The Hong Kong Monetary Authority published a scam alert naming banks on each of three consecutive days this week. Taken together, the alerts of 15 September, 16 September and 17 September 2026 include ten bank entries across six institutions, and every single one describes the same thing: a fraudulent website and an internet banking login screen.
The pattern inside those lists is the part worth reading closely. Four of the six banks appear twice within 48 hours.
What the three alerts actually list
The 15 September notice named four banks: The Bank of East Asia, Shanghai Commercial Bank, Chong Hing Bank and Fubon Bank (Hong Kong). The 16 September notice named one, Chiyu Banking Corporation. The 17 September notice named five: The Bank of East Asia, Shanghai Commercial Bank, Chong Hing Bank, Chiyu Banking Corporation and OCBC Bank (Hong Kong).
Three institutions, Bank of East Asia, Shanghai Commercial and Chong Hing, appear on both the 15 and 17 September lists. Chiyu appears on both the 16th and the 17th. The scam type recorded for every entry on all three days is identical. A second listing within two days does not mean a new customer lost money, and the HKMA does not say it does. What it does tell you is that whatever was reported on the 15th had not been resolved, or had reappeared, by the 17th.
The regulator is a notice board here, not an investigator
The alerts are careful about their own function, and it is easy to misread them as enforcement. Each notice follows the same formula: the regulator is drawing attention to material that the banks themselves published and then reported to it, covering fraudulent sites, fake login screens, phishing emails, and other scams. The direction of travel matters: the banks detected these and reported them to the regulator, which is relaying them with hyperlinks to the banks' own notices.
That framing defines the strict limits of the alerts themselves. They provide no empirical data: no disclosures of customer losses, victim tallies, or estimates of how many depositors accessed a fraudulent portal before it was detected. Similarly, none of the notices confirms that the malicious domains have been neutralised, nor do they detail the subsequent enforcement steps taken by the regulator. Instead, the advisories are operational directives for the public: verify details directly with the named institution, and escalate suspected cases to the Hong Kong Police Force’s Crime Wing Information Centre on 2860 5012.
The HKMA wishes to remind the public that banks will not send SMS or emails with embedded hyperlinks which direct them to the banks’ websites to carry out transactions. They will not ask customers for sensitive information, such as login passwords or One-Time Password, by phone, email or SMS (including via embedded hyperlinks).
A separate warning about the payment rails themselves
Sitting in the middle of that run, on 16 September, is a different kind of notice. Hong Kong Interbank Clearing Limited, the company that operates the Faster Payment System, warned about a fraudulent website at refundrequesthk.cfd that purports to be from HKICL. This is not a bank impersonation but an impersonation of the clearing infrastructure.
On the clearing house's account, the site traded on the language of consumer protection, branding itself around buyer safeguards for payments made over FPS and advertising help with refunds, disputed transactions and general support. The harvesting then ran in two stages. The first went after identity, asking the user for a document number, an image of the document itself and a contact number, with the request dressed up as a verification step standing between them and a promised cash reward. The second went after banking details, seeking the account holder's name, bank, and account number, under the pretext of funding and cashing out a wallet held on the platform. Victims were then moved off the website altogether, into a WhatsApp exchange with someone posing as support staff.
HKICL also flagged that the address varies, warning that the link may carry multiple combinations at its end, giving refundrequesthk.cfd/registered/?uuid=refund as an example.
“HKICL will not directly provide FPS service to individual members of the public or contact individual members of the public proactively under usual circumstance,” the clearing house said in its notice.
The clearing house listed its official addresses as hkicl.com.hk and fps.hkicl.com.hk, and provided a general line, 2533 1111, for anyone wanting to verify a suspicious approach. The pretext keeps returning. HKICL has flagged fake FPS refund services repeatedly in recent weeks, including an earlier warning about fraudulent refund websites impersonating its service.
Why a repeat listing is the signal to watch
For fraud and financial crime teams, the useful intelligence in this run is structural rather than numerical. A scam that produces an identical classification across six institutions in three days and puts four of them on the list twice looks less like six separate criminal efforts and more like shared tooling aimed at a sequence of targets. Convincing fake login screens are cheap to reproduce once the underlying kit exists, and adding another institution costs little.
The takedown question is the one the notices leave open. Nothing in the HKMA's alerts establishes that any fraudulent site was removed, and HKICL's warning about varying link structures shows why that is harder than it sounds: an address that regenerates with a different path outlives the exact one a victim reported, so detection keyed to fixed strings keeps arriving after the fact.
There is also a reporting asymmetry worth noting. Because these alerts originate with banks rather than with the regulator, the list reflects which institutions detected and disclosed, not which were targeted. Hong Kong authorities have been building capacity on the detection side, with the HKMA separately backing wider use of artificial intelligence by banks to fight financial crime, and regional peers have moved toward disruption at the account and message layer, as with Singapore police disrupting more than 30,000 iMessage scam accounts and Thailand ordering cross bank freezes of money mule accounts.
