HomeSecurityUSA: Chinese hackers breached up to 115 million payment cards

US: Chinese hackers breached up to 115 million payment cards

Chinese hackers have orchestrated one of the most devastating payment card fraud operations in recorded history, potentially compromising up to 115 million payment cards across America between July 2023 and October 2024.

See also: Chinese hackers attack Windows systems with Ghost RAT and PhantomNet

Chinese payment card hackers

The operation represents a fundamental paradigm shift in financial cybercrime, combining advanced SMS phishing techniques with strategic exploitation of digital wallet systems to bypass traditional fraud detection mechanisms.

The criminal enterprise emerged in early 2023 as an evolution of simple package delivery scams that had previously targeted services such as Royal Mail during the COVID-19 pandemic. Unlike their predecessors, these Chinese-speaking threat actors developed a systematic approach that converts stolen payment card credentials into tokenized assets within the Apple Pay and Google Wallet ecosystems. This innovative methodology effectively bypasses existing security frameworks that monitor direct card usage patterns, creating an entirely new category of financial crime.

The scale and complexity of the operation became apparent through extensive monitoring of more than 32,094 distinct USPS-themed smishing domains deployed during the campaign period. SecAlliance analysts identified the criminal ecosystem operating with the efficiency and scale of legitimate software-as-a-service businesses, with estimated economic losses reaching into the billions of dollars.

See also: China's Salt Typhoon hacked the US National Guard

The investigation uncovered an extensive infrastructure that combines SMS, RCS, and social engineering via iMessage with real-time multi-factor authentication bypass capabilities. The investigation documented the operational evolution from primitive scams to sophisticated platforms , fake e-commerce businesses, and a recent expansion into stock market takeover schemes.

US: Chinese hackers breached up to 115 million payment cards
US: Chinese hackers breached up to 115 million payment cards

The main threat actor, operating under the alias “Lao Wang,” founded what appears to be the first successful smishing platform focused on digital wallets, which subsequently spawned a diverse ecosystem of threat actors, including Chen Lun, PepsiDog, Darcula , and others who have contributed unique capabilities while targeting different market segments globally.

The criminal organization’s technical infrastructure demonstrates remarkable sophistication through their “Lighthouse” platform, introduced in August 2024 as a significant advancement over previous “v1” phishing kits. The platform incorporates comprehensive defense capabilities, including geofencing mechanisms that restrict access to targeted geographic areas and mobile user enforcement ensuring that only mobile devices can interact with phishing pages.

The phishing kit’s architecture uses sophisticated countermeasures designed to evade detection and analysis. The system blocks IP addresses from known hosting providers, security vendor domains, and Tor exit nodes, and uses a distributed architecture that separates phishing interfaces from back-end data collection systems . This separation provides resilience against takeover attempts and allows for rapid scaling to multiple targeted brands without requiring extensive code modifications.

See also: Chinese group 'Earth Lamia' targets multiple industries

The key innovation lies in the systematic exploitation of digital wallet provisioning processes. Once payment card credentials are collected, malicious actors can manipulate and use them effectively within digital wallet ecosystems.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS