Apple Hong Kong's online checkout system contained a security gap that bypassed one-time password verification, enabling scammers to commit HK$25 million in fraudulent charges during a smartphone launch, with over 700 complaints filed in the first two days. The company allegedly omitted standard two-factor authentication to streamline user experience, potentially shifting fraud liability from banks to the merchant.