Voice phishing simulations in South Korea
South Korea does have a balancing ground, so a voice phishing simulation here never turns on whether your staff agreed to it. It turns on two other things. Acquiring personal data by false or wrongful means is a crime carrying up to three years, which puts the script rather than the paperwork at the centre of the design. And above thirty workers the training plan needs a labour-management council to pass a resolution, not to give an opinion.
Phone numbers
Supplied by Callstrike
Local numbers in South Korea, after a one-time approval.
Running a simulation
Permitted, with a criminal line in the script
Acquiring data by false means carries three years, and binds your supplier too.
Consent
A ground exists, so this is evidence
The balancing ground is harder than Europe's and the regulator anchors it in the contract.
Getting a phone number in South Korea
One approval per country, completed in the console.
Provisioned by Callstrike after approval
Numbers here are not released from open inventory. Your workspace is cleared for this country once, and Callstrike then provisions a dedicated number against it for your simulations. Approval is a one-time, per-country step and usually takes 3 to 5 business days. We only ask for what the regulator requires.
Korean onboarding turns on one choice you make when you sign the carrier's own order form, and it is worth making deliberately because it decides which proof of authority you then have to produce. If the form carries your company's corporate seal, a corporation seal verification certificate has to come with it. If your chief executive signs it personally instead, their government-issued identity document is what goes in the same slot. One document either way, but the wrong pairing is the commonest reason a Korean filing comes back.
The rest of the table below is a business registration certificate, obtainable from the National Tax Service, doing double duty as proof of who you are, and proof that your address falls inside the locality covered by the number's own prefix, which will also take a utility bill, a tax notice, a rent receipt or a title deed. A post office box is not accepted. Alongside the uploads the console form asks you to type your business registration number, your website and the authorised representative's name and work email.
- 01Complete the regulatory clearance formYour administrator, in the Callstrike console. The form asks only for what the regulator requires.
- 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
- 03A dedicated number in South Korea is assigned to youCallstrike
- 04Build and launch the campaignYour team
| What you provide | Accepted evidence, any one of |
|---|---|
| Proof of local addressMust be within locality or region covered by the phone number's prefix; a PO Box is not acceptable. | Business registration certificate, Utility bill, Tax notice, Rent receipt, Title deed |
| Proof of authorityIf the SK Corporate Service Application Form is stamped with the corporate seal, a Corporation Seal Verification Certificate is required. If it is signed by the CEO, the CEO's Government ID must be provided instead. | Corporation seal verification certificate, CEO's government issued ID |
| Proof of business identityThe Business Registration Certificate (사업자등록증) can be obtained from the National Tax Service (NTS) in South Korea | Business registration certificate |
| SK corporate service application formA copy of the order form is located here. Please complete the form and upload it with your bundle application. Must show company's corporate seal otherwise, must show CEO signature if CEO is the applicant. | Completed carrier form |
These requirements are set by the carrier and can change. The form in the console is generated from their current rules, so treat it as authoritative and this table as a summary of what to have ready. Checked 2026-09-07.
Is it lawful to run a simulation in South Korea?
The position in short, before your counsel reads the detail below.
Yes, and the first thing to correct is an assumption people arrive with. Korea is routinely described as offering no balancing ground, and it does offer one: collection and use are permitted where necessary to achieve the controller's legitimate interests and those interests manifestly override the rights of the data subject, limited to what is substantially related to them and within a reasonable scope. That ground survived the 2023 amendment. It is textually harder than the European provision it resembles, because manifestly overriding is a higher bar than not overridden by, and the regulator then narrows it again in a binding notice to an interest arising from statute or from a contract with the person. For an employer that anchors the whole analysis in the employment contract.
The constraint that decides the design is criminal and has nothing to do with your ground. A person who processes personal data must not acquire it, or obtain agreement to its processing, by false or other wrongful means or methods, and breach carries imprisonment of up to three years or a fine of up to thirty million won. That provision is about the act of acquisition under a false identity, which is precisely what a pretext call is, and a separate article applies it to a processor, so it binds Callstrike directly rather than only through the contract. The line it draws is workable: a call that induces an employee to hand over personal data under a false identity is on the wrong side of it, and a call that measures whether they would have, without capturing anything, is not.
Recording is settled by the statutory definition here rather than by academic consensus, which is unusual in this region. Interception is defined as acquiring the content of a telecommunication without the consent of a party, and the companion limb bites on a conversation between other persons. Someone on the call is neither. What makes this worth an explicit architectural decision rather than a default is the sentence: not up to ten years but not less than one and not more than ten, joined with a suspension of qualifications for up to five, so there is no fine-only outcome on the face of the provision. A silent third leg bridged in for monitoring is the exact shape the prohibition is drafted against.
Two things then differ from Japan and should not be assumed across. Korea has a synthetic-voice disclosure duty in force since 22 January 2026: where an operator uses an AI system to produce output difficult to distinguish from the real thing, the output has to be notified or marked so the user can clearly recognise it was generated by one. An exemption for artificial intelligence used only for the operator's internal business purposes exists, but it lives in the Presidential Decree rather than in the Act, and no regulator decision or guidance applies it to a security test, so treat it as available and untested. And on caller identity the practical answer arrives before the legal one: carriers must block a call whose own user has arbitrarily altered the calling number, and calls from abroad presenting a number on the public-institution and financial list are blocked without delay.
What your company needs to do
8 items, in the order you will need them.
- Settle whether the programme is an unfavourable change to the rules of employmentSouth Korea-specificThis is the Korean question and it cannot be deferred, because it decides what you have to obtain. Making or changing rules of employment normally requires you to hear the opinion of the majority union or of a majority of the workers; where the change is unfavourable to them, the proviso requires their agreement instead. No Korean source we found answers which side a simulation programme falls on, and breach of the procedure article is criminally penalised, so this is the item to take to Korean counsel before a campaign rather than after one.
- File the rules of employment with the opinion or the agreement attachedSouth Korea-specificAt ten or more workers the rules go to the Minister of Employment and Labor, and the same applies to a change. The written opinion is attached to the filing, so the paperwork is the proof. The two limbs a programme most plausibly sits in are commendation and sanctions, and the catch-all for other matters applicable to all workers of the workplace.
- At thirty workers, minute a council resolution rather than a discussionSouth Korea-specificA labour-management council is mandatory at that size and meets quarterly. Most matters go to it for consultation, including recruitment, placement, education and training, and the installation of worker-surveillance equipment by name. But the basic plan for workers' education, training and capability development needs a resolution: a majority of each side present and two-thirds of those present in favour. Failing to implement a resolution without justifiable cause carries up to ten million won.
- Anchor the balancing ground in the employment contractThe regulator's binding guideline restates the ground as an interest arising from statute or from a contract with the person, so a free-floating assertion that security is in the company's interest is weaker here than reading the Act alone would suggest. Write the assessment against the contract, and do not import a European one.
- Design so that nothing an employee says is actually harvestedThe three-year offence is built around acquisition, so the exercise has to measure whether someone would have disclosed rather than capture what they disclosed. This is a configuration decision taken before the campaign is built, not a caveat added to a report afterwards.
- Publish who your processor is, and keep the arrangement documentedSouth Korea-specificRunning the exercise through an outside supplier is an entrustment. The arrangement has to be documented, you have to publish who the processor is so that data subjects can check at any time, and you have to educate and supervise them. The publication is the part companies forget, because it is a standing disclosure rather than a contract clause.
- Decide how you meet the synthetic-voice dutySouth Korea-specificThe duty is in force and the internal-business-use exit is in the Decree and untested. Decide deliberately whether the campaign relies on that item or whether the voice is marked, and record which. Note the enforcement shape while you are there: the administrative fine attaches to the advance-notification duty, while the marking and synthetic-output duties are enforced through an investigation and a corrective order, with the fine attaching to ignoring the order.
- Present a Korean number your organisation holds a right of use inThe offence aimed at callers is scoped to deceiving for gain or inflicting harm, so an authorised exercise is outside it, but the second limb catches anyone supplying the number-alteration capability for profit and the ministry's list of justifiable causes is a closed six that covers no private test. In practice the call fails at the network before any of that is argued.
The controls that do the work
How Callstrike is configured, and which provision in South Korea each choice answers.
Auto-hangup before disclosure
The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.
This answers the sharpest provision on the page, and in Korea that provision is criminal. Acquiring personal data, or agreement to its processing, by false or wrongful means carries up to three years or thirty million won, and a separate article applies it to a processor so it reaches your supplier on its own terms. The offence is drafted around the acquisition rather than around the deception, so the call ending the instant an employee begins to give up a credential means the thing the statute punishes never happens. That is a stronger position than arguing about purpose after the event, and it is also the design the regulator's own line between measuring and capturing points to.
In-call debrief and follow-up
A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.
Worker education and training is a matter the labour-management council consults on, and the basic plan for it is the one matter that needs a resolution carried by two-thirds of those present. A second voice that breaks character as the call ends, with vishing training in writing the same day, is what turns the exercise from surveillance the council is being asked to tolerate into a training measure it is being asked to adopt, which is a materially easier vote to win and a materially easier minute to write.
Consent Management
Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.
Korea has a ground, so agreement is not what carries the processing, and the regulator points employers at statute and the contract instead. What this produces are the two dated artefacts the Korean file is actually assessed on: the record of the opinion or the agreement gathered before the rules of employment were filed, which is the step that is criminally penalised if it is skipped, and the standing publication of who your processor is, kept where data subjects can check it at any time rather than produced when somebody asks.
SCORM module
An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.
Korea's synthetic-voice duty is the reason this route reads differently here than anywhere else in the region. Callstrike's vishing simulator delivers the same deepfake voice through a web call the learner opens themselves after working through the module, and a module that says on its own face that the voice is generated needs no reliance on the untested internal-business-use item in the Decree. It also has no Korean calling number to be blocked and no altered number for a carrier to detect. The criminal acquisition rule is not a telephony rule and still governs whatever either route collects.
Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.