Cybersecurity and Scam Prevention Tips for Customers

To help protect your personal information, please stay vigilant against online scams and fraudulent messages claiming to be from CLP. When updating or submitting personal information, applying for services or making payments, always use CLP's official channels.

For example: CLP's official website, CLP App, Our Customer Service Centres

Important Reminder

Cybercriminals are constantly evolving their tactics. Fraudsters may impersonate CLP through fake websites, SMS messages, emails, social media accounts or even by pretending to be CLP staff, with the intention of obtaining your personal information or money.

CLP reminds customers to remain vigilant at all times and never disclose sensitive or personal information to third parties, including passwords, one-time passwords (OTPs), credit card details or bank account information.

1. Common Scam Tactics

  • Fake Websites
    Fraudsters may create websites that closely resemble CLP's official website and claim that you have an outstanding bill, refund or reward waiting to be collected. These websites are designed to trick you into providing account credentials or credit card information.
  • Fraudulent SMS Messages and Emails
    These messages often contain links and use urgent language such as "Pay Immediately", "Your Account Will Be Suspended" or "Overdue Payment Penalty" to pressure customers into taking action without verifying the authenticity of the message.
  • Impersonation of CLP Staff
    Fraudsters may pretend to be CLP employees and claim to offer investment opportunities, refund services or customer promotions, while requesting personal information or payment.
  • QR Code Scams
    Fraudsters may use QR codes to direct customers to fraudulent websites or payment pages in order to obtain personal information, credit card details, or money. Certain CLP promotional campaigns or redemption programmes may involve the use of QR codes. Before providing any personal information or proceeding with any transaction, customers should verify that the website address belongs to an official CLP domain and confirm its authenticity.

2. How to Identify Suspicious Messages

If you receive a suspicious message, stay calm and consider the following:

  • Does it ask for passwords, one-time passwords (OTPs), credit card details or other sensitive information?

  • Does it contain a link, attachment or QR code?

  • Does it request immediate payment, fund transfers or urgent action?

  • Does it offer rewards, refunds or special promotions?

  • Does the sender's information differ from the organization it claims to represent?

  • Does the message contain numerous spelling mistakes, grammatical errors or unusual wording?

If the answer to any of the above is "Yes", exercise caution. Do not respond hastily and verify the authenticity of the message through CLP's official channels first.


3. How to Verify Whether a Message Is from CLP

CLP only publishes communications through the following official domains:

  • https://www.clp.com.hk

  • https://e.clp.com.hk

  • https://clp.to

  • https://web.clp.com.hk

  • CLP will only send SMS messages using the registered SMS Sender ID #CLP.

  • Emails from CLP will only be sent from the following official email domains: @clp.com.hk, @mail.clp.com.hk, @info.clp.com.hk

  • CLP will never ask customers to disclose passwords, credit card information or credit card security codes (CVV) for identity verification or account recovery purposes.

  • CLP will also not proactively send payment links via SMS, email or websites for customers to make payments.
CLP official domains
CLP SMS sender ID
CLP email domains
CLP Fraud Facebook post (771 x 424 px) - 12

4. Beware of Impersonation of CLP Staff and Other Fraudulent Activities

  • CLP employees will never contact customers through social media to promote investment opportunities or request personal information or payment.

  • Please remain vigilant and do not trust unsolicited investment offers from unknown sources.

  • If you wish to verify the identity of a CLP employee, please contact the CLP Customer Service Hotline at 2678 2678.

5. Everyday Cybersecurity Tips

  • Use strong passwords and update them regularly.

  • Access CLP services only through the official CLP website (www.clp.com.hk) and the CLP App.

  • Do not click on suspicious links or download attachments from unknown sources.

  • Keep your device operating systems and applications up to date.

  •  Never share passwords, one-time passwords (OTPs), credit card details or payment information with anyone.

  • Avoid entering personal information when using unsecured public Wi-Fi networks.

  • If you receive a suspicious message, stay calm and seek advice from family members or trusted friends before taking any action.

6. What to Do If You Suspect You Have Been Scammed

If you have provided personal information, passwords, credit card details or made payment through a suspicious website or to an unknown individual, you should take the following actions immediately:

  1. Change your passwords.
  2. Contact your bank or credit card issuer.
  3. Keep copies of relevant messages and screenshots as evidence.
  4. Report the incident to the Police.

If you would like to verify whether a message was issued by CLP, or confirm the identity of a CLP employee, please contact the CLP Customer Service Hotline at 2678 2678.


If you have any doubts about a message claiming to be from CLP, always verify its authenticity first. Do not click on links, provide personal information or make payments before confirming that the communication is genuine.

Back to top