The IRD wants you to claim your refund.
A coordinated campaign impersonating Kakao is targeting New Zealand organisations with fraudulent refund notifications via high-reputation infrastructure.
A high-fidelity phishing campaign has been detected impersonating Kakao, specifically leveraging 'New Refund Status' lures. The messages originate from high-reputation marketing infrastructure, allowing them to bypass traditional signature-based security filters. Technical analysis indicates that the campaign passes all standard authentication checks, including SPF, DKIM, and DMARC, signifying a deliberate attempt to use legitimate mail-delivery nodes for unauthorized credential harvesting.
The email body typically employs accurate Kakao branding to create a sense of financial urgency or curiosity. Users are prompted to interact with links that lead to credential harvesting portals. This technique, often referred to as 'Living off the Land' (LotL), relies on the trusted reputation of the underlying delivery platform to ensure high deliverability rates across organisational perimeters.
Organisations are advised to treat any unsolicited financial or refund-related notifications with clinical skepticism, especially those originating from platforms like Kakao that may be outside standard business workflows. Legitimate status updates should be verified strictly through official mobile applications or independent navigation to the official service portal.
To mitigate this risk, organisations should enforce strict 'First Contact' safety tips and encourage users to utilize the 'Report Phishing' mechanism. Refining tenant-level reputation filtering based on these reports remains the most effective defense against campaigns that utilize trusted global infrastructure to deliver malicious content.

Practical steps you or your IT provider can take to reduce the risk from this kind of threat.
- Do not interact with links in unsolicited refund notifications.
- Verify account status strictly via official mobile applications or the official Kakao portal.
- Report suspicious external messages to the organisational security team.
- Apply tenant-wide blocking for identified malicious sender domains.
See what a genuine Inland Revenue (IRD) message looks like, the real sender domain, the real link destination, and where to report a fake.


