HK$14.7 million lost in Hong Kong card fraud wave

Published

Hundreds of people in Hong Kong have found charges on their credit cards for electronics they say they never bought. Hong Kong's computer emergency response team, HKCERT, issued a public alert on 14 September after what it describes as a large number of reports from residents whose cards were allegedly used in unauthorised online purchases of electronic products.

Citing media reporting of police figures, HKCERT says the Police received more than 700 related reports within a short period, involving approximately HK$14.7 million in losses. Some of those affected said they had not carried out the transactions at all. Others reported that no additional payment authentication notifications had been received, meaning the charges cleared without the confirmation step a cardholder would normally expect to see.

What makes this notable is what HKCERT cannot yet say. The root cause remains under investigation by the relevant organisations, and the alert states plainly that there is currently no evidence suggesting that any particular bank, payment platform or merchant system has been compromised. A lot of money has moved and nobody has yet shown where the card data came from.

Four ways a card number gets out

Rather than point at a breach, HKCERT sets out the routes by which criminals commonly obtain payment details, and the list is worth reading as a checklist because any of them could sit behind a wave like this one.

None of that is new, and that is rather the point. Hong Kong's fraud picture has been shifting for a while: chat app scams overtook bank impersonation there in the first half of 2026, and consumer facing fraud continues to shape the territory's cyber risk profile.

Freeze the card, then call the issuer

HKCERT's advice to the public is ordinary and effective. Review card statements and transaction records regularly, and switch on real time transaction alerts so an unexpected charge surfaces in minutes rather than at the end of the month. Never submit payment information through a text message, an email or a social media platform, and do not click links in messages without verifying who sent them. Avoid entering payment details over public Wi-Fi, and avoid storing card numbers with unfamiliar merchants. If a suspicious transaction appears, freeze or suspend the card immediately, contact the card issuer, keep the records and notifications, and report the incident to the Police.

For businesses and service providers, HKCERT asks for stronger monitoring and detection of suspicious transaction activity, periodic review of payment system security controls, continued anti phishing and awareness training, documented procedures for responding to a data breach, and better customer authentication and verification. It warns that the commercial cost lands as chargeback disputes and lost customer confidence as well as fraud losses.

Organisations and members of the public in Hong Kong can report incidents through HKCERT's online reporting form or its 24 hour hotline on +852 8105 6060. The alert itself is published on HKCERT's site. Until the investigation reports, the honest position is the one HKCERT has taken: the pattern is consistent with payment data stolen somewhere upstream, and the place it was stolen from is still unknown.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions