Our takeHKCERT warns of phishing campaigns that lead to unauthorized credit card transactions. Treat any unsolicited banking or card email as suspect and never click links or enter details.Cyber Resilience desk
Sources (1)
- hkcert · hkcert
What this means for you — Security leader:Review recent card transactions for anomalies and ensure staff are trained to spot phishing attempts targeting payment details. Enable transaction alerts and consider tokenization or virtual cards where possible.
What this means for you — Lean IT orgs:Check your business credit card statements regularly for charges you don't recognise. Train your team to never enter card details after clicking an email link, and use virtual or single-use card numbers when you can.
What this means for you — MSP:Advise clients to enable real-time card transaction alerts, review statements promptly, and run phishing awareness training focused on payment fraud scenarios. Monitor for unusual authorisation patterns across client environments.
What this means for you — Researcher:HKCERT warns of phishing campaigns that result in unauthorised credit card use. Review the linked advisory for campaign indicators and IOCs.