The HKMA Named 13 Banks in 14 Days. Three Are Half.

On 3 September the Hong Kong Monetary Authority relayed scam reports from six banks in a single release. It was the largest of the ten such releases published in the previous fourteen business days, and the only one covering four different attack types at once.

Last updated: September 4

Key takeaways

Link copied
  • The HKMA published 10 bank scam alerts in 14 business days to 3 September, naming 13 banks 35 times.
  • Three banks account for 18 of the 35 mentions: Chong Hing 7, Bank of East Asia 6, Shanghai Commercial 5.
  • A fraudulent website paired with a fake internet banking login screen is 27 of the 35 mentions, or 77.1%.
  • The 3 September release named six banks, the largest single day in the window.
  • On 1 September HKICL warned of fake sites offering FPS refunds and buyer protection it does not provide.
  • These are relayed reports of fake assets, not measured losses; nothing here counts victims or money.

Data highlight

35bank mentions across 13 banks

Banks named in Hong Kong Monetary Authority scam alerts over fourteen business days

17 August to 3 September 2026

Collected by HaiPay on 4 September 2026 from the Hong Kong Monetary Authority's own press-release pages at hkma.gov.hk. For each business day from 17 August to 3 September 2026, URL slots 1 to 8 under that date were requested and the first page titled Scam alert related to banks was taken; the bank names and scam types were then read from the table in that page. Ten of the fourteen business days carried such a release. Those ten releases listed 35 bank mentions covering 13 distinct banks, where a mention is one bank listed in one release and a bank named on four separate days counts four times. The three most frequently named were Chong Hing Bank with seven, The Bank of East Asia with six and Shanghai Commercial Bank with five, together 18 of 35 or 51.4 per cent. Sorting the same 35 mentions by the scam type each bank reported gives 27 for a fraudulent website together with a fraudulent internet banking login screen, three for a fraudulent website alone, two for phishing instant messages, two for phishing emails and one for an unauthorised mobile application; singular and plural wordings were merged and no other normalisation was applied. The four days recorded as carrying no alert should be read as none found at the eight slots checked, not as none published, and weekends and public holidays were not scanned. These are reports of fraudulent assets relayed by the regulator from the banks' own press releases; they are not measured losses and count no victims, transactions or money.

On 3 September the Hong Kong Monetary Authority relayed scam reports from six banks in a single release. It was the largest of the ten such releases published in the previous fourteen business days, and the only one covering four different attack types at once.

HaiPay collected every "Scam alert related to banks" release the HKMA published between 17 August and 3 September by enumerating its press-release URLs day by day. The result is a small dataset the regulator does not publish in aggregate: 35 bank mentions, 13 distinct banks, across 10 of 14 business days.

The concentration is the story

Thirteen banks were named. Three of them account for 18 of the 35 mentions, or 51.4%.

Chong Hing Bank was named seven times in fourteen business days. The Bank of East Asia was named six. Shanghai Commercial Bank was named five. Below them the distribution falls away quickly: OCBC Hong Kong and Chiyu three each, Julius Baer, DBS Hong Kong and Bank of China Hong Kong two each, and five banks once each.

Bar chart of thirteen Hong Kong banks by how often each was named in HKMA scam alerts between 17 August and 3 September 2026, alongside tables of the scam types and the window totals.


That shape is worth pausing on, because the obvious reading is wrong. A bank appearing often on this list is not necessarily a bank with weaker controls. It is a bank whose brand is being impersonated often, which is a statement about how attractive its customer base looks to whoever is building the fake sites, and about how diligently the bank itself reports what it finds. The HKMA's release is explicit that it is relaying press releases issued by the banks. A bank that publishes more may appear more.

What the attackers are actually building

Sorting the 35 mentions by the type of scam each bank reported gives an even tighter distribution.

Twenty-seven of the 35, or 77.1%, are the same thing: a fraudulent website paired with a fraudulent internet banking login screen. Three more are a fraudulent website with no login screen mentioned. Two are phishing instant messages, two are phishing emails, and one is an unauthorised mobile application.

A fake site plus a fake login screen is not opportunistic. It is credential harvesting with a landing page, and the fact that it accounts for more than three-quarters of a fortnight's reports from thirteen different banks suggests a repeatable production line rather than scattered one-offs.

The 3 September release is the exception that shows the pattern. Bank of China Hong Kong reported phishing instant messages and DBS Hong Kong reported phishing emails, while the other four — Bank of East Asia, Shanghai Commercial, Chong Hing and Chiyu — all reported the same website-plus-login-screen combination.

Calendar strip showing the number of banks named on each of fourteen business days from 17 August to 3 September 2026, with a table of the six banks named on 3 September and the scam type each reported.


Two days earlier, the clearing house itself

On 1 September the HKMA carried a separate alert, this one from Hong Kong Interbank Clearing Limited, the operator behind Hong Kong's Faster Payment System.

HKICL said it had noted several fraudulent websites purporting to be from HKICL. In its own description, these sites imitate a "Buyer Online Protection" service and offer three things to consumers: refunds to buyers, a channel to report unauthorised online transactions, and online transaction support — all for payments made over FPS.

One variant goes further. HKICL says it also tries to obtain the user's personal document number and a photograph of their identity document, together with a phone number, for "real name verification" in order to release a cash reward, and separately asks for bank name, account number and account holder name in order to top up and withdraw from the platform's virtual wallet.

HKICL's response is the flat statement that the sites have no affiliation with it, and a point worth quoting for anyone building consumer payment products: it "will not directly provide FPS service to individual members of the public or contact individual members of the public proactively under usual circumstance".

That is the structural weakness being exploited. An instant payment scheme is irreversible by design and, for most consumers, faceless. Nobody has a relationship with the clearing house. So an invented "buyer protection" desk sitting between the consumer and the scheme is plausible precisely because the real thing does not exist in a form the public would recognise.

Why the two alerts belong in the same piece

The bank alerts and the clearing-house alert are the same attack aimed at two different trust anchors. One impersonates the institution the consumer already banks with. The other impersonates the infrastructure underneath the payment.

For a payments business, the second is the harder problem. A bank can send its customers a warning about a fake login screen. Nobody sends consumers a warning about a fake FPS refund desk, because the scheme operator has no consumer relationship to send it through — which is exactly what HKICL had to say in the alert.

What this dataset is, and is not

These are reports relayed by a regulator, not measured losses. Nothing here counts victims, transactions or money. A bank being named tells you a fake asset was found and reported; it tells you nothing about how many people reached it.

The collection method has limits that should be stated. For each business day HaiPay probed eight press-release URL slots and took the first release titled "Scam alert related to banks". A release sitting at a higher slot number on a given day would have been missed, so the four days recorded as carrying no alert should be read as "none found at the slots checked", not as "none published". Weekends and public holidays were not scanned at all.

The scam-type counts are the HKMA's own wording, normalised only for singular and plural. HaiPay did not visit any of the fraudulent sites, did not attempt to verify whether they are still resolving, and did not contact any of the thirteen banks.

What to watch

Three things, all countable from the same source. Whether the three-bank concentration holds over a longer window or turns out to be a fortnight's artefact. Whether the website-plus-login-screen share moves as banks roll out passkeys and device binding, which would push attackers towards the message-based typologies that currently account for four of 35. And whether HKICL has to issue a second FPS impersonation alert, which would suggest the first one did not shift anything.


How to cite

Link copied

HaiPay News, "The HKMA Named 13 Banks in 14 Days. Three Are Half.", https://www.haipay.net/news/hkma-bank-scam-alerts-fourteen-days, September 4th, 2026

About the author

Crystal

Digital Public Relations

A digital PR specialist with a Master's in Journalism & Communication from UNSW. Started as an intern at ABC Australia, now leads public relations at Haipay, crafting press releases and media strategies that bring brand stories to life.

Reviewed by WeiJun TangEditorial policy

4 sources

Discover More