Imagine checking your phone on a Saturday night and seeing multiple unexpected charges totaling tens of thousands of dollars for Apple devices you never ordered. That is the exact nightmare hundreds of Hong Kong residents woke up to during the chaotic pre-order launch of the iPhone 18 series. Over 700 reports flooded local police stations within just two days, pushing total suspected fraudulent transactions past HK$14.7 million. Major financial institutions like HSBC and Hang Seng Bank scrambled to launch urgent investigations as victims took to social media to expose the security breakdown.
If you store your credit card information online or participate in midnight shopping drops, this incident exposes a massive vulnerability in how high-demand retail tech events operate. Let us look at what actually went wrong during the weekend rush and what you need to do to protect your money right now.
What Happened During the iPhone Pre Order Launch
The chaos erupted right at 8 p.m. on a Saturday when Apple opened its online storefront for the new iPhone 18 Pro and Pro Max. Thousands of eager buyers rushed the site, creating extreme network traffic congestion. But legitimate customers were not the only ones hammering the servers.
Cybercriminals capitalized on the massive surge by deploying stolen credit card credentials obtained from prior data breaches and black market leaks. Victims reported receiving sudden alert messages for multiple purchases of HK$11,499 or HK$13,299 each. Some users experienced repeated phantom charges even after their purchase attempts failed or timed out.
Local internet personality "Szetosifu" shared a similar story online, noting that his Hang Seng credit card transaction failed during the checkout queue. Minutes later, his phone buzzed with ten separate SMS notifications confirming charges for Apple items he never managed to buy.
Why Did Security Protocols Fail
Experts point a finger directly at how online merchants handle traffic spikes. Francis Fong Po-kiu, honorary president of the Hong Kong Information Technology Federation, suggested that the Apple Online Store may have bypassed vital security authentication steps to keep servers running smoothly under heavy loads.
That missing piece is often 3-D Secure, the extra verification step that sends an OTP or prompts your banking app to approve a payment. When merchants or payment gateways disable or soften these checks to speed up checkouts, they leave an open door for automated scripts and bad actors.
Lawmaker Johnny Ng Kit-chong echoed these concerns, noting that hackers likely stockpiled card data over months, waiting for a high-volume retail event where fraud alerts might blend in with normal banking activity.
According to the Hong Kong Monetary Authority, merchants have the operational choice to suspend extra verification arrangements. However, that flexibility comes with a heavy price. If verification is dropped, the merchant takes on full liability for any financial losses resulting from unauthorized charges.
Who Pays When Your Card Gets Hit
Panicked cardholders found themselves stuck between automated customer service lines and unresponsive support teams. Many reported waiting up to half an hour just to reach a human agent at banks like HSBC to freeze their cards.
Fortunately, consumer protection rules offer a safety net. The Hong Kong Monetary Authority confirmed that ordinary cardholders who haven't acted with gross negligence or fraud are generally not liable for unauthorized transactions.
Major lenders have stepped up to clarify their stances. Representatives for HSBC stated that customers who used their cards reasonably and reported suspicious activities promptly would be guided through a full refund process under standard card scheme rules. Hang Seng Bank and Standard Chartered offered similar reassurances, urging victims to file formal police reports immediately.
Apple has also announced it is reviewing pending orders to identify and cancel fraudulent purchases before shipments go out.
How to Protect Your Credit Cards Right Now
You cannot control whether a major retailer cuts corners on security during a product launch. You can, however, take aggressive steps to limit your risk.
- Turn on instant push notifications: Do not rely on email digests or delayed statements. Enable real-time push alerts for every single transaction through your banking mobile app.
- Lock unused cards: Many banking apps now let you lock and unlock your credit card with a single tap. Keep your online shopping card locked until the exact moment you intend to make a purchase.
- Use virtual credit cards: Whenever possible, use disposable virtual card numbers or single-use tokens provided by your bank. If the numbers leak, the hacker cannot drain your primary credit line.
- Monitor account history weekly: Fraudsters often test stolen cards with small charges before making large luxury purchases. Catching those micro-transactions early stops the major damage before it starts.
Check your bank statements today. Freeze any card you do not actively need, and report suspicious activity immediately.