Apple Hong Kong's credit card fraud problem
The police on Monday noted that a security gap in the online checkout process—which bypassed the standard requirement for one-time verification passwords—has enabled scammers to ring up HK$25 million in fraudulent charges during the launch of Apple's latest smartphone series.
During the initial two days of pre-orders over the weekend, police had already logged complaints from more than 700 individuals involving roughly HK$14.7 million, with the single largest case reaching approximately HK$114,000.
Apple Hong Kong has a long history of ignoring fraud prevention measures in their credit card checkout procedures. Some years ago, I, too, was victim of a similar fraudulent charge from Apple Hong Kong in the high 5 digits when my credit card was stolen out of my wallet out of a Hong Kong public swimming pool locker. In my case, the card was a UK-issued Chip and PIN American Express card. Despite a PIN being required for purchase, Apple Hong Kong decided to accept the card anyway. They either did not ask for the PIN or accepted an incorrect PIN. Compare this to the average 7-11 in Hong Kong which will request the pin for a Chip and PIN card for even a tiny HK$8.00 transaction.
However, investigators identified a significant procedural gap in the online checkout system, which did not require customers to enter a one-time password via SMS or undergo two-factor authentication.
Now, I can't be entirely sure why they do this, but knowing Apple I would not be surprised if it is intentional. Apple cares very deeply about user experience and interrupting their carefully designed purchase flow asking for a PIN or redirecting to a bank's (ugly) two-factor SMS verification page is something the would probably not want to do.
In the credit card industry, what typically happens when a merchant opts out of a security feature is that liability for the fraudulent transactions moves from the bank to the merchant. This is supposed to incentivize merchants to use security features. I wouldn't be surprised if a company as large and rich as Apple was able to negotiate a special deal for itself.
The problem from a consumer perspective is not so much the liability but the time cost and inconvenience incurred when a company like Apple opts out of these security features and that results in fraudulent transactions that customers have both notice and spend time dealing with. And as any Hong Kong will tell you, there is no punishment worse than having to call the customer support of a Hong Kong bank.