Fake Buyer-Protection Portals: Refund, ID and Bank-Detail Checks
A newly disclosed HKICL impersonation scheme combined refund support, identity verification, bank details, a fake wallet and an impersonated agent. Here is how to verify the service and respond after data entry or payment.

On August 31, 2026, the Hong Kong Monetary Authority and Hong Kong Interbank Clearing Limited (HKICL) warned about multiple websites impersonating HKICL. These were not simple copies of a login page. They presented themselves as a “Buyer Online Protection” service offering refunds, reports of unauthorized online transactions, and support for purchases paid through the Faster Payment System (FPS).
The more elaborate version asked users to complete a supposed real-name check for a cash reward. It collected an identity document number, an ID photo and a phone number, then requested the bank name, account number and account-holder name. Users were guided to top up or withdraw from a virtual wallet through FPS and were eventually directed to a fraudster posing as customer support.
A Fake Buyer-Protection Portal
The first type described by HKICL offered three reassuring functions: a buyer refund, an unauthorized-transaction report and online support for an FPS payment. Those are exactly the services a worried shopper might look for after a disputed purchase. A convincing menu can therefore feel more important than the address in the browser, even though the address is the more reliable check.
The second type added a cash reward and a real-name verification step. It combined an ID image and phone number with bank-account details, then connected those details to a fake wallet. When the process became confusing, an impersonated support agent could tell the user what to do next. The whole sequence was designed to make each new request appear to follow naturally from the previous one.
This matters because the portal uses the language of protection rather than an obvious prize alone. Refunds make bank details seem relevant, real-name checks make an ID photo seem routine, and a support agent supplies reassurance. Users should assess the service owner, the path used to reach the page and the information requested as one connected decision.

What Does Not Match a Genuine FPS Process
HKICL stated that the fraudulent sites had no affiliation with HKICL or any of its businesses. It also explained that, under normal circumstances, HKICL does not provide FPS services directly to individual members of the public or proactively contact them. A portal claiming to process an individual shopper’s refund directly as HKICL is therefore inconsistent with the organization’s normal role.
The official addresses identified by HKICL are www.hkicl.com.hk and fps.hkicl.com.hk. A scam address can contain strings such as FPS or HKICL while ending in an unrelated domain. Logos, payment terminology and a polished support page do not override the actual domain. Close a page opened from a message or advertisement, type the official address in a new window and locate the organization’s notice and contact details there.
Korea’s Internet & Security Agency has separately warned about phishing sites that imitate government agencies and offer fraud-recovery applications. Those sites use reassuring terms and official-looking branding to collect personal or card information or move users into messenger chats. The practical lesson travels well: a page promising help with a loss deserves the same scrutiny as a page asking for payment.
Separate Each Data Request
A phone number paired with an ID image links contact information to a specific identity. Before submitting either, verify why the named organization needs it and whether the service actually belongs to that organization. If the page moves the conversation to a personal messenger account or an unfamiliar domain, stop and use a representative number obtained from the official website.
Bank name, account number and account-holder name may appear necessary for a refund. In this case, however, those fields were linked to topping up or withdrawing from a virtual wallet. Start a genuine refund from the original merchant order, card transaction or bank-transfer record. A new platform asking for a wallet deposit is initiating another transfer, not simply reversing the first transaction.
An on-page support agent cannot prove that the page is genuine because the page and the agent may be controlled by the same operation. Re-check any claim through the official organization and through the bank or card issuer involved in the original payment. Urgency about a disappearing refund does not make further data entry or a transfer safer.
A Verification Sequence
- Close the buyer-protection or refund page opened from a message and type the verified official address yourself.
- Confirm on the official site whether the named organization directly offers that service to consumers.
- Check the original merchant order, card authorization and bank transfer in their respective official apps.
- Stop if one page asks for an ID photo, phone number, bank details and a new wallet top-up.
- Contact the organization using a number found independently on its official website, not the page under review.
Look at the registrable end of the domain rather than the brand words placed before it. A padlock only indicates that the connection is encrypted; it does not establish that the operator is the organization shown on the page. Bookmarks and official banking apps reduce the chance of being diverted through sponsored search results or look-alike addresses.
Also watch for a process that combines unrelated claims, such as real-name verification for a reward and an advance deposit to stop an unauthorized transaction. Funding a new wallet points in the opposite direction from reversing the original payment. Do not continue with screen sharing or another transfer until the original merchant, card issuer or bank confirms the request independently.

If You Entered Information
Preserve evidence before deleting the message: the address, sender, chat history, time, screenshots and transfer record. Write down exactly which fields were submitted. If an ID image and phone number were provided, inform the relevant issuer, mobile provider and financial institution and review account and transaction alerts. If banking credentials or authentication codes were entered, change them through the official app and contact the institution immediately.
If money was transferred, call the bank promptly and ask about freezing the payment. The Korean National Police Agency’s cybercrime system outlines a process that begins with a payment-freeze request to the financial institution managing the recipient account, followed by a police report and the required victim-relief documents. Follow the bank’s instructions for deadlines and supporting records.
Even without a completed transfer, reporting the address and message can help. KISA’s phishing-check service can be used to review and report a suspicious link. Capture the full address and sender before removing the message so the report contains enough context.
This Week’s Checklist
- Return to the original merchant, card or bank app instead of a buyer-protection link.
- Type the independently verified official domain rather than trusting brand words in the address.
- Stop when one page asks for an ID photo, phone number, bank details and a wallet top-up.
- Ask the original bank or card issuer before sending money to receive a refund.
- Preserve the page, conversation and transaction record before starting official reporting.
One Habit for This Week
When a message says “refund,” “unauthorized transaction” or “buyer protection,” do not solve the problem inside that link. Return to the app where the original order, authorization or transfer occurred and start from its official record. That single habit breaks the separate process created by a fake support portal before identity documents, bank details or another payment are handed over.
Sources reviewed
- HKICL alerts public of fraudulent websiteGovernment of the Hong Kong SAR · Official source
- Notification of Fraudulent WebsiteHong Kong Interbank Clearing Limited · Official source
- 정부기관 사칭, 사기 피해자 구제를 유도하는 피싱사이트 주의 권고한국인터넷진흥원 보호나라 · Official source
- 피해자 구제 제도경찰청 사이버범죄 신고시스템 · Official source
SECUFOCUS NOW reorganized and analyzed the material above. This article does not replace the original sources.



Comments
No comments yet.