Meituan Monthly Pay Users Hit by Batch Unauthorized Charges; Firm Cites New Telecom Fraud
Users of Meituan's Monthly Pay service in Shaanxi, Guangdong, Gansu and other regions reported unauthorized batch charges from remote locations, with individual losses ranging from over 1,000 yuan to more than 4,000 yuan. The charges occurred during early morning hours, exploiting a small-amount no-password payment feature. Meituan responded that the incidents likely stem from a new type of telecom fraud, where criminals use malware links to remotely control victims' phones, purchase group-buy vouchers, and resell them. Police have launched investigations, and Meituan has upgraded risk controls and set up a dedicated channel to assist affected users.
Recently, users of Meituan's Monthly Pay service in multiple regions including Shaanxi, Guangdong, and Gansu reported that their accounts were subjected to batch unauthorized charges from remote locations without their knowledge or action. The losses ranged from over 1,000 yuan to more than 4,000 yuan. The unauthorized charges mostly occurred during early morning hours, deducted through Meituan Monthly Pay, and all affected users had enabled the small-amount no-password payment feature for transactions under 500 yuan. The fraudulent orders were for various food and leisure group-buy vouchers, which were quickly redeemed at stores in other locations after being placed.
Meituan responded multiple times on July 29 and 30, stating that after individual reviews, the affected users had a high probability of encountering a new type of telecom fraud. Multiple investigations revealed a highly consistent modus operandi: criminals lured users with promises of "rebates for fake orders" or "high commissions" and sent links containing malware. Once users clicked the link, their phones were remotely controlled. The criminals then used the users' identities to purchase large quantities of group-buy vouchers for popular restaurants and scenic spot packages on Meituan, and resold them on online second-hand platforms for cash. Because the criminals operated the users' own phones, the transaction devices, network environment, and geographic locations matched the users' daily usage, making it difficult for the platform's standard risk control systems to detect and block the activity. Currently, police in multiple regions have filed cases and are investigating. Meituan is actively cooperating by providing complete data such as account login logs, order details, and redemption records to assist in tracking down the criminal groups.
In response to this new criminal method, Meituan has continuously upgraded its risk control strategies: in high-risk scenarios such as group-buy purchases for popular restaurants, it has added risk warnings and verification steps before bulk purchases; restricted the transfer path for group-buy vouchers; and disabled the payment-on-behalf function for high-risk categories. Meituan has opened a dedicated channel for handling unauthorized charges, ensuring that un-redeemed orders are intercepted as soon as users call. For already redeemed orders, a special evaluation process has been initiated, with a dedicated team contacting each affected user to assist in properly handling the related losses.
Multiple affected users confirmed that they had recently clicked on unknown links sent via text messages or social media platforms. Some users experienced abnormal phone behavior such as black screens, lagging, or automatic pop-ups. Meituan customer service stated that for already redeemed group-buy vouchers, the platform cannot process refunds on its own; users need to file a police report and obtain platform backend data through judicial evidence procedures. Industry insiders noted that this type of criminal method, using malware to remotely control phones for unauthorized charges, is a new form of fraud that has recently appeared on multiple internet platforms, with similar cases occurring on other payment platforms.
Why this event matters
The event has a measured impact on 2 industrys. The strongest current signal is negative for Financial Technology, with intensity 50/100 and 70% confidence over a short term horizon.
Financial Technology
- Direction
- negative
- Intensity
- 50
- Confidence
- 70%
- Horizon
- Short term
Local Consumer Platforms
- Direction
- negative
- Intensity
- 40
- Confidence
- 65%
- Horizon
- Short term
Impact figures are analytical estimates that combine direction, intensity, confidence and event importance. They are not investment advice.