FREDERIC J. BROWN

Apple opened pre-orders for the iPhone 18 Pro and iPhone 18 Pro Max at 8pm last Saturday (September 12), but within a day Hong Kong had seen one of the largest collective credit card fraud incidents in recent years. As of September 13, the police’s e-Report Centre had received more than 700 reports involving about HK$14.7 million in total. The biggest single reported loss was about HK$114,000. The case has been classified as obtaining property by deception and remains under investigation. No arrests have been made.

Several victims said they had not placed any orders but received a series of bank text messages about “card-not-present” transactions showing purchases of new phones from APPLE.COM/HK. Yuen Long district councillor Sham Ho-kit wrote on social media on September 13 that he rarely used his card online, but received several messages on the night pre-orders opened saying he had “bought several phones”. He later called his bank’s 24-hour hotline and confirmed that only one transaction had actually gone through. KOL Sito Gap-tai said Hang Seng Bank sent him at least six notifications for card-not-present transactions, each for HK$13,299 — exactly the price of the 512GB iPhone 18 Pro Max — involving nearly HK$80,000 in total. Other transaction amounts reported online included HK$10,499, HK$11,499 and HK$22,998, all matching the official prices of different models.

Where did the verification step go?

The central question is how the transactions were able to go through without authentication. Francis Fong, honorary president of the Hong Kong Information Technology Federation, said the Apple Online Store generally uses a “dynamic risk assessment” system to ensure smooth traffic during pre-orders, exempting some transactions from one-time-password text messages or app-based authentication. He said fraudsters may have exploited card details previously obtained through phishing websites or leaked on the black market to place orders during the rush.

Fong explained that if a merchant enables 3D Secure (3DS) authentication, users are sent a separate six- to eight-digit password to enter when placing an order. However, the process can add 30 seconds to a minute to a transaction. He estimated that Apple may not have enabled the system in order to shorten the checkout process.

Legislative Council Information Technology constituency lawmaker Duncan Chiu also criticised the arrangement on a radio programme, saying the incident suggested the merchant may have suspended 3DS authentication to speed up transactions and should bear full responsibility. He also raised another possibility that cannot be overlooked: some of the unusual transactions may not have been fraudulent card use at all, but may have resulted from buyers clicking repeatedly because of system delays, causing the same phone to be recorded as multiple orders. In other words, some cases could involve technical duplication rather than third-party fraud. Police and banks are still investigating this possibility, and no conclusion has been reached. The public should not assume that every case involved criminal card theft.

Who pays? HSBC and Standard Chartered give consistent responses

Responsibility for 3DS transactions is not an uncharted area. Under the usual arrangements of international card schemes such as Visa and Mastercard, liability lies with the issuing bank if a transaction has gone through 3DS authentication. If a merchant bypasses the authentication, liability shifts to the merchant. HSBC and Standard Chartered said in response to enquiries that whether 3DS is enabled is decided by the merchant, and banks cannot activate it on behalf of customers. Both banks said they would assist customers with refunds if they had used their credit cards reasonably and cautiously. HSBC, Hang Seng Bank, Standard Chartered and Bank of China (Hong Kong) subsequently said they would investigate and, where applicable, initiate chargeback procedures under card-scheme rules.

The Hong Kong Monetary Authority has also commented on the allocation of responsibility. If a merchant does not adopt additional authentication arrangements for operational reasons, the resulting financial loss should be borne by the merchant. Cardholders, meanwhile, do not have to bear responsibility for unauthorised transactions as long as they have not acted with gross negligence or fraudulently. Under the current regulatory framework, this means the liability for the nearly HK$15 million in losses would theoretically fall more heavily on Apple than on the affected cardholders.

Apple Hong Kong later responded to media enquiries, saying all received orders would be reviewed before processing and that it was working to identify and cancel potentially fraudulent orders as soon as possible. As the phones involved have not yet been shipped, the transactions remain at the authorisation stage rather than having been finally settled. The funds therefore remain within the banking system, meaning there is theoretically still room to cancel the orders and release the holds once fraud or duplication is confirmed.

What to watch next

The incident is still developing. Key issues to watch include whether the four issuing banks complete refunds as promised; whether the police investigation concludes that the cases involved solely fraudulent card use or that some were caused by duplicate orders generated by system problems; and whether Apple adjusts its 3DS policy for pre-orders of popular models in future.