Hong Kong police link 1,503 fraudulent iPhone 18 orders to a gap in Apple's online checkout
Hong Kong's police chief says 1,503 iPhone 18 orders were placed with stolen cards because Apple's web checkout skipped verification. All were cancelled.
Hong Kong police have received 1,503 reports of new iPhones bought with stolen credit card details since the phones went on pre-sale in early September.
Commissioner of Police Joe Chow Yat-ming gave the figures after a Kowloon City District Council meeting on Tuesday 29 September, according to the Hong Kong newspaper The Standard. The unauthorised orders totalled more than HK$30 million, which AppleInsider converts to about 3.82 million US dollars. Chow said every one of the transactions has been cancelled, so cardholders, banks and Apple lost no money directly.
The Standard describes the phones as the iPhone 18. AppleInsider calls them the iPhone 18 Pro, which is the model Apple put on sale in September; the police figures as reported do not separate models.
How did the fraud work?
According to Chow, initial investigations traced the orders to a loophole in Apple's online checkout, under which identity and payment verification was reportedly waived for purchases made on the web. In practice, that meant no one-time password and no confirmation in a banking app, the two checks that normally stop a stolen card number being used on its own.
The syndicates hid their locations behind VPN services and entered false or incomplete delivery addresses. When Apple emailed to ask for clarification, they named public pick-up points and sent recruited runners to collect the phones. Chow said the force will pursue the syndicate, and that police have asked Apple to review its transaction process before another phone pre-sale next month. AppleInsider reports that he pointed to the iPhone Duo, due in October.
Apple has not commented publicly. Neither report says whether the gap has already been closed, or why verification was skipped.
Our take
The striking thing is where the police put the blame. Card fraud on a launch is routine; a police commissioner publicly attributing it to the retailer's own checkout is not. If the description is accurate, the weakness was not in the iPhone or in Apple Pay but in a web store that accepted a card number without the bank's second step. That is a choice a merchant makes, usually to reduce friction at checkout, and on a launch week it is a choice that invites exactly this.
The address step is the detail we would want Apple to answer. A delivery address that needs clarifying by email, followed by a request to collect from a public place, is the pattern every fraud team looks for. That it worked often enough to reach 1,503 reports suggests the follow-up was handled as customer service rather than as a fraud signal. Cancelling the orders protected the money. The reports do not say how many phones runners had already collected before that happened.
APPDOOK's view is that the timing of the police request is the useful part. The iPhone Duo goes on pre-order on 16 October at a price of 1,999 dollars, scarce and expensive enough to be worth stealing. It is already drawing criminals online, as we found when a fake iPhone Duo pre-order page turned out to run an iPhone exploit. For buyers in Hong Kong the practical point is reassuring: the reported transactions were all reversed. For everyone else it is a reminder to watch card statements around a launch, because a card stolen anywhere can be spent in a store that does not ask the bank to check.
Sources
Police logs 1,503 iPhone 18 card fraud reports worth over $30m, all transactions canceledThe Standard, 2026-09-29
Hong Kong police want Apple's help in stopping $3.8M iPhone 18 Pro fraudAppleInsider, William Gallagher, 2026-09-29
Reporting and images linked above belong to their respective publishers and are shown from their own servers. The analysis here is our own.





