Hong Kong Warns of AI-Built Fake E-Visa Sites

Hong Kong's privacy commissioner warned on August 4 that suspected fraudulent e-visa sites had generated 16 complaints or inquiries in three months. Victims submitted passport details and other personal data before paying fees, with reported losses ranging from more than HK$300 to more than HK$1,700. The commissioner said AI is making imitation portals harder to distinguish from official government services.
Hong Kong's Office of the Privacy Commissioner for Personal Data warned on August 4 about suspected fraudulent e-visa websites that collect identity information and application fees while imitating official government portals. The office said it received 16 related complaints or inquiries over the previous three months.
People reached the sites through search results while looking for visas, electronic travel authorizations or arrival cards. According to the regulator, victims submitted names, gender, nationality, passport numbers and dates of birth before paying application fees and surcharges. Reported losses in individual cases ranged from more than HK$300 to more than HK$1,700.
Search placement is part of the risk
The regulator's warning is not limited to misspelled links sent through phishing messages. It says people mistook results surfaced by search engines for official application channels. Fraudulent addresses may closely resemble genuine government domains while adding letters, numbers or subtle spelling changes.
Privacy Commissioner Ada Chung told Commercial Radio on August 5 that scammers are using AI to build the imitation portals, making them substantially harder to distinguish from legitimate sites. VnExpress also reported that comparison images released by the office showed fake versions of portals for Canada, Thailand and the United Kingdom.
What applicants should verify
The PCPD advises travelers to inspect the complete URL and avoid assuming that the first search result is an official service. Applicants should instead follow links published by the relevant consulate-general or representative office in Hong Kong. Unexpected calls, emails or messages seeking additional information should be treated cautiously.
For data and security teams, the incident is a reminder that generative tools can lower the cost of producing convincing interfaces without changing the underlying fraud pattern. Controls that rely only on visual inconsistency are therefore weaker than domain verification, trusted-link distribution and rapid reporting or takedown processes. That is LDS interpretation; the confirmed event is the regulator's 16-case warning and the associated exposure of passport and payment data.
Key Points
- 1Hong Kong's privacy regulator received 16 complaints or inquiries about suspected fraudulent e-visa sites over three months.
- 2Victims provided passport and identity details before paying fees, with individual reported losses from more than HK$300 to more than HK$1,700.
- 3The regulator advises applicants to use links from consulates or representative offices instead of trusting search-result placement.
Scoring Rationale
The warning documents an active identity-and-payment fraud pattern involving passport data and AI-assisted imitation sites. Its practitioner relevance is concrete, though the public evidence describes a bounded Hong Kong complaint set rather than a measured global campaign.
Sources
Primary source and supporting public references used for this report.
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems