Hong Kong’s SFC has issued new account security rules for internet brokers and licensed VASPs, requiring phishing-resistant authentication, stronger monitoring, incident reporting and client education.
Hong Kong SFC Issues Account Security Circular on 9 July 2026
On 9 July 2026, theSFCissued a circular to licensed corporations and SFC-licensedVASPs(file reference: SFO/IS/021/2026), requiring robust authentication methods to be implemented for client login and device binding by internet brokers, in order to reduce and mitigate hacking risks arising from phishing attacks and to establish adequate monitoring measures for identifying suspicious activities. The circular sets out regulatory expectations and provides examples of acceptable authentication methods.
The circular applies to licensed corporations carrying on internet trading and licensed for Type 1 regulated activity (dealing in securities), Type 2 (dealing in futures contracts), Type 3 (leveraged foreign exchange trading) and/or Type 9 (asset management, limited to the distribution of funds under their management through their internet trading facilities), as well as virtual asset trading platform operators under Schedule 3B to the Anti-Money Laundering and Counter-Terrorist Financing Ordinance.
Phishing Risks and Regulatory Background
Hong Kong Cybersecurity Incident Statistics
Phishing remains the most common type of cybersecurity incident reported in Hong Kong. According to statistics fromHKCERT, from January to December 2025, the centre handled a total of 15,877 cybersecurity incidents, up 27% year on year and reaching a record high. Of these, 8,973 were phishing incidents, accounting for 57% of all incidents, while the number of phishing-related URLs increased by 29% year on year.
Typical Attack Methods Reported by Licensed Institutions in 2025
In 2025, among cybersecurity incidents reported to the SFC by internet brokers and virtual asset service providers, fraudsters launched large-scale SMS phishing attacks indiscriminately targeting clients of relevant institutions. The attack chain typically included the following steps:
Fraudsters sent SMS messages containing malicious links that impersonated internet brokers and claimed to be information requests from regulators or government agencies;
Clients were deceived into entering user credentials on fake websites, includingOTPcodes used for login verification;
It is suspected that fraudsters carried out man-in-the-middle attacks, intercepted client credentials, gained access to accounts and conducted unauthorised transactions.
(Sources: HKCERT, Annual Report 2025, published on 2026-01, Section 3.1 Incident Handling Statistics and Figure 2 Incident Distribution; SFC, Circular SFO/IS/021/2026, published on 2026-07-09, background section.)
Four Expected Standards of Conduct Set Out by the SFC
Preventive Controls: Phishing-Resistant Authentication
Internet brokers and virtual asset service providers should implement strong authentication solutions covering client login to internet trading accounts, as well as client registration and device binding processes. Institutions must select appropriate authentication methods based on the type and risk profile of their internet trading platforms.
The SFC noted that, as stated in theCircular to Licensed Corporations: Review of Internet Trading Cybersecurity dated 23 September 2020and theNotification to Licensed Corporations: Cybersecurity Review of Licensed Corporations dated 6 February 2025, email OTP and SMS OTP carry various security weaknesses. OTP is not a phishing-resistant authentication solution and should no longer be used for client login and device binding processes.
Acceptable solutions listed in the appendix to the circular include:
Passkeys: passwordless authentication credentials based on public key cryptography, with private keys securely stored on the user’s device or in a passkey manager, without requiring keys to be transmitted or shared; passkeys can only be used on the legitimate websites or applications for which they were created and registered, and are internationally recognised as a phishing-resistant authentication method;
Bound devices: linking a device to a client account using a strong verification method, applicable to mobile and desktop trading applications; both passkey authentication and bound devices can support the “something the client has” factor in a two-factor authentication process.
Institutions should generally not allow clients to bind or register more than three passkeys and/or three devices for an internet trading account. Where a client applies for additional bindings above this limit, sufficient assessment must be conducted before approval. The SFC reiterated that clients must not be allowed to disable session timeout, and idle timeout should be limited to no more than 30 minutes, subject to assessment and continuous monitoring. Longer idle timeout should only be permitted after close monitoring of client login, logout and trading activities.
Detection and Monitoring of Suspicious Transactions
Institutions should promptly notify clients of successful account logins and other high-risk activities, including login from a new device, binding of a new device, and creation or revocation of a passkey or device. Notifications should, as far as practicable, be sent through multiple channels such as email, SMS or other push notifications.
For transaction monitoring, institutions must set predefined thresholds based on client profiles, historical trading behaviour, account activities, device usage and login patterns to identify the following red flags:
Transactions that are inconsistent with a client’s previous trading pattern, transactions carried out at unusual hours, or transactions resulting in significant losses within a short period;
Sudden and unusually large transactions in extremely illiquid or small-cap stocks;
Abnormal transactions occurring shortly after a passkey reset, change of contact details or binding of a new device.
For system login and device binding monitoring, institutions should maintain adequate logs, including device IDs, and conduct timely reviews to detect abnormal events such as binding requests from unusual geographical locations, multiple client accounts being bound to the same device, logins from multiple locations within a short period and abnormally long login sessions.
Response to and Reporting of Hacking Incidents
Institutions should establish procedures for promptly responding to hacking incidents, including immediately stopping unauthorised activities, protecting client assets, notifying affected clients and preventing further damage. Hacking incidents must be reported to the SFC immediately. Institutions must also conduct root cause analysis, identify internal control deficiencies or system vulnerabilities, retain detailed incident reports and implement remedial measures.
Client Cybersecurity Education
Institutions should take reasonable steps to alert clients to phishing and other cybersecurity risks, including:
Fraudulent emails, SMS messages or phone calls impersonating companies, as well as fake websites or mobile applications designed to steal login credentials;
The leakage of account credentials, including usernames, passwords, verification codes or devices, may result in unauthorised access, and clients should not disclose credentials or verification information to third parties under any circumstances;
Using strong and unique passwords, setting appropriate trading controls and limits, enabling alerts for key account activities, and promptly reviewing and reporting suspicious or unauthorised transactions.
(Source: SFC, Circular SFO/IS/021/2026, published on 2026-07-09, Expected Standards of Conduct paragraphs (A) to (D), appendix on authentication examples.)
Compliance Implementation Timetable
| Compliance Area | Timeline | Applicable Institutions | Regulatory Focus |
|---|---|---|---|
| Phishing-resistant authentication | 2026-07-09 to 2027-07-08 (12-month implementation period) | Internet brokers, licensed VASPs | Discontinue OTP for client login and device binding, and adopt passkeys or bound devices; large internet brokers must implement this immediately |
| Monitoring and client notification | Immediate enhancement from 2026-07-09 | Internet brokers, licensed VASPs | Identify suspicious logins, transactions and fund/virtual asset withdrawals, and notify clients of significant account activities through multiple channels |
| Hacking incident response | Continuous effectiveness from 2026-07-09 | Internet brokers, licensed VASPs | Contain unauthorised activities, protect client assets, report to the SFC immediately and conduct root cause analysis |
| OTP risk mitigation during the transition period | 2026-07-09 to 2027-07-08 | Internet brokers, licensed VASPs | Where OTP is still used during the transition period, suspicious activity detection must be strengthened, and account access must be immediately suspended or restricted upon detection of fraud |
During the implementation period, institutions should strengthen their internet trading systems by introducing strong authentication methods, conduct sufficient testing before deployment, promote reliable authentication methods to all clients as soon as practicable, and provide clients with guidance and support on the implementation and use of the new solutions. If difficulties are expected during the 12-month implementation period, the case officer must be notified immediately.
Regulatory Responsibilities of Senior Management
The senior management of internet brokers and virtual asset service providers, particularly managers responsible for overall management and supervision and managers responsible for information technology, are ultimately responsible for overseeing the implementation of the above enhancement measures and ensuring that client accounts are properly protected. Institutions may seek advice and assistance from system vendors and IT security experts as needed.
Under paragraph 4.3 of theCode of Conductand paragraph 11.10 of theVirtual Asset Trading Platform Operators Guidelines, licensed institutions are required to implement adequate internal controls and operational capabilities to protect their operations and clients from financial losses arising from theft, fraud and other dishonest acts. If an institution fails to take sufficient measures after a hacking incident to prevent, detect and stop large-scale unauthorised transactions through client accounts, the SFC will hold the relevant company accountable. Enquiries about the circular may be directed to the case officer, or to Ms Carmen Kwok at 2231 1455.
(Sources: SFC, Circular SFO/IS/021/2026, published on 2026-07-09, management responsibilities section; SFC,Code of Conduct, paragraphs 4.3 and 12.5(e);Virtual Asset Trading Platform Operators Guidelines, paragraphs 11.10 and 16.7(b)(c).)
Key Questions on Hong Kong SFC Authentication Regulation
Why does the SFC list passkeys as an acceptable phishing-resistant authentication solution?
Passkeys are based on public key cryptography, with private keys securely stored on the user’s device or in a passkey manager. Login verification is usually completed locally through biometrics or a personal identification number, without requiring keys to be transmitted or shared online. Passkeys are designed to be used only on the legitimate websites or applications for which they were created and registered, making them difficult for phishing websites to capture. They have been recognised by international bodies such as the US National Institute of Standards and Technology and the UK National Cyber Security Centre as a phishing-resistant authentication method.
Why does the SFC consider one-time passwords unsuitable for client login and device binding?
The SFC noted that email OTP and SMS OTP are exposed to the risk of clients being deceived into entering them on phishing websites, where they may be intercepted through man-in-the-middle attacks. In cybersecurity incidents reported to the SFC by licensed institutions in 2025, fraudsters used SMS phishing links impersonating brokers or regulators to obtain client OTPs and carry out unauthorised transactions. As OTP does not have phishing-resistant properties, the SFC requires institutions to discontinue the use of OTP in client login and device binding processes.
What specific work must licensed institutions complete during the 12-month implementation period?
From 9 July 2026 to 8 July 2027, institutions must promote reliable authentication methods such as passkeys or bound devices to all clients, complete sufficient testing before deployment, and provide clients with guidance and support on the new solutions. They must also immediately enhance client notification, monitoring and surveillance, and incident response procedures. If OTP is still used during the transition period, institutions must strengthen detection of suspicious logins and unauthorised transactions, and immediately suspend or restrict account access upon detecting abnormal activity.
What should clients do if they detect suspicious activity in their accounts?
If clients detect suspicious logins, abnormal transactions or unauthorised fund/virtual asset withdrawals in their accounts, they should immediately contact their internet broker or virtual asset service provider to report the matter, so that the institution can verify the situation and, where applicable, stop unauthorised activities. Institutions must also promptly notify clients through multiple channels of significant account activities such as successful logins, new device bindings and passkey creation or revocation, helping clients identify risks at an early stage.