The credit card statement is where a phishing attack stops being an inbox problem and becomes a household bill. In August, Taiwan’s Criminal Investigation Bureau recorded 505 phishing cases with NT$54.51 million in losses, according to CIB data cited by the Taipei Times. The loss figure rose 317% from a year earlier, and the cases included scammers impersonating Momo and Shopee.

For cardholders, the first sign often is not a drained bank account. It is an unfamiliar e-commerce charge, sometimes for a few hundred NT dollars, sometimes for tens of thousands. The charge may carry a merchant name that looks nothing like the platform in the fake message. That is where the dispute process begins — and where the friction starts.

Why the fake Momo and Shopee messages work

The CIB’s public warning page points to a “Help Me Vote” LINE phishing campaign and notes a 94% drop in account takeovers from January to July 2026. That decline does not mean fraud disappeared. It suggests many campaigns moved to links that ask for card numbers, one-time passwords or personal data directly. A message that looks like a Shopee order confirmation, a Momo refund notice or a delivery failure can lead to a page that copies a familiar checkout screen.

The scammers are not necessarily attacking Momo or Shopee’s own systems. They rent the trust of those brands. The fake page may ask for card number, expiry date and OTP, then route the payment through a third-party processor, a foreign acquiring bank or a shell merchant. The real platform may have no transaction to reverse. That gap matters when the issuer asks for proof.

August’s numbers also show how uneven the damage can be. A NT$54.51 million total across 505 cases averages about NT$108,000 per reported case. Some victims lose a small test charge; others lose a sum that takes months to earn. The average is not a promise of what any one household will face, but it shows why card issuers treat phishing losses differently from a simple stolen-card report.

The chargeback is not a one-click refund

When a cardholder disputes an e-commerce charge, the issuer starts a chargeback or dispute process. The bank may ask for a signed form, screenshots of the messages, police report details and confirmation that the card was not handed over. If the transaction was completed with a one-time password, the issuer may treat it as cardholder-authorised, even if the cardholder was tricked into entering it. If the card details were stolen without an OTP, the path is usually clearer. Either way, the cardholder often waits.

During the wait, the statement still arrives. A provisional credit may be reversed if the dispute fails. Minimum payment rules still apply. Miss a payment while a dispute is open, and the household can face interest and fees on a charge it did not intend to make. That is the practical friction: the bank’s fraud team and the billing system do not always move at the same speed.

The merchant side is messy too. If the charge came from a foreign processor or a merchant that has already disappeared, the issuer may struggle to recover the money. A Momo or Shopee impersonation case can look like a legitimate e-commerce purchase in the card network data. The descriptor may be a string of letters, not the platform name the victim remembers seeing.

The timing adds pressure. Mid-Autumn Festival travel and barbecue spending put more transactions on cards, and a busy weekend makes it easier to miss a small test charge. Cardholders who check the statement only once a month may find a scam charge after the dispute window has narrowed.

What cardholders can do before the next statement

The CIB and TDNS both repeat a simple rule: do not click unknown links. If a message says a parcel failed or an order needs a refund, open the retailer’s own app or type the address, not the link. Check the card statement line by line. If a charge is unfamiliar, call the number on the back of the card and ask for the dispute process in writing. Report to police if personal data or a large sum is involved.

Keep the evidence in one place: screenshots, order numbers, chat logs, the bank’s case number and any police report. Ask the issuer whether the charge was made with an OTP. That answer shapes the dispute. Ask whether a provisional credit will be applied and what happens to the statement balance if the case takes weeks.

Issuers can help by flagging unusual e-commerce descriptors, sending real-time alerts and making the dispute checklist easier to find. But the cardholder still carries the first move: notice the charge, challenge it quickly and keep the paper trail. The statement is the document that counts.