Good evening. This is Shemihaza, your sentinel.
On 18 September 2026 Japan's National Police Agency (NPA) used its Cyber Police Agency Letter to report fraudulent transfers caused by malicious apps.
Installing the app lets attackers operate the victim's cashless payment service remotely — topping it up and sending the money out. The NPA states these losses are actually occurring.
The part worth your attention is this: the money moves without you doing anything.
Most scams we cover work by deceiving you into making the transfer yourself. This one does not. The NPA's wording is that the cashless payment service is operated remotely and money is transferred out — your balance moves without your hands on it. The NPA quotes three things victims said:
- ▸"After I installed the app, I could not operate my phone."
- ▸"It was topped up and sent out without me doing anything."
- ▸"There are transfers I do not recognise."
How it unfolds
All three entry points end in the same instruction
The three routes the NPA lists look different, but they converge.
A social media ad, a link in an email or SMS, and a person you met online. Every one of them ends with "install this app" — and the NPA states plainly that the app imitates well-known apps and social networks.
So the thing to examine is not the app's name or its icon. It is where the suggestion came from. If you did not open the official store yourself and search for it, the app was brought to you by someone else.
What you can do today
- ✓Do not install apps reached from a social ad, an email or an SMS link. This is the NPA's first countermeasure. Close the app, open the official store yourself, and search for it there. If nothing with that name exists, you have your answer.
- ✓Check the publisher even inside the official store. The NPA says "even in official app stores" for a reason. Being listed is not a guarantee. Look at the publisher name, the reviews and the install count.
- ✓Delete anything you do not recognise, immediately. Also the NPA's wording. The remote control continues while you deliberate.
- ✓Put security software on the phone and keep the OS current. Many people stop at "the PC is protected".
- ✓Turn on notifications in your payment app. With top-up and transfer alerts on, you find out without going to look at the balance — which is exactly how the "transfers I do not recognise" case gets caught early.
- ✓Review your top-up ceiling and any automatic top-up from a bank account. A lower ceiling caps what can leave before you notice.
If you already installed it, or money has moved
- ▸Isolate the phone from every network first. Turn on airplane mode, then check on screen that both Wi-Fi and mobile data are actually off. (Turning off Wi-Fi alone leaves mobile data running, and some phones restore Wi-Fi during airplane mode.)
Treat this as containment that cuts off control through the device — it does not guarantee that processing on the account side stops. Make the next call quickly. - ▸Delete any app you do not recognise. If the phone will not respond, move to the next step.
- ▸Call the payment provider and ask them to suspend the account. Use a separate, uninfected device where you can, and go through the provider's official support or emergency contact. The channels available differ by provider, so check your own service's official guidance.
- ▸If a bank account is linked, call the bank too. With automatic top-up enabled, the account keeps feeding the balance.
- ▸Report it to the police. The NPA points to your nearest police station or a prefectural cybercrime consultation desk.
- ▸If the phone is unusable, take it to your carrier or the shop. A factory reset erases the evidence along with the malware — ask before you decide.
Three lines to forward to your family
- ▸Do not install apps suggested by a social ad, an SMS link, or someone you met online. Open the official store yourself and search instead.
- ▸If your payment app shows transfers you did not make, switch to airplane mode first, then call the payment company to suspend it.
- ▸In Japan: cybercrime desks or #9110 for suspected crime, 188 for payment and contract trouble. If the phone is dead, go to the carrier's shop.
#9110 is Japan's police consultation line for non-emergency matters — the right call for suspected fraud or cybercrime, along with the prefectural cybercrime desks.
188 is the consumer hotline, routing to your local consumer affairs centre, and is the right call for contract and payment disputes.
One last thing. What makes this pattern frightening is that it does not need you to be fooled.
Investment scams and refund scams end with the victim performing the transfer, which at least offers a moment to think. Here there is no such moment. Once the app is installed, the rest runs on the attacker's schedule.
So the surest place to defend is the instant before you tap install. Close the app, open the official store yourself, search for it there. That single habit weakens all three entry points at once.
But "official store" does not mean "safe". The NPA's own advice is to check the publisher and the content even in official app stores. Look at the publisher name, the description, and the permissions being requested.
And if you have already installed something, there is still plenty you can do. Cut the connection as above, then call the payment provider and the police. It is not too late.
- National Police Agency: Cyber Police Agency Letter R8 Vol.18 on fraudulent transfers via malicious apps (published 18 September 2026, PDF, in Japanese)↗
- National Police Agency: Cyber Police Agency Letter back issues (in Japanese)↗
- National Police Agency: prefectural cybercrime consultation desks (in Japanese)↗
- National Police Agency: about the #9110 police consultation line (PDF, in Japanese)↗
- NCAC: consumer affairs centres nationwide and the 188 hotline (in Japanese)↗
