Hong Kong police are investigating a suspected security gap in the online checkout process after fraudsters allegedly used compromised payment card details to place unauthorised orders worth about HK$25 million during the launch of Apple’s latest smartphone series.

By Monday afternoon, 1,209 cardholders had reported suspected fraudulent activity, with victims believing their financial information had been used without permission to purchase newly released iPhones. Police said the scale of the cases had grown rapidly after pre orders opened, raising concerns about how the transactions were approved and whether the absence of SMS one time verification codes made the fraud easier to carry out.

The suspected scam emerged almost immediately after pre orders began at 8pm on Saturday.

During the first two days of the pre order period, police received complaints from more than 700 people involving approximately HK$14.7 million in suspected fraudulent charges. The largest individual case involved transactions worth about HK$114,000.

The number of reports continued to rise over the following hours. By Monday afternoon, the total number of affected cardholders had reached 1,209, while the estimated value of the suspected fraudulent purchases had climbed to around HK$25 million.

Police believe the transactions may have been made using payment card information that had already been compromised before the launch of the new devices.

28b5e937-fea8-43e5-a7c5-917d1f88aed9.png

Missing SMS Verification Codes Under Scrutiny

Investigators have focused on the checkout process used to complete the purchases, particularly the apparent absence of one time passwords sent to cardholders by SMS.

One time verification codes are commonly used as an additional security measure for online transactions. The process requires the person making a purchase to enter a temporary code sent directly to the registered mobile phone number associated with the payment card.

In the cases now under investigation, police said the checkout process did not require such an SMS verification step.

That meant someone who already possessed a cardholder's payment details could potentially complete a purchase without needing direct access to the cardholder's phone or receiving further approval from the legitimate account holder.

Police said this gap created an opportunity for fraudsters to process unauthorised transactions using compromised financial credentials.

Many affected cardholders reportedly discovered the suspected fraud only after receiving automated transaction alerts from their banks shortly after the pre order window opened.

For some victims, the first indication that their card information had been misused came after a bank notification showed an unfamiliar purchase. By then, the suspected transactions had already been processed or submitted.

The rapid increase in complaints suggests that the fraudsters may have acted quickly after pre orders opened, potentially using previously obtained card information to secure devices during the initial rush for the latest smartphones.

Police are now attempting to determine where that financial information came from and how it reached the people responsible for the suspected scheme.

Investigators Trace Possible Source of Compromised Data

Law enforcement authorities said they are examining possible sources of the leaked or compromised payment information while also tracing the digital activity connected to the purchases.

The investigation includes efforts to identify the individuals and possible criminal groups involved.

Police are seeking to establish whether the payment details used in the transactions were collected through earlier data breaches, phishing operations, fraudulent websites, malware or other forms of financial crime.

At this stage, preliminary checks by the affected banks and Apple found that their internal systems appeared to be operating normally and showed no indication that they had been compromised through an external cyberattack.

That finding has shifted attention away from an immediate breach of either organisation's internal systems and towards the possibility that the payment information had been obtained elsewhere before being used for the iPhone purchases.

Investigators are expected to examine transaction records and other digital information to identify patterns among the affected accounts.

The unusually large number of cases may help investigators determine whether the fraud involved a coordinated operation rather than isolated incidents.

Police have not publicly identified those responsible for the suspected transactions, and the criminal investigation remains ongoing.

c4a766f7-3241-4edc-b7ba-37077e14033d.png

Police Work With Banks and Apple to Cancel Orders

Authorities have begun coordinating with Apple and the relevant banks to limit further financial losses.

Police said they had passed details from reported cases to both parties so that suspicious orders could be identified and cancelled as quickly as possible.

The aim is to stop fraudulent purchases before devices are dispatched and, where possible, reverse unauthorised transactions before victims suffer permanent financial losses.

Police have also formally requested detailed transaction records from Apple and the banks involved.

Those records are expected to help investigators track how and when the purchases were made, identify possible links between transactions and examine whether the same methods, accounts or digital identifiers were used across multiple cases.

The cooperation between law enforcement, financial institutions and the retailer has become an important part of the effort to contain the fraud while the investigation continues.

For affected cardholders, however, speed remains important.

People who discover suspicious activity on their accounts have been urged not to wait for the situation to resolve itself.

What Cardholders Should Do if They Spot a Suspicious Charge

Police have advised anyone who suspects that their credit card has been used without permission to take immediate action.

The first step should be to lock or freeze the affected card to prevent additional transactions. Cardholders should then contact the issuing bank and report the suspected unauthorised activity.

Police also advised affected customers to contact Apple regarding any suspicious orders connected to their payment details.

Victims should file a police report and obtain the relevant case reference number. That reference number should then be provided to the issuing bank to support the dispute process and help financial institutions investigate the transaction.

Cardholders should also continue monitoring their accounts for further suspicious activity, particularly during periods when fraudsters may attempt to use stolen payment information for high demand products.

The case has drawn attention to the role that additional verification can play in preventing online payment fraud. Possession of a card number and other payment details does not necessarily mean the person using them is the legitimate cardholder, which is why additional checks can help stop unauthorised purchases.

With more than 1,200 cardholders already reporting suspected misuse and approximately HK$25 million linked to fraudulent transactions, police are now working to identify the source of the compromised payment information and trace those behind the purchases.

Have you checked your recent bank and credit card transactions since the latest iPhone pre orders opened? Anyone who identifies an unfamiliar charge should immediately freeze the card, contact their bank and report the transaction before further unauthorised purchases can be made.