Source: Digitpol / District Court of Hong Kong
Original report:
Review published:
Jurisdiction: Hong Kong / Netherlands
Reported legal status: Defendant acquitted; identity not proven beyond reasonable doubt

What the court record says

In HKSAR v Hu Chunmei (DCCC 5/2024, [2025] HKDC 980, District Court of Hong Kong, 9 June 2025), the Hong Kong Police Force began investigating a Bank of China (Hong Kong) account after its Electronic Reporting Centre received a report from Digitpol Netherlands concerning suspected cybercrime activity.

According to the published judgment, the investigation focused on substantial foreign currency transfers from the Netherlands into an account held in the name of a Hong Kong-registered company. The account received approximately USD 650,687.54 and EUR 411,811.66, with transaction patterns involving rapid conversion and withdrawals. Digitpol’s report formed part of the initial intelligence that triggered the official inquiry, and neither the prosecution nor the defence disputed its authenticity or relevance.

Why the defendant was acquitted

The defendant told the court that in 2019 she had been asked by an individual involved in parallel trading to provide identification, and had sent photographs of both sides of her PRC Resident Identity Card via WeChat. This raised the possibility that her identity information was later misused by third parties to register the Hong Kong company and open the bank account.

The court could not exclude the defence argument that her identity had been exploited, and the prosecution failed to prove beyond reasonable doubt that she was the person who attended the bank branch to complete the account opening. The judgment shows how prosecutions can fail when criminals use identity fraud, intermediaries and weak onboarding controls at financial institutions, the bank could not establish who actually opened the account.

Editorial analysis, not additional case facts

Forensic lessons: the hidden clues are in the domain and registration data

When account-holder identity cannot be proven, the technical trail becomes decisive. In BEC and payment-diversion cases, the fraudulent domain’s WHOIS creation date is often the strongest objective clue: a domain registered days before the first payment instruction, under a name that does not match the impersonated supplier, points to premeditated fraud rather than a legitimate business change.

Preserve the domain creation date, registrar, nameservers and email-server records as early as possible, alongside the original messages and bank records. Registration data cannot by itself prove who controlled the account, but it anchors a timeline that banks, courts and investigators can test against other evidence, exactly the kind of corroboration that was missing on the identity question in this case.

Primary source

Read the official Digitpol / District Court of Hong Kong report

This review summarizes the cited public report. The original source date is shown separately from this review’s publication date. Subsequent proceedings or recoveries have not been verified here.

This is an independent review of a publicly reported case, not a Digitpol client case or a claim of involvement. No undisclosed domain indicators or private victim evidence are included.