Reports from users in Shaanxi, Gansu, and Guangdong indicate their Meituan accounts were hacked from distant locations without their knowledge, with all thefts utilizing the Meituan Monthly Pay feature and exploiting a no-password payment setting for amounts under 500 yuan.
Mr. Quan, a user from Zhangye, Gansu, saw his account charged via Monthly Pay for approximately 2,475 yuan near midnight on July 21, used to purchase multiple group-buying vouchers. "I didn't notice at all until around 1,500 yuan was stolen again on July 24," he said. He didn't get a text alert from Meituan for the July 24 charge but did receive a risk warning from his bank via Postal Savings Bank credit card, which halted the transaction. Opening the bank app, he saw "Meituan Special Invitation" and then checked his Meituan account around 5 a.m., discovering six unredeemed vouchers. He manually canceled them, recovering the 1,500 yuan loss from July 24. However, the five vouchers stolen on July 21 had already been fully redeemed and were unrecoverable.
Screenshots Mr. Quan shared show the five redeemed vouchers were purchased between 12:00 a.m. and 12:25 a.m. on July 21, with redemption times from 11:39 a.m. to 8:29 p.m. that day. All were labeled "Beef******" and redeemed in locations including Beijing, Nanjing, Nantong, and Yiwu.
Mr. Wu from Wuzhou, Guangxi, faced a more intense attack. Between 2:35 a.m. and 2:43 a.m. on July 23, his account generated four consecutive orders via Dianping and Meituan, all for group-buying vouchers from a "Beef****** Store" in Jinhua, Zhejiang, totaling 1,669.47 yuan. The vouchers cost 456.59 yuan, 377.88 yuan, 378 yuan, and 457 yuan respectively. All four were paid through Meituan Monthly Pay, with one order through Dianping and three through Meituan. The Monthly Pay bill showed the entire amount added to his August bill, due on August 8. Although Mr. Wu was in Guangxi, the vouchers were fully redeemed in Jinhua. His refund requests for all four orders were rejected by the platform, with only a "Refund Request Denied" message. He filed a police report with the Datang Police Station in Wuzhou, receiving a receipt confirming the report on July 24 at 6:10 p.m., with the case noted as "under further investigation."
Mr. Xu from Weinan, Shaanxi, experienced a similar situation. Around 3:30 a.m. on July 12, his Monthly Pay was used for four consecutive orders totaling about 1,800 yuan, all for vouchers from "Beef******" stores in Xi'an. He said he had enabled small-amount no-password payments with a limit under 500 yuan, and each theft was under that threshold. "On July 22, I suddenly got a Monthly Pay repayment reminder and after paying one, I noticed there were 11 installments left, which is when I realized something was wrong," Xu explained. He was in Weinan while the vouchers were redeemed in Wenzhou, Hangzhou, and Beijing. He reported the case to local police, who have not yet responded regarding filing a formal case.
On July 28, a reporter contacted Meituan customer service on behalf of affected users. The representative stated that the redeemed vouchers could not be refunded, and the platform believes the users may have accidentally clicked malicious links, leading to virus infection and remote control of their accounts. Obtaining detailed backend information for the stolen orders requires a judicial investigation process.
Consumers are advised to regularly check and manage their "No-Password Payment/Auto-Debit" settings. On Alipay, go to 'My' – 'Settings (gear icon)' – 'Payment Settings' – 'Auto-Renewal/No-Password Payment'. On WeChat, go to 'Me' – 'Services' – 'Wallet' – 'Payment Settings' – 'Auto-Renewal'.
Consumer protection authorities urge caution when enabling auto-debit features. Beyond frequent small public services, be careful when subscribing to memberships, travel, or games with auto-debit (no-password payment), especially regarding first-month discounts leading to auto-renewal. Periodically clean up no-password authorizations and auto-renewal items in payment apps. Also, develop a habit of regularly checking bank, WeChat, Alipay, telecom, and utility bills for any unusual charges, and address them promptly to prevent prolonged unauthorized deductions.
Recently, the National Development and Reform Commission, the State Administration for Market Regulation, and the Cyberspace Administration of China jointly issued the "Internet Platform Price Behavior Rules." Article 20 stipulates that when offering no-password payment services, platform operators and in-platform merchants must prominently display relevant options to consumers and provide convenient cancellation methods.
In response to the chaos surrounding no-password payments, the Payment and Clearing Association of China recently released a "Recommendation on Strengthening the Security Management of 'No-Password Payment' Services." It advocates that payment service providers enhance security management by, for example, eliminating default activation and providing a one-click cancellation function for no-password payments. Additionally, providers should use risk modeling and big data analysis to improve risk control capabilities, promptly intercepting or requiring secondary verification when transaction patterns deviate from a user's normal habits, thereby preventing fund losses.
Comments