第一财经

Credit cards in Hong Kong have been collectively stolen and used fraudulently!

原文:香港出现信用卡被集体盗刷!

Hong Kong Citizens' Credit Cards Used Illegally to Buy iPhones: A Warning About Payment Security

Summary of Key Points

Recently, a significant incident of collective credit card fraud occurred in Hong Kong. During the pre-sale period for the iPhone 18 Pro (note: this may be a typo or refer to a future model based on the context of the news), many Hong Kong citizens received text messages from their banks indicating that their credit cards had been used for "card-not-present" purchases on the Apple official website without them making any orders. As of September 14, more than 1,200 people had reported the incidents, involving a total loss of HK$25 million.

Several major banks, including Standard Chartered, HSBC, and Bank of China, responded promptly, assuring that if the transactions were confirmed to be unauthorized, cardholders would not be responsible for the losses and providing ways to urgently block their cards. The police investigation revealed that the bank systems were not hacked; the flaw lay in the Apple official website's pre-sale process, which did not require a one-time password (OTP) or other secondary authentication methods. This allowed fraudsters to complete purchases using stolen card information without the need for the cardholders' confirmation.

---

Detailed Analysis

1. The Nature of the Incident: It's Not About Hacked Banks, but About Low Security Standards in the Payment Process

Many people's first thought was, "Has my bank been hacked?" However, the police's initial investigation pointed out a more concerning issue: the banks' systems were not compromised; the problem was with the lax security measures in the payment process.

It's like having a secure door lock at home, but the delivery box outside has a vulnerability—someone with your delivery information (card number, expiration date, CVV code) can take your items without you even having to provide identification.

In this case, the fraudsters had access to a large amount of Hong Kong citizens' credit card information, likely obtained from previous breaches. They didn't need to hack the banks; they just needed to enter the card details on the Apple official website. Since the website did not require an OTP for confirmation, the fraudsters could make purchases unnoticed.

In simple terms: It's like someone using a photocopy of your ID to open a membership account because the merchant didn't require you to be present or use facial recognition. The responsibility lies with the merchant (in this case, Apple) for not properly verifying the customer's identity.

2. Why iPhones? The Convenience of Card-Not-Present (CNP) Payments Becomes a Double-Edged Sword

Why did the fraudsters target the Apple official website? Because it supports CNP payments and often simplifies the verification process for a better user experience.

In physical stores, you need to insert your card or enter a password, which adds a layer of security. Online, especially on platforms like Apple, which prioritize smooth transactions, the verification process might be reduced to avoid delays in purchasing popular items. This allowed the fraudsters to submit orders quickly and in bulk. The convenience came at the cost of security.

3. Banks' Standard Response: Calm Customers, Investigate, and Refund

Standard Chartered, HSBC, and Bank of China handled the complaints professionally in three steps:

  • Step 1: Immediate Action to Stop Losses. Banks warned customers to lock their cards immediately through the app to prevent further transactions.
  • Step 2: Initiate an Investigation. Banks stated they would investigate and mentioned 3-D Secure, an additional online security feature that requires an OTP. However, they also noted that whether 3-D Secure was used was up to the merchant (Apple).
  • Step 3: Guarantee Compensation. All banks emphasized that if the transactions were unauthorized, customers would not be charged. This is a standard practice in credit card transactions, where the bank refunds the amount if the customer can prove they didn't make the purchase.

Implications for Consumers: Even though the banks say you won't be charged, you still need to provide evidence (e.g., showing where you were and that you didn't place the order). This process can take weeks or months, during which your funds might be held or the transaction could be disputed, causing inconvenience.

4. The Dark Side of the Scam Chain: How Did the Card Information Get Leaked?

The police confirmed no cyber attack; the card information likely came from a well-organized criminal network:

  • Source of the Leak: Data from previous breaches on other websites, apps, or even offline POS machines, leading to the spread of credit card details on the dark web.
  • Data Processing: Criminal groups test the cards to determine which are valid and have sufficient balances.
  • Targeted Attacks: They target high-value, easily liquidated items with simple verification processes, such as iPhone pre-sales. iPhones are valuable and can be resold, and Apple's reputation makes it harder to recover the funds.

Warning: Your credit card information may have been compromised without your knowledge. This incident is just the tip of the iceberg, highlighting the vulnerability of personal information protection.

5. Tips for Consumers to Stay Safe

Although the banks will refund the money, to avoid future issues, you can take the following precautions:

  • Enable Transaction Notifications: Make sure your bank app sends notifications for all transactions, especially for large or international/online purchases.
  • Use Card Locking Features: Freeze or limit online payments for cards you rarely use.
  • Be Cautious with CNP Payments: Avoid using payment methods that don't require OTP unless necessary.
  • Regularly Check Your Accounts: Check your transaction history weekly or monthly.
  • Use 3-D Secure: Always enter an OTP when shopping with merchants that support it. If a merchant doesn't offer 3-D Secure and the transaction is large, use other payment methods with additional security measures (e.g., PayPal, Apple Pay).

Conclusion: This incident is not about a hack but about a flaw in the payment process combined with criminal tactics. It shows that convenience often comes at a cost to security. Banks and platforms need to balance user experience with security, and consumers should be more vigilant and manage their payment settings wisely.