Gunjo · Business Intelligence for the AI Era
← Sticker Wall SCAM · DETAIL

Phishing Scam Impersonating Corporate Finance Departments for High-Temperature Allowance: Luring Victims to Input Card Details for Fraudulent Charges

The primary victims are employees of enterprises, government agencies, and public institutions, especially office workers accustomed to receiving administrative or financial notifications via WeChat Work, DingTalk, or internal work groups. These individuals are habituated to using links within groups for daily tasks like clocking in, applying for benefits, or checking salaries, leading to a natural trust in group messages. Furthermore, the scam is particularly lethal to new employees unfamiliar with official allowance distribution processes, as well as frontline outdoor laborers and blue-collar workers who know of the allowance policy by name but are unaware of the specific distribution channels. Psychologically, victims often suffer from 'payment anxiety' and 'FOMO' (fear of missing out): seeing labels like 'claim today only' or 'last few hours' leads them to skip verification steps and rush to enter card details. Additionally, long-term compliance with instructions from superiors in work groups creates path dependency and blind obedience, significantly lowering their vigilance compared to SMS messages from strangers.

SCAM

Key Fields

FIELD STAMPS
IndustryHealthcare / Elderly Care
RegionChina(中国大陆)
ScaleGray Market
ChannelOther
⚠️ This entry compiles scam tactics and public reporting; it is not investment or legal advice. Content is organized from public reporting and third-party complaint platforms; this site does not make any finding of illegality against the parties involved, who may contact us for correction if they object. If you encounter fraud, report it to the police immediately (110 / anti-fraud hotline 96110 in mainland China; local police overseas).

Who Gets Targeted

The primary victims are employees of enterprises, government agencies, and public institutions, especially office workers accustomed to receiving administrative or financial notifications via WeChat Work, DingTalk, or internal work groups. These individuals are habituated to using links within groups for daily tasks like clocking in, applying for benefits, or checking salaries, leading to a natural trust in group messages. Furthermore, the scam is particularly lethal to new employees unfamiliar with official allowance distribution processes, as well as frontline outdoor laborers and blue-collar workers who know of the allowance policy by name but are unaware of the specific distribution channels. Psychologically, victims often suffer from 'payment anxiety' and 'FOMO' (fear of missing out): seeing labels like 'claim today only' or 'last few hours' leads them to skip verification steps and rush to enter card details. Additionally, long-term compliance with instructions from superiors in work groups creates path dependency and blind obedience, significantly lowering their vigilance compared to SMS messages from strangers.

骗局怎么运作

  • Step 1: Cybercriminals obtain employee contact lists and internal group rosters of target companies through social engineering databases, credential stuffing, leaked corporate address books, or compromised internal accounts. They filter for industries most associated with high-temperature subsidies, such as construction, logistics, manufacturing, sanitation, and urban management, to determine targets for mass distribution.
  • Step 2: Scammers rapidly build high-fidelity phishing pages mimicking local Human Resources and Social Security bureaus. Templates typically include official government logos and formal notification headers with a 'claim' portal. Domains often use highly similar variants like 'human-resources-query.com' or 'high-temp-subsidy-register.com', featuring countdown pop-ups that demand same-day processing to create urgency.
  • Step 3: Using compromised internal accounts or impersonating finance, HR, or administrative executives, scammers send notifications to work groups via group announcements or '@all' mentions. The script typically reads: 'According to the Municipal Human Resources and Social Security Bureau, this month's high-temperature allowance is ready. Please click the link to register. Claims close at 5:00 PM today; failure to claim will be considered a waiver.'
  • Step 4: After clicking the link, employees are directed to the fake government page and prompted to enter full sensitive information, including name, ID number, bank card number, registered mobile number, and SMS verification code. Some versions even require secondary facial recognition. The page footer includes forged copyright information from the Social Security Development Center to enhance credibility.
  • Step 5: The criminal backend receives the submitted information in real-time. They immediately use the SMS verification code to sign up for quick payments or bind the bank card to a third-party payment platform. Within minutes, they complete purchases, transfers, or virtual item top-ups, draining the account balance before destroying the phishing domain and moving to the next set of corporate groups.
  • Step 6: To expand coverage, scammers rewrite the same links into SMS versions, falsely claiming to be from a corporate finance department or a municipal human resources bureau. These messages claim a subsidy of several hundred yuan is available for today only and are mass-distributed to phone number segments purchased from the black market, creating a dual-channel phishing matrix via corporate groups and SMS.

红旗信号(看到这些快跑)

  • 🚩 High-temperature allowances are legally distributed by employers along with salaries or deposited directly into payroll cards. There is no process for employees to apply online themselves. Any link requesting a bank card number and SMS verification code is a scam.
  • 🚩 Notifications featuring strong countdowns like 'claim today only' or 'void after deadline' are red flags. Official subsidies never set emergency windows of only a few hours. Such language is a typical tactic to induce urgency.
  • 🚩 The domain name does not match the official website of the local Human Resources and Social Security Bureau. Common signs include minor variations in the domain suffix or added words like 'query' or 'registration'. Accessing the site often reveals an unregistered domain.
  • 🚩 The sender's number or account is not the usual finance or HR contact but a new profile picture or nickname, or a regular finance account suddenly sending links outside of working hours, suggesting the account may have been compromised.
  • 🚩 The page requests a full set of sensitive information, including ID number, bank card number, registered mobile number, SMS verification code, or even facial recognition. Official government applications only require an ID number and social security account; there is never a scenario requiring an SMS verification code.
  • 🚩 Multiple replies in the group claiming to have received the money or thanking the sender are likely bot scripts or accomplices following up, not genuine colleague interactions. Privately message the person to verify if they actually received the funds.

真实案例

  • According to CNR on June 26, 2026, several office workers in Hangzhou received a link in their WeChat Work group disguised as a corporate administrative notice titled 'Corporate High-Temperature Allowance Registration'. After clicking and entering their bank card numbers and SMS codes, their payroll account balances were drained. Police issued an urgent warning that this is a typical phishing attack.
  • A woman in Ningbo reported in public media that she saw a link in her company group posted by a colleague, labeled as a Ministry of Human Resources and Social Security allowance claim. Within minutes of entering her information, over 3,500 yuan was withdrawn from her bank card. The case is currently under investigation by public security authorities.
  • According to Macao's 'Cheng Pou' (All About Macau), a man in Zhejiang clicked a high-temperature allowance link sent by a colleague in a work group, resulting in about 1,800 yuan being stolen from his bank card. He later discovered the colleague's account had been compromised without their knowledge.
  • In July 2026, the Tian'an Police Station of the Futian Branch of the Shenzhen Public Security Bureau reported a phishing scam disguised as employee benefits: an employee was added to a fake 'colleague group' and scanned a QR code labeled '2026 Summer High-Temperature Allowance Application Channel for Employees'. After entering their bank card payment password and SMS verification code, they suffered a total loss of over 1,700 yuan. (Source: https://m.gmw.cn/2026-07/05/content_1304520886.htm)
  • In July 2025, the Kunming Public Security Bureau Anti-Fraud Center reported that a citizen saw a 'Salary Subsidy' application link in a work group, allegedly posted by the HR department. After following the process, the subsidy was never received, and the victim lost 5,000 yuan. (Source: https://m.gmw.cn/2025-07/04/content_1304074839.htm)

Official Stance

  • Beijing police issued an urgent warning on June 15, 2026, stating that colleagues asking you to claim high-temperature allowances in work groups is a 'strike while the iron is hot' scam. No organization requires personal online applications for these allowances; do not click on any subsidy links in groups or SMS messages.
  • The Tianjin Anti-Fraud Center issued a warning on July 20, 2026, explicitly stating that all online applications for high-temperature allowances are scams. Official distribution is handled by employers via payroll to bank cards; there is no self-service channel on government platforms.
  • Wenzhou Net's publicity channel issued a warning article on August 4, 2026, advising people never to click on high-temperature allowance links. They reported that victims have already been scammed and emphasized that any subsidy page requesting a verification code is a phishing trap.

How to Protect Yourself

  • ✅ Upon receiving any link for high-temperature allowances, subsidies, or benefits, immediately verify with your company's finance or HR department in person or by phone to confirm if such a program exists and what the official distribution channel is. Do not click links in groups directly.
  • ✅ Carefully check the domain name in the browser address bar. Official Human Resources and Social Security websites have specific government domain suffixes. If you see non-registered domains spliced with words like 'query', 'registration', or 'application', close the page immediately.
  • ✅ Any subsidy application page requesting a bank card number, registered mobile number, or SMS verification code should be treated as a phishing page. Immediately take a screenshot as evidence and exit. Official government distribution will never ask for full bank card information.
  • ✅ If you have already clicked and entered information, immediately call your bank's customer service to report the card as lost or freeze the account. Simultaneously, report the incident to local public security authorities and call the 96110 national anti-fraud hotline to report the phishing domain, aiming to stop losses before fraudulent charges occur.
  • ✅ Enterprises should strengthen account security on internal instant messaging platforms, mandate two-factor authentication for all employees, require regular password changes, and implement administrator approval mechanisms for new group members and sudden announcement links to reduce the possibility of account hijacking and malicious link distribution at the source.