Multiple residents suspect their credit cards have been fraudulently used to purchase new iPhones, with unauthorized transactions spanning HSBC, Hang Seng Bank, and Standard Chartered Bank.
Following the opening of pre-orders for Apple’s latest iPhone 18 Pro and iPhone 18 Pro Max at 8pm on Saturday (Sep 12), several victims took to social media to report cumulative losses exceeding HK$60,000.
In response to inquiries, HSBC said it is aware of the online discussions and reminded customers to freeze their cards via the HSBC HK App or by calling the customer service hotline upon detecting unauthorized transactions. It will also launch investigations for affected cardholders and, where applicable, initiate chargeback procedures in accordance with credit card scheme rules.
HSBC added that while 3-D Secure (3DS) technology enhances security, its implementation is ultimately determined by individual merchants.
Bank of China Hong Kong (BOCHK) has reminded customers who detect unauthorized transactions on their credit cards to immediately log in to mobile banking to block their cards.
Customers can also suspend their cards and submit a disputed transaction application via the online customer service platform or the customer service hotline, with the bank emphasizing that all cardholders are protected by a chargeback mechanism.
BOCHK added that it also provides 3DS authentication for online transactions to further protect customers, though its implementation depends on individual merchants.
Standard Chartered reaffirmed that it has established mechanisms to monitor transactions closely and is actively assisting customers, merchants, and credit card organizations to follow up on suspicious activities.
The bank reminded customers who detect any unauthorized transactions to notify it as soon as possible, report the incident to the police, and instantly block their credit cards using online banking or the SC Mobile app.
It will launch investigations according to established procedures and submit chargeback applications to the relevant credit card organizations where applicable, while emphasizing that it provides 3DS authentication for merchants.
Customers will not be held liable for the disputed amounts if investigations confirm that the transactions were unauthorized by the cardholder, the bank added.
Meanwhile, the Hong Kong Monetary Authority (HKMA) reassured cardholders that merchants who fail to implement additional authentication arrangements, such as in app authentication or one-time passwords, must bear the liability and financial losses arising from any unauthorized transactions.
In general, cardholders will not be held liable for unauthorized transactions if they have not committed any fraudulent or grossly negligent acts, the HKMA added.
Francis Fong Po-kiu, honorary president of the Hong Kong Information Technology Federation, said the incident may have occurred because Apple waived SMS one-time passwords or in-app authentications for select transactions to ensure smooth traffic flow during the surge.
Fong suggested that scammers took advantage of these relaxed security protocols during the pre-order rush to execute real-time transactions using credit card credentials previously acquired through phishing websites or illegal channels.
He reminded members of the public to avoid entering sensitive credit card information on unfamiliar websites or clicking links from unverified sources. He also cautioned against authorizing third parties to purchase products or services on their behalf.