Phishing scams exploit contactless mobile card binding
HKMA Press

Phishing scams exploit contactless mobile card binding

Banks in Hong Kong reported phishing scams that trick victims into binding payment cards to unauthorized contactless mobile wallets. The Hong Kong Monetary Authority issued a public warning and alerted lenders to the fraud schemes on September 4, 2026.

From fake refunds to hijacked wallets

Fraudsters impersonated merchants and organisations through phishing messages, fraudulent websites, and deceptive phone calls to capture payment card credentials and ATM personal identification numbers.

Criminals frequently used pretexts such as compensation for goods to trick victims into surrendering sensitive information.

To bind payment and ATM cards to devices under their control, fraudsters coaxed victims into approving provisioning requests via mobile banking applications or two-way SMS verification.

Once the cards were linked to contactless mobile payment services, unauthorized transactions followed immediately.

The HKMA shared the operational tactics with the banking industry.

Four rules for digital security

The HKMA emphasized that binding a payment card to a device is a high-risk operation requiring strict user vigilance.

The regulator advised the public never to click links from unknown sources or disclose card numbers, ATM PINs, passwords, and one-time passwords to anyone.

Users must refuse any authorization requests prompted by unverified parties across mobile apps or SMS channels, while carefully scrutinizing all bank notices.

Anyone suspecting fraud should immediately contact their bank, alert the police, and consult the Anti-Scam Helpline at 18222.

Convenience creates a security gap

Contactless provisioning reveals how payment convenience continues to undermine basic security safeguards.

Relying on public vigilance rather than mandatory banking friction offers little protection against targeted deception.

Supervisors must enforce stricter authentication protocols for device binding rather than issuing routine warnings.

Report an error