A red “의심” (uisim, “suspicious”) banner flashed across my phone mid-call this summer, and I hadn’t touched a single setting to make it appear. That’s because Samsung, SK Telecom, KT, and LG U+ all started pushing free, AI-based voice-phishing detection hard in February 2026, after Korea’s science ministry publicly told people to turn it on.
The Alert I’d Never Seen Before

The number wasn’t blocked, wasn’t spam-tagged, nothing I’d seen before — just eleven digits and a Seoul area code that looked almost right. I picked up out of habit, heard a recorded voice claiming to represent a bank’s loan department, and by the time I’d registered that something felt off, the banner had already flipped from 의심 to “경고” (gyeonggo, “warning”) with red text sitting over the call screen for the rest of the 40-odd seconds I stayed on the line.
I hung up. Then I got curious.
In Korea, this particular flavor of phone fraud has its own name: voice phishing (“보이스피싱,” boiseu-pishing — a Konglish compound locals shorten to “보피” in casual speech). It’s been a national headache for over a decade, but what stopped me that day wasn’t the scam call itself — it was realizing my phone had been quietly running interference on it without me ever opting in.
What “AI Voice Phishing Detection” Actually Means On Your Phone

On February 12, 2026, Korea’s Ministry of Science and ICT publicly urged citizens to actually use the AI-based detection tools that were, by that point, already sitting on most people’s phones. The push covers four separate systems, and they don’t all work the same way.
Samsung’s is built into the stock Galaxy Phone app: it analyzes calls from unknown numbers on-device, meaning the audio itself never leaves your phone, and issues that same two-stage 의심-then-경고 escalation I saw. The three carriers each ship their own layer on top of that. LG U+’s app, ixi-O (익시오, iksi-o), includes an “Anti Deep Voice” feature that flags AI-synthesized or manipulated voices while a call is still happening, plus a voiceprint check against a database of convicted scammers’ actual voices. KT’s version runs through its caller-ID app WhoWho (후후, huhu) and combines real-time context analysis, speaker recognition, and deep-voice detection in one pass. SK Telecom folds a similar layer into its own AI call app, A Dot Call.
The distinction that matters most, in my opinion, is the on-device part. A lot of “AI security” marketing in Korea quietly means “we upload your data to get scored somewhere else.” This one doesn’t — Samsung’s alert is generated locally, which is presumably why the government felt comfortable telling tens of millions of people to just leave it on.
The Apps, Compared: Which One Actually Catches a Deepfake Voice
Once you go past what’s pre-installed, there are six apps Korean tech blogs keep coming back to when they compare voice-phishing defenses. I went through what each one is actually built to catch:
| App | Maker | How It Catches Things | Best For |
|---|---|---|---|
| A Dot Call (에이닷 전화) | SK Telecom | AI call-pattern analysis, auto-records and summarizes calls | Anyone who wants a call log and a warning in one place |
| ixi-O (익시오) | LG U+ | Real-time deepfake-voice flagging + voiceprint match against a convicted-scammer database | Parents’ or grandparents’ phones — this is the one with the safety net built in |
| WhoWho (후후) | KT | Real-time context analysis, speaker recognition, and deep-voice detection combined | A carrier-grade option if you don’t want to switch carriers |
| Citizen Kono (시티즌코난) | An independent mobile-security developer | Scans installed apps for malicious remote-control software | Anyone who already clicked a link or installed something they now regret |
| PhishingEyes (피싱아이즈) | Infinigru (private developer, same maker as Citizen Kono, runs a police/bank joint-response network) | Flags risky activity on a relative’s phone and alerts a registered guardian | Elderly relatives who won’t check their own phone |
| Whoscall (후스콜) | Gogolook | Spam-number database plus a link and screenshot safety check | A five-second gut-check before you pick up an unknown number |
None of these need each other to work, and most people I know end up running two: whatever their carrier already gives them, plus Whoscall as a habit for numbers that don’t look like scams so much as they look like nothing at all.
Your Bank Is Sharing AI Models, Not Your Data
The apps only cover the call itself. The bigger, quieter change happened on the banking side. Starting in July 2026, the Financial Security Institute (금융보안원, Geumyung Boan-won — the body that coordinates cybersecurity across Korea’s financial sector) and all three of Korea’s internet-only banks — Kakao Bank, K Bank, and Toss Bank — deployed a shared AI fraud-detection model built on federated learning.
Here’s what that actually means for your banking app, because “federated learning” is one of those phrases that sounds like it should require you to change something and doesn’t. Each bank keeps training its own model on its own transaction history — nothing about your account ever leaves that bank’s servers. What gets shared afterward is just the trained model’s weights, the math the model learned, not a single row of anyone’s real data. Your transfer screen, your login, your OTP — none of it looks different. What’s different is the fraud-scoring layer behind it now has the pattern-recognition benefit of three banks’ worth of scam attempts instead of one, and the Financial Security Institute reports it catches up to 205% more fraudulent transactions than any single bank’s model managed alone. A wider rollout to smaller financial firms through the institute’s ASAP platform is planned for the fourth quarter of 2026.
I’ve written before about what it’s actually like working in IT at a Korean financial company, and federated learning is exactly the kind of project that sounded like a whiteboard fantasy back when I first heard the term and only became a shipped, production thing this year. The tension it solves — wanting the accuracy of a bigger dataset without the compliance nightmare of ever moving anyone’s actual account data across a company boundary — is the whole reason banks that compete with each other for customers were willing to sit down and share anything at all.
Is Any of This Working? The 2026 Numbers So Far

According to National Police Agency figures reported in late August 2026, recorded voice-phishing cases fell 46% year-on-year between January and July — 7,940 cases versus 14,707 over the same stretch in 2025 — and reported losses fell 53%, from ₩776.6 billion down to ₩361.4 billion. Police credit part of the drop to the AI detection push and part to a separate crackdown that seized 9,199 illegal signal-relay devices, the hardware scam call centers use to make overseas numbers show up as local ones.
It didn’t feel like nothing. It also isn’t the whole story.
On the same day I sat down to write this — August 27, 2026 — researchers at Sungkyunkwan University, led by Professor Park Eun-il, announced an AI tool that can pinpoint the exact manipulated segment inside an otherwise genuine voice recording, down to about one second of audio. Two related papers were accepted at Interspeech 2026 in Sydney this September. That’s solving a different problem than a live-call banner — it’s built for investigators and courts trying to prove after the fact that a recording was doctored — but it’s the same trajectory: this isn’t a one-time government press release, it’s an active research area.
None of that erases what still happens to the people who get caught anyway. One Korea Development Institute estimate puts the average loss per voice-phishing victim in 2023 at roughly ₩17 million — about one-and-a-half times the prior year — and separate recovery tallies put refund rates somewhere in the 20% to 26% range, depending on which report you check. Detection is getting better. Getting your money back once it’s actually gone still isn’t.
What I Actually Installed — For Me, and For My In-Laws

My own phone didn’t need much. The Galaxy alert was already running when I went digging through settings — I don’t remember switching it on myself, and I’m fairly sure I didn’t — so I added Whoscall on top of it, mostly out of habit, for the numbers that aren’t scary so much as just unfamiliar.
My mother-in-law was the real project. She’s the same person who still freezes in front of a kiosk despite the 2026 accessibility law working exactly as it was designed to, so asking her to personally spot a synthetic voice was never realistic. She’s on LG U+, so I installed ixi-O, sat her down to record five sentences for the voiceprint check, and layered PhishingEyes on top so that if anything trips on her phone, an alert lands on mine too. She complained about reading five sentences out loud into a phone held by her son-in-law. I didn’t care.
That’s the actual point of a guardian alert — it doesn’t ask her to be the one who catches it.
If you only do one thing after reading this: turn on whichever carrier app matches your own phone today, because for most people that’s a five-minute free download, not a research project. But don’t let any of it change how you answer a call from someone claiming to be a bank, a prosecutor, or a courier and asking you to move money or read out a one-time code — the fastest way to lose to this scam is still just staying on the line, red banner or not.
