Hong Kong's national computer emergency response team logged 8,358 security incident reports in the first six months of 2026, a figure almost identical to the 8,142 it handled over the same stretch of 2025. The headline number barely moved. What sits underneath it did, according to HKCERT's mid-year review, published on 31 August.
Phishing made up 63% of everything reported, at 5,305 cases. Within that, social media and instant messaging platforms drew 46% of the cases, well ahead of banking, finance and electronic payment services on 17% and cryptocurrency platforms on 15%. Criminals still want money. They are increasingly going through the chat window to get it rather than the bank login page.
The volume held steady, the target moved
Botnets were the second largest reported category at 1,377 cases, or 16%, followed by a catch-all "Others" bucket at 921 cases and malware at 713. HKCERT's per-platform count inside the phishing figures is stark: WhatsApp was impersonated in 1,435 reported cases, Telegram in 557, TikTok in 315 and Meta in 115. WhatsApp alone drew roughly three times as many reports as the platform behind it. E-commerce sites accounted for 11% of phishing cases and technology companies 6%.
A locked account you never locked
The WhatsApp lure HKCERT describes does not steal a password, because it does not need one. A message tells the target their account has been locked over a security risk and offers a link to unlock it. The link opens a fake "WhatsApp Security Centre" page that asks for a phone number, then walks the victim through opening WhatsApp, going to Settings and then Linked devices, and either scanning a QR code shown on the page or choosing "Link with phone number" and entering a code the site supplies. That attaches the attacker's device to the victim's account, and the attacker reads the conversations from then on. IntelFusions covered the same linked devices abuse in August, dressed up as a request to vote in a competition. Same mechanism, different pretext.
Water bills are the new tax notice
HKCERT also tracked a run of phishing that dresses itself as government. Fake Inland Revenue Department pages return every tax season. In 2026 the growth was in fake Water Supplies Department bills, where reported cases more than doubled between February and April. The messages lead with subject lines such as "Water Account Information Update Notice", hide the destination behind shortened links or friendly text like "WSD Service Platform", and land on payment pages asking for phone numbers and card details. The domains lean on near-miss strings including wsdbg, wsdio, wsdde and wsdazx. HKCERT says it has seen sites impersonating iAM Smart and Hongkong Post in the same vein since 2024. Hong Kong carries a High targeting level in our country profile.
Six of the eight public alerts HKCERT issued in the period concerned phishing, including one in March on ClickFix, the trick of persuading a victim to paste an attacker's command into the Windows Run box or the macOS Terminal themselves. IntelFusions has tracked that technique spreading through fake download pages. The remaining two alerts covered the Mirai botnet hitting end of life D-Link routers, and the FortiBleed credential exposure that HKCERT warned could reach Hong Kong organisations among the more than 70,000 Fortinet devices suspected to be affected.
Review linked devices and enable two step verification
- Treat any message claiming your messaging account is locked as hostile, and never unlock an account through a link in it.
- Never scan a QR code from a web page in the Linked devices screen, and never type a code a website gives you into "Link with phone number".
- Open your Linked devices list now and remove anything you do not recognise.
- Turn on two step verification on WhatsApp and Telegram.
- Check bills and tax notices in the department's own app or website, never through the link in the message.
The flat headline is the trap here. A national CERT reporting roughly the same volume two years running looks like a plateau, but the composition says where the next year of losses comes from: the account people carry in their pocket, taken over without a single stolen password.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.