently restricted from using the service if such fraudulent activities are detected.

This report contains data on accounts that have been blocked or reported through the “Talk Siren” warning signs. Service-restriction data is excluded from this report and is available in the Enforcement > General Chat report.

Select Period:
Select Period

Summary

In the second half of 2025, approximately 165K accounts were blocked by users through Talk Siren alerts, including Globe Signal, Stranger Signal, and Fake Signal, and approximately 42K accounts were reported. The total numbers of blocks and reports decreased by approximately 35% and 30%, respectively, compared to the first half of 2025.

In particular, the approximately 52% drop in Stranger Signal blocks appears to reflect heightened user vigilance during the initial contact with unfamiliar parties and the alert system functioning as intended. However, this numerical decrease alone cannot be taken as evidence that phishing risk has fallen — it should be understood as an indicator limited to the scope captured by the system.

Recent phishing tactics are analyzed to be evolving in directions that bypass warning indicators — such as impersonation of family members or acquaintances, romance scams, and monetary requests following long-term trust building. These types tend to disguise themselves as trusted relationships rather than appearing at the unfamiliar-contact stage, and may be difficult to capture at the moment of a Talk Siren alert; they are sometimes identified through subsequent user reports and operator review.

In fact, during the same period, the number of accounts restricted under the Fraud and Impersonation category in the Enforcement > General Chat area increased compared to the previous half. This suggests that there are cases where harm not recognized, blocked, or reported during the early-warning stage emerges only through the enforcement process. Since automated detection and enforcement operate at different points in time, reviewing the two reports together provides a more multi-dimensional understanding of the overall flow of phishing response.

Kakao plans to improve the precision of user-report-type analysis and to continuously refine its detection logic based on patterns of anomalous activity and reports from malicious accounts. We also plan to strengthen user reporting channels and operator review systems to build a protection framework in which preventive measures and enforcement work in a complementary manner.

How many accounts were blocked or reported because a “Globe Signal” warning sign was displayed?

Blocked
Reported
0
50K
100K
150K
200K
2024 H1
2024 H2
2025 H1
2025 H2
How was the data calculated? (i): Number of unique accounts blocked or reported after the “Globe Signal” was displayed during the relevant period

How many accounts were blocked or reported because a "Stranger Signal" warning sign was displayed?

Blocked
Reported
0
100K
200K
300K
2024 H1
2024 H2
2025 H1
2025 H2
How was the data calculated? (i): Number of unique accounts with a history of messaging suspension or full-service restrictions during the relevant period

How many accounts were blocked or reported because a "Fake Signal" warning sign was displayed?

Blocked
Reported
0
10K
20K
30K
40K
50K
2024 H1
2024 H2
2025 H1
2025 H2
How was the data calculated? (i): Number of unique accounts blocked or reported after the "Fake Signal" was displayed during the relevant period