Fake TikTok Apps Hijack Smartphones in Japan, Fueling Surge in Unauthorized PayPay Transfers

September 21, 2026

Summary

Japan is seeing a sharp increase in unauthorized PayPay transfers linked to fake TikTok-style applications. The malicious apps, including ones advertised as an adult version of TikTok, can infect smartphones and allow criminals to control them remotely. Attackers may also make calls, send messages, or activate the camera without permission. Fraudulent Rakuten apps are also being used to steal login IDs and passwords through fake promotions. Users should check their PayPay and other account histories for unfamiliar activity. Delete suspicious apps and download software only from official app stores. PayPay says eligible victims may receive compensation of up to the full loss, depending on the case. Read the full article for practical steps to protect your smartphone and accounts.

Fraudulent apps exploit interest in an alleged adult version of TikTok

Smartphone users in Japan are being warned about a growing cybercrime campaign in which malicious applications posing as TikTok can take control of devices and enable unauthorized money transfers through PayPay, one of the country’s most widely used cashless payment services.

PayPay says reports from customers claiming that money was sent without their knowledge increased sharply from August. Investigations have confirmed cases in which victims installed applications carrying names such as “TikTok 18+,” believing they could access adult-oriented video content. The applications were not official TikTok products. Instead, they infected smartphones with malware and allowed criminals to control the devices remotely.

Once installed, the malicious software can reportedly interfere with smartphone operations and facilitate transfers to third parties through the victim’s PayPay account. PayPay is urging customers to check their transaction histories carefully and look for unfamiliar applications installed on their devices.

How the scam reaches smartphone users

According to warnings from PayPay and cybersecurity experts, victims are often directed to fraudulent app stores through social media advertisements, emails, or other online messages. The links may be designed to look legitimate and can use attention-grabbing offers or adult-content claims to persuade users to download software outside official app marketplaces.

Cybersecurity company Trend Micro, based in Tokyo, says it has identified multiple malicious applications impersonating an adult version of TikTok. The company warns that the risks go beyond financial losses. After installation, attackers may be able to remotely operate many functions on a smartphone, including placing calls, sending messages or emails to contacts, and activating the camera.

Masaya Takahashi, a senior specialist at Trend Micro, advised users to delete suspicious applications immediately and to obtain apps only through official app stores. However, experts also stress that users should carefully check the developer name, reviews, download numbers, permissions, and the app’s official website, since fake applications can sometimes appear convincing.

Fake Rakuten apps also target account credentials

A separate campaign involving fraudulent applications impersonating Rakuten has also been detected in Japan. According to Rakuten and the Anti-Phishing Council, victims may receive emails or text messages claiming that they have won a prize, earned Rakuten Points, or received a coupon. The messages then direct them to a fake app store, where they are encouraged to install an application resembling an official Rakuten Points app.

Trend Micro’s analysis found that the fraudulent Rakuten application asks users to enter their Rakuten ID and password during login. Those credentials can then be stolen and potentially reused by criminals to access accounts or conduct further fraud.

What users should do

People who suspect they have installed a malicious application should avoid entering additional passwords or payment information, disconnect the device from the internet if necessary, and seek assistance from their mobile carrier, the relevant payment provider, or a cybersecurity professional. They should also review payment and account activity, change passwords from a trusted device, enable multi-factor authentication where available, and report suspected fraud to the police or appropriate consumer-protection authorities.

PayPay says eligible victims may receive compensation of up to the full amount of their loss, depending on the circumstances and the details of the case. Users should contact the company promptly and preserve evidence, including suspicious messages, application names, transaction records, and website addresses. The incident highlights the importance of Japan’s shift toward cashless payments while underscoring a basic digital-safety rule: attractive offers from unofficial sources can carry serious risks.