How Chinese Smishing Syndicates Stole Over 100 Million US Payment Cards: The New Digital Wallet Fraud

Listen to this Post

Featured Image
In a chilling development, Chinese cybercriminal groups have orchestrated one of the largest and most sophisticated payment card fraud campaigns targeting the United States. Between July 2023 and October 2024, these syndicates reportedly compromised up to 115 million payment cards, leveraging cutting-edge smishing (SMS phishing) techniques combined with digital wallet exploitation to bypass traditional fraud defenses. This massive breach has caused billions of dollars in financial losses and signals a new era of fraud that weaponizes social engineering, real-time multi-factor authentication (MFA) bypass, and phishing-as-a-service platforms.

Massive Scale of the Fraud Operation

Security researchers at SecAlliance have revealed the staggering scale of this campaign. Chinese-speaking criminal groups have used SMS, RCS, and iMessage messages as entry points, tricking victims with fake notifications about package deliveries, tax refunds, toll payments, or vehicle registrations. Victims are lured to mobile-optimized phishing pages requesting sensitive personal and payment information. These pages then collect payment card details and one-time passwords (OTPs) in real time, allowing attackers to add stolen cards to digital wallets like Apple Pay and Google Wallet on devices they control. This method bypasses traditional transaction checks since the digital wallet provisioning process authenticates via MFA.

Evolution of Smishing and Phishing Infrastructure

Initially simple scams, these attacks have rapidly evolved into complex, phishing-as-a-service platforms run by groups such as the one led by a developer known as “Lao Wang.” His Telegram channel “dy-tongbu” serves as a marketplace for advanced phishing kits designed to evade security researchers, employing geofencing, IP blocking, and strict mobile-device restrictions. Since its launch in early 2023, this marketplace has grown from thousands to over 4,400 members. Inspired by this model, many other Chinese-speaking groups have launched similar platforms focused on exploiting digital wallets.

Sophistication Beyond Traditional Fraud

Unlike traditional card-not-present fraud, where stolen numbers are used for online purchases subject to fraud detection, this campaign’s core innovation is the immediate provisioning of stolen cards into digital wallets. Once provisioned, the cards can be used for contactless payments at physical stores, online shopping, and even ATM withdrawals in some locations without a physical card. Some threat actors have even established malicious merchant accounts with trusted payment processors like Stripe and PayPal to further monetize their thefts.

Expansion into New Criminal Ecosystems

By August 2024, the scope of these campaigns broadened with the rise of fake e-commerce websites that lure actively searching consumers via sophisticated advertising on Meta, TikTok, and Google. Additionally, a new criminal supply chain emerged, selling devices pre-loaded with stolen card data, indicating highly organized downstream networks specializing in monetizing these digital wallet compromises. The latest evolution targets the financial sector with phishing operations aimed at taking over brokerage accounts globally rather than merely stealing payment cards.

What Undercode Say:

This report unveils a fundamental transformation in payment card fraud, driven by the weaponization of mobile-based social engineering and digital wallet technologies. The ability to bypass MFA in real time while harvesting payment credentials shows the attackers’ deep understanding of the digital payments ecosystem and security infrastructure weaknesses. The reliance on phishing-as-a-service platforms signals that these fraud tactics are not isolated but increasingly commodified, allowing wider access to sophisticated attack tools.

The evolution from generic SMS scams to multi-layered campaigns involving fake e-commerce shops and brokerage account takeovers reveals the dynamic nature of cybercrime in adapting to both technological advances and shifting consumer behaviors. By investing in elaborate defensive mechanisms such as geofencing and mobile device enforcement, these syndicates are raising the bar for security research and law enforcement efforts, complicating detection and takedown operations.

Furthermore, the use of legitimate payment processor platforms for money laundering and cashing out stolen funds indicates a broader infiltration of the financial ecosystem by criminal enterprises. The emergence of downstream networks selling pre-loaded devices highlights the development of specialized roles within the cybercrime economy, reminiscent of traditional organized crime structures but in the digital realm.

This campaign underscores the urgent need for innovation in fraud prevention, particularly focusing on the security of digital wallet provisioning and real-time transaction monitoring. The rapid growth of digital payment adoption, accelerated by consumer convenience, has opened new avenues for exploitation. Payment providers, regulators, and cybersecurity firms must collaborate closely to build more robust multi-factor authentication solutions resistant to real-time bypass and to improve the transparency and accountability of merchant onboarding processes.

For consumers, heightened awareness of smishing tactics and cautious interaction with unsolicited messages remain critical. As attackers perfect their social engineering narratives around trusted services like delivery notifications and tax refunds, educational efforts need to focus on identifying suspicious communication and verifying requests through official channels.

In summary, this fraud operation is a clear signal that cybercriminals are evolving with the times, turning emerging payment technologies into lucrative crime tools. It challenges the cybersecurity community to rethink traditional defense models and adapt to increasingly mobile and real-time attack methods.

🔍 Fact Checker Results

✅ The scale of card compromises between 12.7 million to 115 million cards is supported by independent security research.
✅ The exploitation of Apple Pay and Google Wallet digital tokens in fraud is well-documented in recent cybersecurity reports.
❌ No evidence supports claims of involvement by specific governmental entities; these are criminal syndicates.

📊 Prediction

Looking ahead, we can expect smishing campaigns to continue evolving alongside mobile payment technologies. Criminals will likely innovate new real-time MFA bypass techniques and target emerging digital wallet platforms beyond Apple Pay and Google Wallet. The rise of fake e-commerce ecosystems funded by social media advertising suggests phishing attacks will become more personalized and harder to detect. Financial institutions will face increased pressure to enhance authentication methods and develop AI-driven behavioral analysis tools to spot anomalous wallet provisioning and payment activity. Without rapid, coordinated action across technology providers and regulators, the financial losses and consumer impact from these schemes could rise exponentially in the next few years.

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: www.infosecurity-magazine.com
Extra Source Hub:
https://stackoverflow.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon