Risk Horizon
Live

Intelligence generated by AI from public regulatory sources. Not investment or regulatory advice. Verify before relying on any output.

IncreasingMedium2026-07-06

HKICL flags multiple fraudulent FPS impersonation domains

Banking SupervisionOtherGeneral RegulatoryPaymentsHong KongConf: High
Regulatory Event

HKICL identified several fraudulent domains impersonating it, targeting FPS users with fake refund and transaction support services.

Analysis

Multiple lookalike domains (companyhk.xyz, hkiclfps.com and variants) were flagged as phishing sites soliciting personal data. The proliferation of domains signals scaled infrastructure behind FPS-targeted fraud.

Relevance

Scaled phishing infrastructure against FPS increases fraud losses and regulatory scrutiny on payment participants.

Required Action

Action Required

Expand domain takedown coordination, sanction fraud watchlists, and refresh customer scam warnings on FPS channels.

Justification

Multiple simultaneous fraudulent domains demonstrate industrialised payment fraud requiring escalated controls.

Control Commentary

Escalate monitoring of FPS-branded lookalike domains and coordinate with HKICL/HKMA on takedowns. Review customer-facing scam warnings and internal fraud detection thresholds for FPS transactions.

Source

HKICL has recently noted fraudulent websites at companyhk.xyz, hkiclfps.com, hkicl-fps.cc.cd, fps-hkicl.ccwu.cc and fps-hkicl.cc.cd purported to be from the HKICL. The fraudulent websites imitate as Buyer Online Protection to provide services including refund to buyer, unauthorised online transaction reporting, and online transaction support for FPS payment.

RH-2026-07-02-006