The “Beware of Scammers!” page is the Hong Kong Monetary Authority’s public anti-fraud education section, with its core component being a public list titled “Fraudulent Banking Websites, Phishing Emails, and Similar Scams”: The HKMA compiles press releases issued by various banks (and the HKMA itself) regarding fraud incidents into a large table organized by date, listing them row by row.Date of Release, Impersonated Organization, Type of Fraud (with link to press release), Website Involved. It is not a real-time alert system, but rather aAn alert archive that is continuously collected and regularly updated— Whenever a bank discovers a new fraudulent website, phishing email, or fake app, it issues a press release and adds the information to this list, which the public can access and verify at any time. A closer look at this list reveals several trends:
First, the update frequency is high, and the time span is long. The latest entries go as far as August 2026, with new ones added almost every week, and the archive extends back several years—scammers never ”stop.”
Second, almost all of Hong Kong's major banks have been targeted by counterfeiters. HSBC, Bank of China (Hong Kong), Standard Chartered, Bank of East Asia, DBS, Overseas-Chinese Banking Corporation, Shanghai Commercial Bank, Chong Hing Bank, Chiyu Bank, CITIC Bank International, Bank of Communications (Hong Kong), CCB Asia, ICBC Asia, ZhongAn Bank, Ant Bank, Furuong Bank, Dah Sing Bank, Fubon Bank, LiHui Bank… along with international private banks such as Julius Baer and Yingfeng, as well as the Bank of Singapore, have all appeared on the list of thoseImpersonationon the list.
Third, the range of fraud schemes is becoming increasingly ”comprehensive.” In addition to fraudulent websites and online banking login pages, there are also spoofed emails, phishing text messages and instant messages, fake mobile apps, and fake social media accounts and posts. For example, a fake WeChat account named ”CITIC Bank (International) Cross-Border Services” appeared under the name of CITIC Bank (International); there was a fake TikTok account for Bank of Singapore; DBS Bank’s fraudulent posts were disguised as Facebook ads; ZhongAn Bank had its name used to develop a fake app called ”ZA Repay”; and DBS Bank’s phishing emails used sender addresses disguised as seemingly official domains such as ”@dbsportal.com.”
Fourth, fraud has become ”assembly-line style.” On August 10, 2026, alerts regarding ”fraudulent websites and online banking login pages” for Shanghai Commercial Bank, Chong Hing Bank, Overseas-Chinese Banking Corporation, and Chi Yu Bank all pointed to the same set of domain names—carousellref[.]money-receive[.]fun cap (a poem) carousell[.]money-receive[.]fun ...all following the same path. The same set of fake login pages can be deployed in bulk simply by swapping in different banks” logos—this is a classic characteristic of ”industrialized phishing”: build the site once, then ”reuse” it across the entire industry.
Fifth, the list specifically displays URLs in a format designed to prevent accidental clicks. All URLs related to the case should be written as carousell[.]xxx This practice of replacing the dot with [.] The purpose of this approach is to prevent readers from falling into a trap after copying the text—they’ve even been extremely careful about the very act of ”exposing the villain.”