Amp.Scmp Hong Kong Police Disrupt HK$16.8 Million Phishing Syndicate
Article Content
- •15 individuals arrested in a joint operation against a phishing syndicate.
- •Scammers impersonated the Water Supplies Department to exploit public trust.
- •Phishing scams in Hong Kong surged by 83.5% in early 2026.
Hong Kong and mainland Chinese authorities have dismantled a cross-border phishing syndicate that defrauded victims of HK$16.8 million (US$2.14 million) by impersonating the Water Supplies Department. The operation, named Operation Boldhawk, led to the arrest of 15 individuals between March and June 2026. Scammers targeted residents through malicious text messages, exploiting their trust in government services. In the first five months of 2026, Hong Kong police reported 1,009 phishing scams, an 83.5% increase from the previous year, with 841 cases linked to fake payments from the Water Supplies Department. One victim, a 71-year-old, lost over HK$310,000 after entering credit card details on a fraudulent site. Victims ranged from ages 17 to 86, indicating that anyone can fall prey to such scams. Authorities emphasize the need for public vigilance against these threats.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Water Supplies Department in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…