VYPR
researchPublished Jul 23, 2026· 1 source

Massive Tech Support Scam Campaign Targets Over 13 Million Japanese Users via Email

A sophisticated tech support scam campaign has sent over 13 million emails to Japanese users, employing workplace-themed lures that suggest an expansion towards enterprise targets.

A large-scale tech support scam campaign, observed over a 165-day period from mid-December 2025 through May 2026, has delivered more than 13 million emails, primarily targeting Japanese users. This campaign represents a significant shift from previous malvertising-driven tactics to a sustained email distribution model, employing a complex infrastructure to lure victims into fraudulent support calls.

The operation utilized spoofed sender addresses, a rapidly rotating network of over 33,000 disposable fake alert websites, and globally distributed delivery infrastructure. Legitimate hosting and remote access services were also abused to facilitate the scam. The sheer volume of emails, averaging around 81,000 per day, with a peak in February 2026 reaching approximately 160,000 daily, underscores the campaign's extensive reach.

Analysis revealed that 94% of the observed emails were directed at addresses within Japan's .jp top-level domain. The emails were sent or relayed from approximately 240,000 IP addresses worldwide, indicating a robust and geographically dispersed operational backbone. The landing sites, designed to look like urgent security alerts, were created and discarded rapidly to evade detection and takedown efforts.

Notably, the campaign has shown an evolving sophistication, with emails increasingly incorporating workplace-themed lures. These messages often reference internal corporate communications such as performance reviews, salary revisions, and security audits. This strategic shift suggests a potential move to target individuals within organizations, aiming to compromise corporate accounts and extract larger financial gains.

Tech support scams typically involve displaying fake security warnings to trick users into contacting bogus technical support lines. Once contact is made, threat actors pose as support staff, remotely access the victim's device, and then demand payment for fraudulent services or repairs. In Japan, these scams have been a persistent threat, with previous Trend Micro research indicating a high encounter rate among users.

Official data from Japan's National Police Agency highlights the financial impact of these scams, categorized as "support-pretext" billing fraud. While reported cases saw a decrease in 2025, the average loss per case significantly increased, doubling from the previous year. This indicates that while fewer individuals may be falling victim, those who do are losing substantially more money.

To mitigate these risks, users are advised to exercise caution with unsolicited messages, avoid clicking on suspicious links or calling provided phone numbers, and to close fake warning screens without interaction. Verifying any security alerts through official company channels is crucial. Organizations should bolster email security measures, implement robust email authentication and filtering, restrict unauthorized remote access software, and conduct regular employee training on recognizing and reporting social engineering tactics.

Synthesized by Vypr AI