Fake KakaoPay / NaverPay payment-confirmation spoof — Korean e-wallet brand keywords (카카오페이 / 네이버페이) + payment-confirm / 결제확인 / 본인인증 narrative + off-brand href (not kakao.com / naver.com / pay.naver.com). KakaoPay processes ₩3T+ quarterly; ~50M South Korean users. Real Kakao/Naver send from @kakao.com / @naver.com which are on the BRAND_TRUST_MAP — sender guard removes them automatically. Source: Red-Team R8 multi-agent council C3 (KR payment-rail specialist).
kr-kakaopay-naverpay-payment-confirm-lure
What this tier means
High-confidence threat indicator — phishing, impersonation, BEC, or scam pattern. Strong contributor to the trash decision.
How Gorganizer detects this
Fake KakaoPay / NaverPay payment-confirmation spoof targeting South Korean e-wallet users. The phish narrative arrives as: "카카오페이 결제 확인이 필요합니다 — 아래 링크를 클릭하여 본인 인증을 완료하세요" (KakaoPay payment confirmation required — click below to complete identity verification), or "NaverPay 거래 알림: 의심스러운 결제가 감지되었습니다 — 즉시 확인하세요" (NaverPay transaction notice: suspicious payment detected — verify immediately). Both wallets serve ~50M users in South Korea; KakaoPay alone processes ₩3T+ quarterly. Detection: KakaoPay / NaverPay / 카카오페이 / 네이버페이 brand keyword AND 결제확인 / 결제승인 / 본인인증 / 계정확인 / payment confirmation narrative AND off-brand href (not kakao.com, kakaopay.com, pay.kakao.com, naver.com, pay.naver.com). Real Kakao / Naver send from @kakao.com / @naver.com — both are on the BRAND_TRUST_MAP so canonical senders are excluded by the sender guard automatically. Source: Red-Team R8 multi-agent council C3 (KR payment-rail specialist).
False-positive guard
Every signal in Gorganizer feeds a multi-module score — never a sole verdict. This is a threat-tier signal — it adds a strong contribution to the trash score. The full pipeline still requires convergence across multiple modules + a margin over the safety floor before deletion happens, and Gmail's trash (30-day recovery) is always used — never permanent delete.
About the scoring engine
Gorganizer's scoring engine emits over 1,800 signals across six modules — headers, sender, subject, body, attachments, and structural metadata. Every email is scored by every module independently; the final verdict requires multiple modules to agree and the trash score to beat the safety floor by a margin.
Sacred safety guards — never delete starred emails, replies, calendar invites, receipts/invoices, or attachments — apply unconditionally regardless of any signal.
Ready to clean your inbox?
Gorganizer scans your Gmail with this signal and 1,800+ others, then cleans everything in one click. $4.99 one-time, no subscription.
Get started