Chat app scams now outnumber bank scams in Hong Kong

Hong Kong's national computer emergency response team logged 8,358 security incident reports in the first six months of 2026, a figure almost identical to the 8,142 it handled over the same stretch of 2025. The headline number barely moved. What sits underneath it did, according to HKCERT's mid-year review, published on 31 August.

Phishing made up 63% of everything reported, at 5,305 cases. Within that, social media and instant messaging platforms drew 46% of the cases, well ahead of banking, finance and electronic payment services on 17% and cryptocurrency platforms on 15%. Criminals still want money. They are increasingly going through the chat window to get it rather than the bank login page.

The volume held steady, the target moved

Botnets were the second largest reported category at 1,377 cases, or 16%, followed by a catch-all "Others" bucket at 921 cases and malware at 713. HKCERT's per-platform count inside the phishing figures is stark: WhatsApp was impersonated in 1,435 reported cases, Telegram in 557, TikTok in 315 and Meta in 115. WhatsApp alone drew roughly three times as many reports as the platform behind it. E-commerce sites accounted for 11% of phishing cases and technology companies 6%.

A locked account you never locked

The WhatsApp lure HKCERT describes does not steal a password, because it does not need one. A message tells the target their account has been locked over a security risk and offers a link to unlock it. The link opens a fake "WhatsApp Security Centre" page that asks for a phone number, then walks the victim through opening WhatsApp, going to Settings and then Linked devices, and either scanning a QR code shown on the page or choosing "Link with phone number" and entering a code the site supplies. That attaches the attacker's device to the victim's account, and the attacker reads the conversations from then on. IntelFusions covered the same linked devices abuse in August, dressed up as a request to vote in a competition. Same mechanism, different pretext.

Water bills are the new tax notice

HKCERT also tracked a run of phishing that dresses itself as government. Fake Inland Revenue Department pages return every tax season. In 2026 the growth was in fake Water Supplies Department bills, where reported cases more than doubled between February and April. The messages lead with subject lines such as "Water Account Information Update Notice", hide the destination behind shortened links or friendly text like "WSD Service Platform", and land on payment pages asking for phone numbers and card details. The domains lean on near-miss strings including wsdbg, wsdio, wsdde and wsdazx. HKCERT says it has seen sites impersonating iAM Smart and Hongkong Post in the same vein since 2024. Hong Kong carries a High targeting level in our country profile.

Six of the eight public alerts HKCERT issued in the period concerned phishing, including one in March on ClickFix, the trick of persuading a victim to paste an attacker's command into the Windows Run box or the macOS Terminal themselves. IntelFusions has tracked that technique spreading through fake download pages. The remaining two alerts covered the Mirai botnet hitting end of life D-Link routers, and the FortiBleed credential exposure that HKCERT warned could reach Hong Kong organisations among the more than 70,000 Fortinet devices suspected to be affected.

Review linked devices and enable two step verification

The flat headline is the trap here. A national CERT reporting roughly the same volume two years running looks like a plateau, but the composition says where the next year of losses comes from: the account people carry in their pocket, taken over without a single stolen password.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions