지금왜@whynow

지금 뜨는 이유

Translated from Korean

Voice Phishing: Why is it so hard to get my money back? The dilemma of low recovery rates in the non-banking sector vs. real-time AI security

"Voice phishing," a term so familiar that we've become desensitized to it, captured the public's attention once again today. This came after audit data revealed that the recovery rate for fraud cases in the non-banking sector—such as savings banks or mutual finance companies—is less than 25%, while a major corporation simultaneously announced a new security service using real-time AI to block such scams. However, as it became known that the service plans to collect original audio recordings of users' private calls to detect financial fraud, concerns over privacy violations hidden behind technological convenience have sparked a new debate.

The reality of the non-banking sector: 3 out of 4 voice phishing victims never get their money back

If you receive a voice phishing call and frantically send money, can you actually recover your hard-earned funds? Sadly, the answer depends entirely on which financial institution you use. If you sent the money through a non-banking account, such as those at savings banks, mutual finance cooperatives, post offices, or securities firms, the chance of recovery is extremely slim.

According to data submitted by the Financial Supervisory Service to National Assembly member Kang Joon-hyun, the voice phishing recovery rate for non-banking financial institutions in the first half of 2026 was a mere 22.6%. Of the 23 billion KRW in total damages suffered by victims, only 5.2 billion KRW was recovered. Essentially, 3 out of 4 victims watched their money vanish. This is a poor performance, lagging 12 percentage points behind the 34.6% recovery rate of commercial banks during the same period.

The reason why non-banking wallets are such easy targets for criminals is clear: they have been significantly slower than commercial banks to adopt fraud detection systems (FDS) that monitor and block suspicious transactions in real time. While commercial banks have woven tight defense nets using AI and advanced monitoring techniques, the preventive measures in the non-banking sector have lagged behind.

The demographic characteristics of non-banking users also play a significant role. With a high proportion of elderly customers who are relatively less comfortable with smartphone banking and slower to react to scam calls, banks often miss the "golden time" to freeze transactions before criminals can distribute and withdraw funds from other accounts. Ultimately, the combination of systemic gaps and delayed responses has left the non-banking sector as a major blind spot for phishing victim relief.

Blocking transfers via real-time call monitoring: The experiment by ixio and Woori Bank

If getting money back after it's stolen is nearly impossible, the most certain preventive measure is to block the path of the transfer before the money leaves. This is where AI enters as a potential savior. The "ixio Voice Phishing Financial Shelter Service," launched through a partnership between LG Uplus and Woori Bank, focuses on this real-time blocking mechanism.

The operation is both intuitive and sophisticated. Once a user starts a call, ixio, an on-device AI assistant operating within the smartphone, analyzes the caller's voice and the conversation in real time. It detects voice patterns to determine if the caller is a fraudster or using sophisticated deepfake audio, and immediately flags keywords associated with financial scams.

As soon as signs of fraud are detected, ixio sends an immediate warning signal to Woori Bank's Fraud Detection System (FDS). Upon receiving the signal, the bank's system begins monitoring the customer's transfer transactions in real time, cutting off the path for funds to leave by temporarily freezing the transfer just before the damage occurs. Even if the victim hits the transfer button without realizing it's a scam, the system steps in to physically lock the money ahead of time.

Collecting my original call recordings? Privacy concerns reignited

However, this smart preventive technology became the center of a heated privacy controversy as soon as it was released. This follows the revelation that LG Uplus plans to collect the original audio recordings of actual voice calls, with user consent, to improve the accuracy of its AI model and for training purposes.

While the intention to block financial fraud at the source is noble, the fact that original recordings containing the most intimate details of a person's daily life are being stored on a major corporation's server for training purposes has sparked considerable resistance. Critics point out that even if collection is restricted to users who have given consent, it undermines the security benefits of on-device AI, which typically processes data only within the device.

Users are even more uneasy due to a specific precedent: in December 2025, ixio experienced an incident where call summaries and contact information for 36 subscribers were exposed to 101 other users due to a cache server configuration error. With the memory of broken trust and data leaks still fresh, the decision to send highly sensitive original call recordings to a server is difficult for the public to accept.

Balancing financial security and privacy: The task ahead for us

Real-time blocking through technology is undoubtedly a powerful weapon against criminal organizations exploiting the loose security nets of the non-banking sector. Preventing crime to safeguard assets is an urgent public interest that is more intuitive than any other value.

However, the good intention of preventing crime cannot be an excuse to collect the most private conversations and original voices of individuals. Since leaked biometric and voice data cannot be changed as easily as a password, it is natural that voices of anxiety are growing.

Ultimately, for technology to become a true shield, a process must first be implemented that provides users with transparent choices and rigorously proves the safety of data management. We must now watch to see what reasonable compromise tech companies and the Personal Information Protection Commission can find between the justification of financial safety and the right to personal data protection.

Related links

Loading comments…