For some context, you can't live in South Korea and not use Kakao, even your grandma has it.
So the fact that they have so many holes in their security is a cause for concern.
You grandma isn't going to know a fishy link when she sees one, especially with this exploit where domain looks legitimate.
A contributing factor is the hierarchical work culture in Korea. You boss gives you a deadline for a feature which is treated an non-negotiable so you cut corners to get it out. Your boss can't 'see' security vulnerabilities, but can see a UI. So you get told "good job" and then get given the next unachievable deadline.
This all amounts to an app full of security holes, and until Kakao stock drops because of it, they're not going to address it.