Gunjo · Business Intelligence for the AI Era
← Sticker Wall SCAM · DETAIL

Fake Ministry of Human Resources and Social Security High-Temperature Allowance Phishing Scam: Exploiting Work Chat Groups to Distribute Fake Links and Steal Employees' Payroll Card Funds

The primary victims are rank-and-file employees of enterprises and public institutions, especially blue-collar workers with relatively weak anti-fraud awareness and young white-collar workers who have just entered the workforce. This group frequently pays attention to the distribution of high-temperature subsidies in summer, exhibiting high psychological sensitivity and a sense of urgency regarding official welfare and time-limited collection. Driven by natural trust in colleagues or financial identities within work chat groups, they click on links without thinking and fill in their payroll card numbers, ID numbers, and verification codes, ultimately leading to their payroll cards being fraudulently debited, and struggling to defend their rights afterward due to a lack of evidence-collection awareness.

SCAM

Key Fields

FIELD STAMPS
IndustryHealthcare / Elderly Care
RegionChina(中国大陆)
ScaleGray Market
ChannelOther
⚠️ This entry compiles scam tactics and public reporting; it is not investment or legal advice. Content is organized from public reporting and third-party complaint platforms; this site does not make any finding of illegality against the parties involved, who may contact us for correction if they object. If you encounter fraud, report it to the police immediately (110 / anti-fraud hotline 96110 in mainland China; local police overseas).

Who Gets Targeted

The primary victims are rank-and-file employees of enterprises and public institutions, especially blue-collar workers with relatively weak anti-fraud awareness and young white-collar workers who have just entered the workforce. This group frequently pays attention to the distribution of high-temperature subsidies in summer, exhibiting high psychological sensitivity and a sense of urgency regarding official welfare and time-limited collection. Driven by natural trust in colleagues or financial identities within work chat groups, they click on links without thinking and fill in their payroll card numbers, ID numbers, and verification codes, ultimately leading to their payroll cards being fraudulently debited, and struggling to defend their rights afterward due to a lack of evidence-collection awareness.

骗局怎么运作

  • Disguising identity to infiltrate group chats: Fraudsters first obtain QR codes for internal corporate communication groups such as WeChat and DingTalk through illegal channels, or control a group member's account via trojan programs. They then change the nickname and avatar to a finance or human resources department staff member, creating a false identity of an official administrator in the group and lowering the vigilance of other employees.
  • Precisely timing the release of phishing links: Typically choosing periods when high-temperature subsidy policies are centrally distributed (such as June to August), they send so-called 2026 high-temperature allowance application notification links in the group, accompanied by a script claiming that according to the notice from the Human Resources and Social Security Bureau, this year's high-temperature allowance application has begun, and colleagues are requested to click the link to fill in information before 18:00 today, treating overdue submissions as automatic forfeiture, using policy timeliness to exert pressure.
  • Forging official pages to steal information: When employees click the link, they are redirected to a phishing page that highly mimics the official website of the Ministry of Human Resources and Social Security or local social security bureaus, even featuring a forged national emblem or official logo. The page requests employees to fill in their name, ID number, bank card number, and reserved mobile phone number, claiming it is necessary to verify the account for fund disbursement, while actually transmitting the information directly to the fraudsters' backend server.
  • Intercepting verification codes to complete fraudulent debits: After acquiring sensitive information such as employee bank cards, fraudsters initiate quick payment or transfer requests in the backend, at which point the employees' phones receive a verification code SMS. The phishing page simultaneously prompts them to enter the verification code of the bound mobile phone to confirm their identity, inducing employees to actively submit the verification code. Fraudsters thereby instantly complete the fund theft or transfer out the remaining payroll card balance.
  • Destroying traces and inducing secondary scams: Once the funds arrive, fraudsters immediately withdraw the notification link from the group chat or directly exit the group chat and block the victims. Some syndicates also induce victims to download so-called compensation apps or pay unfreezing fees, further draining the victims' remaining funds until they discover their payroll cards have been wiped clean, completing the entire closed-loop cycle.

红旗信号(看到这些快跑)

  • 🚩 Discovering that a finance or HR representative who rarely speaks suddenly sends links related to subsidy applications in the group, demanding time-limited completion of personal and bank account information.
  • 🚩 The link domain name is not an official URL, typically consisting of a long string of irregular letters and numbers, or disguised as a highly similar domain differing by only one or two letters.
  • 🚩 The so-called high-temperature allowance application page requests extremely sensitive financial information such as bank card numbers, passwords, CVV codes, or mobile SMS verification codes; regular entities distributing allowances never require employees to apply themselves and provide such content.
  • 🚩 The message carries strong threatening or urging scripts, such as valid only today, no makeup for overdue submissions, or please click to process as soon as possible, manufacturing psychological panic and a sense of urgency.
  • 🚩 The phishing webpage has rough typesetting, potentially containing typos, blurry images, or customer service contact information as personal mobile phone numbers, which obviously do not comply with the regulatory characteristics of official government agency websites.

真实案例

  • In June 2026, according to CNR reports, multiple office workers in Hangzhou received high-temperature allowance collection links disguised as corporate notices in their company chat groups. After filling in their bank cards and verification codes as prompted, funds in their payroll cards were completely wiped out. Local police urgently intervened and issued a warning. (Source: [https://www.cnr.cn/mspd/sywzl/20260626/t20260626_527677291.shtml](https://www.cnr.cn/mspd/sywzl/20260626/t20260626_527677291.shtml))
  • In August 2026, a woman in Ningbo saw a high-temperature allowance application link sent by a colleague from the Ministry of Human Resources and Social Security in a work chat group. After clicking in and filling out information, over 3,500 yuan was instantly deducted from her payroll card. The case was subsequently registered and investigated by public security organs. (Source: [https://www.163.com/dy/article/L3L0QMT10514R9OJ.html](https://www.163.com/dy/article/L3L0QMT10514R9OJ.html))
  • According to Macao Daily reports, in 2026, a man in Zhejiang clicked on a high-temperature subsidy link sent by a colleague in a work chat group, suffering a fraudulent debit of 1,800 RMB. The modus operandi was completely identical to typical in-group phishing scams.
  • In August 2026, Mr. Gao, an employee of an enterprise in Jiaxing, Zhejiang, received a high-temperature allowance collection link sent by a colleague via Enterprise WeChat. Clicking the link and following the steps to fill in information such as his ID and bank card, as well as entering his payment password and verification code, he received three inexplicable deduction notices totaling about 1,800 yuan the very next second. Afterward, he discovered that his colleague's account had long been hacked by fraudsters to mass-send scam messages. Mr. Gao immediately reported it to the police, and the case was publicized by Zhejiang Public Security. (Source: [http://news.anhuinews.com/xwgn/202608/t20260804_9462788.html](http://news.anhuinews.com/xwgn/202608/t20260804_9462788.html))
  • In July 2026, Mr. Sun, a resident of Shushan District, Hefei, received a push notification and external link containing a high-temperature subsidy application notice. After entering his name, ID number, and bank card number and submitting the SMS verification code as prompted by the page, 670 yuan was transferred out of his bank card within minutes. Upon investigation, the link was found to be a phishing website forged by criminals, and the case was publicized by Feidong Public Security. (Source: [https://m.163.com/dy/article/L2GSLJUG0514JUFD.html](https://m.163.com/dy/article/L2GSLJUG0514JUFD.html))

Official Stance

  • On June 15, 2026, Beijing police urgently reminded citizens through media outlets such as Beiwang Online that no unit distributing high-temperature allowances requires individual applications, nor will they ask for bank card passwords or mobile verification codes. Do not click on unknown links in chat groups.
  • On July 20, 2026, the Tianjin Anti-Fraud Center issued an early warning, explicitly pointing out that all online links regarding online applications for high-temperature subsidies on the internet are scams, reminding citizens to remain vigilant and understand subsidy policies through regular channels.
  • On August 5, 2026, the news section of Qingdao Network Radio and Television Station, in conjunction with the police, issued a warning emphasizing that high-temperature allowances are distributed by employers along with wages, and official institutions will never request employees to self-register and verify through temporary links.

How to Protect Yourself

  • ✅ When receiving subsidy application notices in chat groups, be sure to verify with your unit's genuine finance or human resources department via phone or in person, and do not blindly trust instructions from a single account in the group.
  • ✅ Remember national regulations: high-temperature allowances are position allowances distributed by employers alongside wages during the summer. Official institutions and employers will never request employees to apply or register themselves by distributing external links.
  • ✅ On any unofficial website page, firmly refrain from entering bank card numbers, passwords, CVV codes, or SMS verification codes received on your mobile phone. Treat any request for verification codes as a scam.
  • ✅ If you find that you have clicked a suspicious link, disconnect your mobile network immediately, freeze the involved bank card, and report to the anti-fraud center by calling 110 or 96110, while saving chat history and webpage screenshots as evidence.