SN

私人新聞日報Private News Daily

Private use only · Michael SoMichael So

本頁為 Michael So 私人自用,非公開發佈,亦非任何機構之產品。 This page is for the personal use of Michael So only. It is not a public release and is not a product of any organisation.

港聞Hong Kong

一周約50宗WhatsApp帳戶騎劫騙案 損失近2,000萬About 50 WhatsApp account hijacking scams per week, causing nearly 20 million in losses

星島日報 ·2026-10-02

警方過去一周接獲約50宗「WhatsApp帳戶騎劫」騙案,總損失近2,000萬港元。其中一宗受害人誤信「生意夥伴」訊息,轉帳200萬枚泰達幣,折合損失約1,500萬港元。In the past week, the police received about 50 cases of 'WhatsApp account takeover' scams, with a total loss of nearly HK$20 million. In one case, a victim was deceived by a message from a 'business partner' and transferred 2 million Tether coins, resulting in a loss of about HK$15 million.

辛正兒 - WhatsApp帳戶騎劫盛行 借口求轉帳莫衝動過數 | 社論

發佈時間:02:00 2026-10-02 HKT

過去一周,警方接獲約五十宗「WhatsApp帳戶騎劫」騙案,總損失近2000萬港元。其中一宗,受害人誤信「生意夥伴」訊息,轉帳200萬枚泰達幣,折合損失約1500萬港元。與此同時,香港家庭計劃指導會轄下上水婦女會亦發現其WhatsApp帳戶遭黑客入侵,須報警及通報私隱專員公署。兩則新聞並置,揭示一個殘酷現實:騙徒的技術門檻正在降低,而市民的防備意識卻遠遠追不上。

細看警方「守網者」拆解的騎劫流程,手法並不複雜--白撞訊息、假客服、假驗證流程、騙取八位數代碼、以另一裝置登入。整套劇本瞄準的不是系統漏洞,而是人的慣性。受害人收到「合作夥伴」轉帳要求,往往因信任關係而略過核實;收到「客服」指示,又因急於解決問題而順從輸入驗證碼。騙徒深諳人性:恐懼、信任、匆忙,都是比密碼更易攻破的缺口。

家計會事件更提醒我們,機構帳戶同樣脆弱。婦女會會員眾多,一旦帳戶被騎劫,騙徒便能以「官方」身份向會員發送訊息,索取個人資料或金錢。機構的聲譽,無形中成為騙徒的背書。事後道歉與檢討固然必要,但更重要的是事前防範--定期審查連結裝置、加強員工培訓、向會員發出清晰警示,缺一不可。

面對層出不窮的騙術,市民該如何自處?第一,對任何WhatsApp訊息保持戒備,不因對方是「熟人」而鬆懈;第二,當對方要求個人資料或輸入密碼驗證,應先拒絕、收線、冷靜,再循官方渠道核實;第三,凡未經證實真身而要求即時轉帳的訊息,一律不應答應,務必致電雙重核實;第四,下載防騙視伏APP,掌握最新騙案手法。

然而,單靠市民自救並不足夠。監管機構與通訊平台必須承擔更大責任。WhatsApp的「連結裝置」機制本是便利設計,卻被騙徒反覆利用,平台是否應加入更嚴謹的二次確認?電訊商能否攔截可疑的驗證碼轉發?銀行與加密貨幣錢包能否對異常大額轉帳增設冷靜期?這些問題,不能永遠停留在「呼籲市民小心」的層面,需要各界推動改變,以加強社會的防騙防火牆。

辛正兒

Xin Zheng'er - WhatsApp Account Hijacking Prevalent: Don't Impulsively Transfer Money Over Excuses | Editorial

Published time: 02:00 2026-10-02 HKT

Over the past week, the police received about fifty reports of 'WhatsApp account hijacking' scams, with total losses approaching HKD 20 million. In one case, the victim, mistakenly trusting a message from a 'business partner,' transferred 2 million Tether coins, resulting in a loss of about HKD 15 million. At the same time, the Sheung Shui Women's Association under the Family Planning Association of Hong Kong also discovered that its WhatsApp account had been hacked, requiring a report to the police and notification to the Privacy Commissioner. Placing these two news items side by side reveals a harsh reality: the technical threshold for fraudsters is decreasing, while public awareness and defensive measures are far behind.

Looking closely at the 'Internet Guardians' breakdown of the hijacking process by the police, the method is not complicated—sending a random message, fake customer service, fake verification process, stealing an eight-digit code, and logging in with another device. The entire script targets not system vulnerabilities, but human habits. When victims receive transfer requests from 'partners,' they often skip verification due to trust; when receiving instructions from 'customer service,' they comply by entering verification codes out of urgency to solve the problem. Scammers understand human nature well: fear, trust, and haste are all gaps easier to exploit than passwords.

The Family Planning Association incident further reminds us that institutional accounts are equally vulnerable. With many members in women’s associations, once an account is hijacked, scammers can send messages to members under the guise of being 'official,' requesting personal information or money. The institution's reputation, invisibly, becomes an endorsement for the scammers. While post-incident apologies and reviews are certainly necessary, what is even more important is prevention beforehand—regularly checking connected devices, strengthening staff training, and sending clear warnings to members are all indispensable.

Facing endless scams, how should citizens protect themselves? First, remain vigilant toward any WhatsApp messages and do not let your guard down just because the sender is a 'familiar person.' Second, when someone asks for personal information or to enter a password for verification, you should first refuse, hang up, stay calm, and then verify through official channels. Third, any message requesting immediate transfer of funds without verified identity should never be complied with; always double-check with a phone call. Fourth, download anti-fraud apps to stay informed about the latest scam tactics.

However, relying solely on citizens to help themselves is not enough. Regulatory agencies and communication platforms must take on greater responsibility. WhatsApp's 'linked devices' feature was originally designed for convenience, but it has been repeatedly exploited by fraudsters. Should the platform implement stricter secondary verification? Can telecom operators intercept suspicious verification code forwarding? Can banks and cryptocurrency wallets introduce cooling-off periods for unusually large transfers? These issues cannot forever remain at the level of 'urging citizens to be careful'; various sectors need to push for changes to strengthen society's anti-fraud firewall.

Xin Zheng'er

原文出處:Source: 星島日報 ↗