
Hong Kong recently witnessed a large-scale credit card fraud incident: over 700 unauthorized transactions with total losses of approximately HK$14.7 million, all linked to iPhone 18 Pro series pre-orders. The incident not only exposed how hackers exploit new product hype to steal and misuse credit card data, but also pushed a long-neglected issue into the spotlight: can merchants sacrifice customer payment security in pursuit of conversion rates, shorter checkout times, and coping with peak traffic?
The answer is clear: no. A transaction may be smooth, but if the verification mechanism behind it is bypassed, the end result is customer financial loss, collapsed trust in the platform, and the merchant’s own legal and financial liability.
The Core of the Incident: 3DS Suspected of “Making Way for Traffic”
According to reports, Francis Fong, Honorary President of the Hong Kong Information Technology Federation, raised a speculation that should alert every merchant: Apple may have temporarily disabled the 3D Secure (3DS) additional authentication protocol in order to reduce server load and shorten waiting times during peak periods.
3DS is a critical line of defense for online credit card transactions. It requires cardholders to take an extra verification step at payment, such as entering a one-time password or confirming via their bank’s app, to confirm that “the payer is the cardholder.” When this step is skipped, fraudsters only need to obtain credit card data to complete transactions like ordinary consumers, making it harder for both merchants and issuing banks to intercept them in time.
The report cites clear Hong Kong Monetary Authority (HKMA) guidelines: if a merchant suspends additional authentication for operational reasons, the merchant should bear full responsibility and financial liability for any resulting fraudulent transactions. In other words, abandoning security for “speed” is not cost-saving—it is transferring risk from the system onto one’s own balance sheet.
Why Do Merchants Always Want to Take Shortcuts?
We must honestly face business reality. Merchants considering disabling or reducing verification strength usually do so for several reasons:
Conversion rate anxiety: Every extra verification step causes some customers to abandon payment. Especially during buying frenzies, merchants fear losing to competitors by a single second.
Server pressure: When a new product goes on sale, traffic surges instantly. Additional authentication increases system load and may cause website crashes or checkout timeouts.
Illusion of customer experience: Some mistakenly believe “no verification” equals “convenience,” ignoring that convenience and risk are often two sides of the same coin.
Misjudgment of liability: Some merchants assume fraud losses are mainly borne by banks or cardholders, but HKMA guidelines and international card scheme rules both indicate that if a merchant actively lowers security standards, liability may fall back on the merchant itself.
These reasons sound “pragmatic,” but they all rest on a dangerous assumption: customer security can make way for business goals. This incident precisely demonstrates that once this assumption collapses, the cost is far greater than waiting a few extra seconds.
Security Is Not a Cost—It Is a Brand Asset
For merchants, credit card security has never been merely a technical compliance requirement; it is a core component of brand trust.
Imagine: a customer successfully buys a phone during a high-traffic pre-order, only to discover afterward that their credit card was fraudulently used, or even that multiple orders were placed. They will not blame only the hacker—they will blame the platform: “Why was it so easy to be fraudulently used?” “Why did I place only one order but the system submitted multiple?” “Why wasn’t there one more layer of authentication to protect me?”
This loss of trust is hard to quantify but genuinely affects repurchase rates, customer lifetime value, and word of mouth. Conversely, a merchant willing to insist on verification even during peak periods—willing to let customers wait a few extra seconds—sends the message: “Your money matters more than my server load.” That is true long-term competitiveness.
What Can Merchants Do? Five Non-Negotiable Principles
1. Never actively disable 3DS or other strong authentication under any circumstances
If the system cannot handle peak traffic, invest in scaling, queuing mechanisms, or phased sales—do not dismantle the security gate. HKMA guidelines already state clearly: operational reasons are not grounds for exemption.
2. Build security design into peak-period contingency plans, not after-the-fact remediation
Before pre-orders, limited releases, holiday promotions, and similar events, stress-test the complete checkout path including the 3DS flow. Security and performance are not either-or; they are engineering problems to be planned together.
3. Anomaly transaction monitoring must be real-time and proactive
Apple’s post-incident identification and cancellation of suspected fraudulent transactions is the right direction, but it would be more ideal to intercept at the moment of transaction. Merchants should work with payment service providers to build rules engines that provide real-time alerts for multiple orders in a short time, abnormal repeats on the same credit card, high-risk IPs, and similar behaviors.
4. Duplicate order issues must be fundamentally resolved at the interface and system level
Some netizens complained that they placed only one order but multiple orders were submitted. Francis Fong believes this is more likely a platform system failure—for example, customers clicking the “place order” button multiple times. Merchants must ensure buttons have anti-duplicate submission mechanisms, order statuses are clear, and customers are proactively notified of anomalies rather than waiting for them to discover the problem themselves.
5. Data breach protection and incident reporting must not be neglected
Francis Fong emphasized that organizations managing large databases need to strengthen protection against data leaks. Merchants should minimize storage of credit card data, encrypt sensitive fields, strictly limit internal access, and establish breach response and reporting procedures. Concealment or delay only expands the damage.
Self-Protection Reminders for Consumers
Although this article focuses primarily on merchant responsibility, consumers can also proactively reduce risk:
Enable real-time credit card transaction notifications and contact the bank immediately upon any anomaly.
Use virtual credit card numbers or payment platform intermediaries where possible, avoiding direct provision of primary card numbers to merchants.
Shop on reputable platforms and check whether the checkout page has a 3DS verification step.
If unauthorized transactions are discovered, report to police immediately and preserve evidence.
Conclusion: Speed Should Never Come at the Cost of Security
The iPhone 18 pre-order incident in Hong Kong is a warning signal. Hackers will strike during hype periods, merchant systems will face peak pressure at the most critical moments, and customer credit card data will be exposed to risk. At such moments, a merchant’s choices define its values.
Abandoning or reducing customer payment security to achieve business goals is not a shortcut—it is a liability. It may buy temporary conversion rates, but at the cost of legal liability, financial loss, and brand trust. Truly professional merchants choose security over traffic, and responsibility over speed, because they know: customers return not because checkout was two seconds faster, but because they believe their money is safe here.
HKMA guidelines have already clarified where liability lies. What remains is whether merchants are willing to put customer security before business goals. This is not just a compliance issue—it is a matter of integrity.