Look, the fraud itself isn't the regulatory story here. Cheung Kwok-keung's reporting puts the number at almost 700 unauthorised transactions, HK$8,000 to HK$10,000 apiece, all charged through Apple's wallet infrastructure to cards issued by Hong Kong banks. Lawmaker Johnny Ng wants Apple explaining itself. But Apple isn't the regulated entity in this chain (it's the rail, not the bank), and the HKMA's Banking Conduct Department doesn't supervise device wallets. It supervises the card issuers whose authorised institutions have to run the fraud-detection and customer-notification obligations under the Supervisory Policy Manual's TM-E-1 technology risk module, regardless of where the compromise actually originated.
That's the arithmetic that matters for a compliance head reading this Monday: 700 reports in one window is a pattern, not 700 isolated disputes, and under TM-E-1 an authorised institution has to treat a clustered fraud signal as a control failure to investigate and report, not a customer-education exercise. The banks issuing the "check your statement" warnings are the ones who'll need to show the HKMA where the leak sits, whether that's a compromised merchant token, a provisioning weakness in the wallet enrollment flow, or something upstream of both. Separately, the SFC's September 11 order barring Mok Cheuk Ling from the industry for 42 months is a routine licensing action, no read-through here. The next date that matters is whichever bank first has to file a fraud incident disclosure with the HKMA under TM-E-1, and none had as of this writing. Until one does, the obligation sits with the card issuers, not the platform everyone's blaming.