Sites impersonating a "visa, entry permit or booking agent" look identical to the real thing. You will not catch them by looking at the page. Before you hand over a passport number and card details, spend ten seconds on the URL.
Three checks before paying or entering a passport number
- Check the very end of the domain — is it
.go.kror.gov - Stop if one letter looks off (typosquatting)
- Look the address up with Google Safe Browsing
How the trick works
It comes down to one thing. The real domain is the part at the end.
- Prefixing —
k-eta.go.kr.some-site.comissome-site.com. Everything before it is decoration - One-letter swaps — k-eta to k-etaa, gov to g0v, booking to bo0king with a zero
- Hyphens and subdomains piled up to look official, like
official-keta-apply.com - Shortened links from an unknown source — you cannot see the end at all
There are only two official addresses
- K-ETA — k-eta.go.kr
- Immigration — hikorea.go.kr
Do not tap links that arrive by text or email. Type these two in yourself. That single habit defeats every trick above, because none of them survive you typing the address.
Do this now
- Bookmark both addresses
- If you have already entered card details somewhere, call your card issuer to freeze it
Worked examples and how to report a site are on the WeBring blog.