30 Fake Domains Impersonating Hong Kong's Payment Rail

Hong Kong Interbank Clearing Limited runs the Faster Payment System, the rail that moves money between Hong Kong bank accounts in seconds. It is not a consumer brand. Almost nobody has an account with it. That is exactly what makes it useful to impersonate: since 22 January, the HKMA has published 22 alerts naming fraudulent websites that claim to be HKICL, and between them they name 30 different domains.

Last updated: September 9

Key takeaways

Link copied
  • The HKMA has published 22 alerts about websites impersonating clearing house HKICL since 22 January 2026.
  • Those alerts name 30 distinct fraudulent domains, built from 23 different names.
  • One name, fpshkicl, was registered on five suffixes; hkrefundplatform on three in three weeks.
  • 22 of the 30 domains use a suffix other than .com or .cc, mostly cheap new ones.
  • The lure changed in late June, from credential theft to a fake "Buyer Online Protection" refund service.
  • Alerts came every 14.7 days before the change and every 8.6 days after it.

Data highlight

30fraudulent domains across 22 alerts

Distinct fraudulent domains named in Hong Kong Monetary Authority alerts about websites impersonating Hong Kong Interbank Clearing Limited

9 September 2026

Counted by HaiPay on 9 September 2026. HaiPay retrieved the 600 most recent Hong Kong Monetary Authority press releases from the HKMA public press release API, a window covering 21 August 2025 to 8 September 2026, and identified 22 releases about fraudulent activity impersonating Hong Kong Interbank Clearing Limited, the first dated 22 January 2026 and the most recent 7 September 2026. No such alert appears in the window before 22 January 2026. Each alert page was read in full and the domains it names were extracted, giving 30 distinct fraudulent domains, of which 21 alerts name at least one; the remaining alert, dated 26 May 2026, concerns a fraudulent Faster Payment System advertisement on Facebook rather than a website. HKICL's own address, fps.hkicl.com.hk, appears in the alerts as the legitimate site and is excluded from the count. Behind the 30 domains there are 23 distinct second-level names, because three were registered on multiple suffixes: fpshkicl on .asia, .click, .com, .fun and .help; hkrefundplatform on .cfd, .click and .sbs; and fps-hkicl on two. Twenty-two of the 30 use a suffix other than .com or .cc. Twenty contain the string hk in the name, sixteen contain fps and ten contain hkicl. One domain, monetaryauthorityhk.xyz, impersonates the Hong Kong Monetary Authority rather than the clearing house. Classifying each alert by the lure it describes, eleven alerts between 22 January and 18 June 2026 describe sites intended to obtain login credentials and direct users to WhatsApp chats with a fraudster impersonating customer service personnel, a mean interval of 14.7 days, while ten alerts between 22 June and 7 September 2026 describe sites imitating Buyer Online Protection and offering refunds, unauthorised transaction reporting and transaction support for payments over the Faster Payment System, several requesting an identity document number and photograph for real name verification, a mean interval of 8.6 days. In the same 600-release window the HKMA published 189 releases titled Scam alert related to banks. The alerts do not state losses, victim numbers or whether the domains were taken down, and HaiPay did not visit any of the sites and did not contact HKICL or the HKMA.

Hong Kong Interbank Clearing Limited runs the Faster Payment System, the rail that moves money between Hong Kong bank accounts in seconds. It is not a consumer brand. Almost nobody has an account with it.

That is exactly what makes it useful to impersonate. Since 22 January, the Hong Kong Monetary Authority has published 22 alerts naming fraudulent websites that claim to be HKICL. Between them they name 30 different domains, and the most recent alert is two days old.

A brand nobody can verify

When a scam site imitates your bank, you have a test available. You know what your bank's app looks like, you have its card in your wallet, and its real address is printed on your statement.

A clearing house is different. You use it constantly and you have never visited its website. You could not name its domain if asked. So when a page says it is the operator of FPS and offers to help with a payment that went wrong, there is nothing familiar to compare it against, and the institutional authority is if anything greater than a bank's.

The domains reflect that. Of the 30, twenty put "hk" in the name, sixteen put "fps" and ten put "hkicl". They are not trying to look like a bank. They are trying to look like the plumbing.

Thirty domains, twenty-three names

Read as a set rather than one alert at a time, the list shows a small operation rotating stock.

Behind the 30 domains there are only 23 distinct names, because three were re-registered on multiple suffixes. The name fpshkicl appears on .asia, .click, .com, .fun and .help. The name hkrefundplatform appears on .cfd, .click and .sbs, in alerts dated 19 August, 1 September and 7 September, which is a takedown-and-replace cycle running about a fortnight.

Twenty-two of the 30 use a suffix other than .com or .cc. The list runs through .cfd, .click, .sbs, .lat, .xyz, .fun, .help, .top and .asia: the cheap end of the domain market, where registration costs a few dollars and takes minutes. That is the economics of the thing. The defender has to get a takedown; the attacker has to fill in a form.

One entry in the set is not impersonating the clearing house at all. monetaryauthorityhk.xyz impersonates the Hong Kong Monetary Authority, the regulator publishing the alerts.

Grid of the thirty fraudulent domains named in HKMA alerts about sites impersonating Hong Kong Interbank Clearing Limited, with counts showing 23 distinct names, 22 on suffixes other than .com or .cc, and 16 containing the string fps.


The script changed in June

The alerts are formulaic, which makes the moment they stop being formulaic easy to see.

From 22 January to 18 June, eleven alerts describe the same thing: sites that "intend to trick user into giving away login credentials" and then push the victim into "WhatsApp chats with the fraudster impersonating as customer service personnel." Credential theft with a human closer.

From 22 June the wording changes completely. Ten alerts describe sites imitating something called "Buyer Online Protection," offering three services: refund to buyer, unauthorised online transaction reporting, and online transaction support, all for payments made over FPS. Several ask for an identity document number and a photo of the document, together with a phone number, for "real name verification" in order to release a cash reward.

That is a different crime. The first version steals a login. The second harvests identity documents from people who believe they are claiming a refund, and it works on someone who has already lost money once.

The pace changed with the script. The eleven credential alerts span 147 days, one every 14.7 days. The ten Buyer Online Protection alerts span 77 days, one every 8.6 days.

What the archive does and does not show

HaiPay pulled the 600 most recent HKMA press releases, a window reaching back to 21 August 2025, and read every HKICL alert in it in full.

There are none before 22 January 2026. On this evidence the campaign against the clearing house is a 2026 phenomenon, though a window that starts in August 2025 cannot speak to anything earlier.

For scale within the same archive, the HKMA published 189 releases titled "Scam alert related to banks" over the same period. Impersonating the clearing house is the rarer variant. It is also, on the wording of the alerts, the more organised one, because the bank alerts name individual reported cases while the HKICL alerts describe a single product being redeployed.

Two panels comparing the two phases of HKICL impersonation alerts: eleven alerts from January to June 2026 describing credential theft and WhatsApp contact at one every 14.7 days, and ten alerts from June to September 2026 describing a fake Buyer Online Protection refund service at one every 8.6 days.


What HaiPay could not establish

How many people lost money, or how much. The alerts warn; they do not quantify, and no figure appears in any of the 22.

Whether the domains were taken down, and how quickly. The alerts do not say, and HaiPay did not visit any of the sites.

Whether the same operator is behind both phases. The changeover is clean and the infrastructure style is consistent, but the alerts do not attribute, and neither does this piece.

HaiPay did not contact HKICL or the HKMA.

What to watch

Whether hkrefundplatform appears on a fourth suffix. Three registrations of the same name in three weeks is a pattern, and the next one would confirm the replacement cycle rather than suggest it.

Whether the alert rate holds at roughly one every nine days, which would put the next one around the middle of September.

And whether other instant payment schemes start publishing this. Hong Kong names the domains, which is what makes counting possible at all. Most schemes do not, so nobody can tell whether their rails are being impersonated at this rate or worse.

This piece reads published regulator alerts. The domains listed are reproduced from those alerts as a record of what was reported; nobody should visit them. If you believe you have been targeted, contact your bank.

How to cite

Link copied

HaiPay News, "30 Fake Domains Impersonating Hong Kong's Payment Rail", https://www.haipay.net/news/hkicl-fps-fraudulent-domains, September 9th, 2026

About the author

Crystal

Digital Public Relations

A digital PR specialist with a Master's in Journalism & Communication from UNSW. Started as an intern at ABC Australia, now leads public relations at Haipay, crafting press releases and media strategies that bring brand stories to life.

Reviewed by WeiJun TangEditorial policy

4 sources

Discover More