How Scammers Use SMS: Hong Kong & Taiwan Cases, Consumer Defences, and What Providers Can Do

On this page
  1. How scammers use SMS
  2. Hong Kong: three representative SMS fraud types
  3. Taiwan: three representative SMS fraud types
  4. Consumer tips and official channels
  5. What SMS providers can do
  6. Concrete detection example (defensive only)
  7. Conclusion
  8. Sources / References

Key takeaways

  • SMS fraud (smishing) often impersonates banks, government, couriers and telcos, using urgency and a familiar sender name to lower scepticism.
  • Hong Kong Police figures for 2025 show 43,212 deception cases and about HK$8.1 billion in losses; phishing cases fell to 1,093 (−60% year on year).
  • Taiwan’s NCC has, since 18 November 2024, required commercial SMS that include URLs or phone numbers to be verified by telecom operators; police have also broken up abuse of bulk-SMS platforms and fake base stations.
  • Consumers should check official Sender IDs, avoid suspicious links, and verify via official channels: Hong Kong 18222 / Scameter+; Taiwan 165 / 165dashboard.tw.
  • Rigorous A2P SMS providers should run Detect→Hold→Review→Block/Release across KYC/KYB, content and domain reputation, traffic anomalies and sender identity.

How scammers use SMS: Hong Kong and Taiwan cases, consumer defence, and what providers can do

When you receive a text that says your account needs “immediate verification,” you probably glance at the sender name first. That reflex is exactly what smishing (SMS phishing) exploits: the message sits in the same inbox as family chats, costs little attention, and urgency squeezes out doubt.

For brands, the damage is not only customer loss. Texts that impersonate you erode trust and make real OTPs and delivery notices harder to believe. This article summarises publicly documented Hong Kong and Taiwan patterns, consumer defences and reporting channels, and what an SMS provider (A2P SMS / enterprise SMS API) can do to reduce platform abuse.

How scammers use SMS

Public alerts repeatedly show impersonation of banks/payments (fake charges, account suspension), government/anti-scam units (asset recovery), couriers/post (failed delivery, lost-parcel compensation), and telcos/platforms (SIM misuse, unclaimed rewards).

Typical layers include:

  1. Sender ID spoofing — making the message look like a bank or known brand. After Hong Kong’s SMS Sender Registration Scheme, fraudsters may still use non-# names, numeric CLIs, or local illegal radio equipment. Even a # prefix is not a licence to click links or hand over passwords.
  2. Malicious links or callback numbers — harvesting credentials, card data or OTPs.
  3. Urgency and loss framing — inflated “already deducted” amounts and deadlines.
  4. Secondary scams — impersonating anti-scam officers or solicitors to “help recover” funds from people already victimised.

SMS lowers scepticism because it has long carried OTPs and bank alerts; space is short, so calls to action dominate; and no app install is required. The text is often only the opener.

SMS is not the root problem — abused identity and trust are. Legitimate businesses still need SMS for authentication and service notices.

Hong Kong: three representative SMS fraud types

1) Bank / post impersonation — fake charges and failed delivery (Oct 2025)

On 15 October 2025, ADCC warned of texts impersonating HSBC, Hongkong Post and others, claiming automatic renewals/charges or delivery failure, then steering victims to fake hotlines or sites. Use Scameter+ and Anti-Scam Helpline 18222. ADCC also published a compilation of fraudulent SMSs on 21 October 2025. Alert · Compilation

2) SF Express HK — lost-parcel compensation (Jul 2025)

On 7 July 2025, ADCC described SFHK-impersonating texts asking recipients to call back, then offering compensation via fake “claims/UnionPay staff,” pushing victims onto fraudulent sites to raise transfer limits and surrender banking credentials and OTPs. Verify parcels in the official app. Alert

3) Fake ADCC / HKMA solicitors (Apr 2025)

On 16 April 2025, HKMA and Police warned of messages claiming ADCC/HKMA had appointed solicitors to recover frozen or defrauded funds. They will not contact the public on personal finances or commission solicitors for recovery. ADCC’s registered Sender ID is #ADCC18222; official texts contain no hyperlinks, only 18222. HKMA · ADCC

Selected Hong Kong figures and policy

  • 2025 deception overall: 43,212 cases (−2.9%), losses about HK$8.1 billion (−11.3%); phishing 1,093 cases (~−60%). ADCC statistics
  • Earlier phishing series (Security Bureau LegCo reply, 7 May 2025): 2023 — 4,322 cases / HK$102.4m; 2024 — 2,731 / HK$53.5m; Jan–Feb 2025 — 242 / HK$4.9m. Press release. Label the vintage when you reuse numbers.
  • SMS Sender Registration Scheme: OFCA scheme live since 28 December 2023; registered senders use # Sender IDs; unregistered # traffic is blocked; opened to all sectors from February 2024. OFCA SSRS

Taiwan: three representative SMS fraud types

1) Bulk-platform abuse — fake loan texts (sent Apr–May 2024; announced Jul 2025)

Criminal Investigation Bureau accounts (via press, 25 July 2025) describe ~160,000 fake-loan SMS messages in April–May 2024 used to harvest mule accounts; about 9 victims and over NT$1 million transferred; 7 arrested. Avoid unknown links and never hand over bank accounts for “loan packaging.” Check 165dashboard.tw or call 165. Epoch Times report

2) Fake base stations (2025)

CIB briefings around 18 August 2025 describe vehicle-borne fake base stations blanketing a small area and blasting phishing SMS (including “cash handout” lures). Public figures cited 6 sites seized from 13 Jan to 21 Jul 2025 (vs 2 in 2024), about 78 victims and over NT$5 million in losses for related methods. Treat odd landline/0800/alphanumeric senders tied to hot policies as suspect; call 165. CNA via CTS

3) Fake telco + fake 165 via messaging apps (2024)

A Taoyuan Police awareness case (published 3 Nov 2024) describes a telco-impersonation call “transferred to 165,” then LINE video “statements” and ID uploads. Hang up, then dial 165 yourself. Police will not ask you to upload ID cards or surrender assets over LINE. TYPD

HK vs TW — evidence-based, not forced

LensHong KongTaiwan
ContentBank charges, post/courier, fake recoveryFake loans, fake telco/165, policy lures
Sender controlsOFCA # Sender ID registryTelco verification/whitelist for commercial SMS with URLs/numbers (from 18 Nov 2024)
Channel abuse# misuse blocked; local fake-base-station bypasses reportedBulk platforms abused; mobile fake cells in casework
Public checks18222, Scameter+, OFCA registry165, 165dashboard.tw

If you message both markets, align Sender and content compliance per jurisdiction.

Consumer tips and official channels

Do not verify using numbers or links inside a suspicious text. Prefer official apps/sites and saved hotlines. OTPs belong only in flows you started.

Hong Kong: Anti-Scam Helpline 18222; Scameter/Scameter+; OFCA SSRS.
Taiwan: 165 (emergencies 110); 165dashboard.tw. NCC commercial-SMS URL/number verification from 18 Nov 2024: LTN, Taipei Times.

What SMS providers can do

Account (KYC/KYB)

Verify the business and operators; start new accounts on low limits; support roles and optional maker-checker. For Hong Kong # Sender IDs, help clients through OFCA registration and secure-network expectations.

Message

Score phishing-like urgency + non-official domains without banning legitimate notices; check URL reputation, young lookalike domains, and opaque public shorteners; raise risk when Sender and brand claims diverge.

Traffic

Watch day-two blast volume, sudden recipient spikes, and geo/number-range drift; freeze compromised API keys quickly.

Sender identity

Hong Kong — SSRS with # prefix (live since 28 Dec 2023). Taiwan — commercial SMS with URLs/numbers must match telco-verified registrations (from 18 Nov 2024).

Response playbook

Detect → Risk Score → Hold → Human Review → Block/Release → Investigate → Report.
Anti-fraud must not silently drop every legitimate enterprise message that contains a link; allowlists and pre-approved templates protect good traffic.

Mapping to a platform like UFOSEND

From the public UFOSEND SMS page, confirmed capabilities that support a trust posture include: OFCA # Sender ID assistance and secure-network help; direct carrier routes with auditable DLR; TLS 1.2+ API, IP allowlists, webhook HMAC; DNC/unsubscribe suppression; dashboard permissions and send logs.

Automated phishing holds and new-account blast pauses are framed here as industry best practices rigorous A2P providers should operate — ask vendors about review queues and false-positive SLAs. Use tracked links only to owned, approved landing pages. Related reading: OFCA Sender ID guide, phishing SMS, OTP/SMS pumping protection, finance vendor due diligence.

Concrete detection example (defensive only)

Signals: API account 2 days old; ~50,000 recipients; “account suspended — verify now” copy; newly registered lookalike domain. Stack account age, blast size, credential-harvest language, domain age, missing high-trust Sender registration, and list/use-case mismatch.

Action: auto-Hold → raise score → human review (authority, use case, landing-page control) → Block and investigate key leakage if unverified → report when warranted. Long-standing clients with stable domains should use allowlists/templates so genuine service notices are not false-positive casualties.

Conclusion

SMS remains a dependable channel for OTPs and service alerts. The failure mode is forged identity, abused trust, and platforms that will not interrupt misuse. Consumers, brands, telcos, regulators and providers each own a link in that chain.

If you are reviewing Hong Kong/Taiwan SMS compliance and send governance, contact us to discuss # Sender ID, API onboarding and enterprise send controls.

Sources / References

  1. OFCA, SMS Sender Registration Scheme (since 2023-12-28) — https://www.ofca.gov.hk/en/consumer_focus/guide/hot_topics/ssrs/
  2. OFCA, Scheme open to all sectors, 2024-02-21 — https://www.ofca.gov.hk/en/news_info/press_releases/index_id_2339.html
  3. ADCC, Scam Situation in Hong Kong (2025 stats) — https://www.adcc.gov.hk/en-hk/statistic.html
  4. HKSAR press release, LCQ7 Combating phishing, 2025-05-07 — https://www.info.gov.hk/gia/general/202505/07/P2025050700292p.htm
  5. ADCC, HSBC / Hongkong Post / Douyin phishing SMSs, 2025-10-15 — https://www.adcc.gov.hk/en-hk/alerts-detail/alerts-1978309482792943617.html
  6. ADCC, Compilation of Fraudulent SMSs, 2025-10-21 — https://www.adcc.gov.hk/en-hk/alerts-detail/alerts-1980544509240999938.html
  7. ADCC, Fraudulent SFHK SMSs, 2025-07-07 — https://www.adcc.gov.hk/en-hk/alerts-detail/alerts-1942080164619333634.html
  8. HKMA, Phishing messages reminder, 2025-04-16 — https://www.hkma.gov.hk/eng/news-and-media/press-releases/2025/04/20250416-3/
  9. ADCC, Will not commission solicitors, 2025-04-16 — https://www.adcc.gov.hk/en-hk/alerts-detail/alerts-1912348976005840897.html
  10. Liberty Times, Commercial SMS verification from 18 Nov 2024, 2024-11-14 — https://www.taipeitimes.com/News/taiwan/archives/2024/11/14/2003826886
  11. Epoch Times (CIB briefing), 160k fake-loan SMS, 2025-07-25 — https://www.epochtimes.com/b5/25/7/25/n14560462.htm
  12. CNA/CTS, Fake base station phishing SMS, 2025-08-18 — https://news.cts.com.tw/cna/society/202508/202508182503758.html
  13. Taoyuan Police, Fake 165 ID-upload case, 2024-11-03 — https://www.typd.gov.tw/index.php?action=view&catid=551&id=362&pg=0
  14. NPA, 165 dashboard — https://165dashboard.tw/
  15. UFOSEND, Business SMS & SMS API — https://ufosend.com/en/sms/