FORSMILE
JA
ネット安全2026/09/09

"15,622 Points" Emails Push a Malicious Android App: 8 September Alert

Japan's Council of Anti-Phishing published an urgent alert on 8 September 2026: emails are luring people into installing a malicious Android app, and the campaign was still running that morning. Never install an app from a link in an email. Here are the real subject lines and who to call if you already did.

Back to Blog

Good evening. This is Shemihaza, your sentinel. Tonight's subject is a campaign that was flagged only yesterday, on 8 September.

Here is the conclusion first: never install an app from a link in an email or an SMS. Install apps from the official site's own link or from your phone's app store. That single habit is enough to make tonight's scheme fail.

Japan's Council of Anti-Phishing published an urgent alert on 8 September 2026, titled "Phishing emails leading to the installation of a malicious app". The emails try to get Android users to install a malicious app, and the Council states that as of 11:30 that same morning the campaign was confirmed to be still sending. It warns that similar emails are likely to keep arriving.

Here are some of the subject lines the Council published, translated into English — the originals are in Japanese. If one of these lands in your inbox, do not open the link.

・Are you using an Android phone? Claim your 15,622 points right now
・[Expiring soon] Have you completed your 15,622 point claim? (Android only)
・No losers! Your personal lucky number [XXXX] has been issued
・Check your usage statement in the app
・Notice of your 3,000 yen discount coupon
・[Rakuten Bank] 25th anniversary cash giveaway

The Council says it has confirmed a wide variety of pretexts — app updates, notifications, point awards, prize draws, coupons and giveaways. It also confirms emails impersonating brands beyond the ones listed. So "my bank was not on the list, therefore this is genuine" is not a conclusion you can draw.

Five stages to a malicious app

The five stages of a malicious app install (based on the urgent alert published by Japan's Council of Anti-Phishing on 8 September 2026)
  • 1. The hook: an email or SMS says something like "claim your 15,622 points now" or "[Expiring soon] ... (Android only)". The pretexts vary widely — app updates, notifications, prize draws, coupons, giveaways.
  • 2. The look: the landing page is built to look genuine. The Council notes that phishing emails are often created by copying real ones.
  • 3. The push: this is the fork in the road. You are told to install from the link in the email, not from the app store. Legitimate apps do not arrive that way.
  • 4. The breach: once installed, your IDs, passwords and card details are the target.
  • 5. The response: who you should contact depends on what you typed in. That list is near the end of this article.

Half of the subject lines contained invisible characters

This part is what we checked ourselves.

Going through the subject lines the Council published character by character, 7 of the 14 listed contained characters that do not render on screen — zero-width spaces and similar invisible code points. In the subject "当選確認をお待ちしておりま□す" ("we are awaiting your prize confirmation") and in "誕生月ログインで特典G□ET" ("log in during your birthday month and get a perk"), for instance, a zero-width character sits at the □ position. There is no way to notice this by looking.

The point is this: "the Japanese reads oddly, so it must be fake" no longer works. The wording is natural, the company name is real, and the message itself is a copy of a real one. Rather than trying to spot the fake, fix one rule of behaviour: never install an app from a link in an email.

Why spotting it is so hard

The Council's alert says it plainly: "Phishing emails are often created by copying genuine emails, and outside mail services that support the 'genuine mail visibility' feature, telling them apart is extremely difficult."

"Genuine mail visibility" refers to a feature that shows an icon or mark on legitimate mail. The Council recommends using a mail app or service that has it, and getting into the habit of checking whether a message is genuine. Put the other way round: in an environment without that mechanism, relying on your eyes is a losing game.

There is a second point in the alert worth repeating. "The fact that phishing email reaches you means your email address has leaked onto the internet." And: "Leaked information is traded among criminals and cannot be erased."

If spam filtering is on and the flood continues, the Council suggests creating a new address on a mail service that offers the genuine-mail visibility feature and migrating to it.

What you can do today

  • Install apps only from the official site's own link or from your phone's app store. This is the Council's first instruction. Never from a link in an email or SMS
  • Do not open login or install prompts that specify "Android only" or "check it in the app". Targeting Android app installs specifically is the signature of this campaign
  • Check that your spam filter is switched on. Almost every mail service has one, and it matters most for people receiving a lot of this
  • Use a mail app or service with the "genuine mail visibility" feature. An icon on legitimate mail beats eyeballing every message
  • If the phishing flood does not stop, consider rebuilding your address. Receiving these emails at all means the address has leaked
  • If the message concerns a company you actually use, check through its official app or a site you bookmarked yourself — never through the route the sender provided
📦
Amazon で関連書籍・ツールを検索
セキュリティソフト スマホ Android
Amazonで探す →(アソシエイトリンク)

Three lines to forward to your family

  • If an email offers points or says "Android only", do not install anything from its link. Apps come from the app store, full stop.
  • Natural-sounding Japanese proves nothing. These mails are copies of real ones, so you cannot tell by looking.
  • If you installed it and typed something in: change the password immediately, call the card issuer for card details, call the bank for banking credentials. In Japan, 188 for consumer advice and #9110 to consult the police.

If you already installed it, or typed something in

Who you contact depends on what you entered. This is the guidance the Council of Anti-Phishing publishes.

  • You entered an ID and password: change the password immediately. If you use the same ID (email address) on other services, check that none of them uses an easily guessed password and change those as needed. Also review your login and usage history for anything unfamiliar, and contact the service's support desk if necessary
  • You entered credit card details: contact the card issuer's lost-and-stolen desk immediately to suspend the card and, if needed, have it reissued
  • You entered online banking credentials: contact your financial institution immediately
  • You have already suffered a loss: contact the cybercrime consultation desk of your prefectural police headquarters
  • The four items above are what the Council publishes as the response when information has been entered into a phishing site

A line worth drawing honestly. That Council guidance covers information entered into a phishing site. It does not set out how to recover a phone after a malicious app has been installed, and we will not invent a procedure and present it as safe. For removing the app and checking the state of the device, contact your handset maker's or mobile carrier's official support, or your prefectural police cybercrime consultation desk. Deal with the contacts above first, though: anything touching money and bank accounts is the more urgent call.

And the numbers for when you do not know where to start. These are Japanese lines and work inside Japan. Consumer hotline 188 connects you to the consumer affairs centre for your municipality or prefecture. Police consultation line #9110 is for when you are unsure whether what happened is a crime. Both can be called before anything bad has happened.

Tonight was not a lesson in spotting fakes. "Never install an app from a link in an email." That is the whole rule. However good the wording gets, holding that line makes the scheme fail. Take just that with you.

Tonight's spot-the-scam quiz

🛡Shemihaza's Quiz — Can you spot it?

An email arrives from a service you actually use: "[Expiring soon] Have you completed your point claim? (Android only)". The Japanese reads naturally and the logo looks right. What do you do?

Related articles