Hong Kong SFC Mandates Anti-Phishing Safeguards for Crypto Platforms and Brokers
As virtual-asset fraud and social-engineering scams proliferate worldwide, conventional authentication methods are struggling to stop new forms of attack. Hong Kong’s Securities and Futures Commission said phishing accounted for 57% of the cybersecurity incidents reported in the city in 2025, while losses from technology crimes reached HK$1.29 billion in the first quarter of 2026. Scammers frequently use man-in-the-middle attacks to intercept one-time passwords, or OTPs, sent by text message or email, prompting authorities to impose stricter safeguards on virtual-asset platforms and online brokers.
The SFC issued Circular 26EC35 on July 9, 2026, requiring licensed virtual-asset platforms and online brokers to stop using OTPs sent by text message or email for login and device binding. Firms must adopt stronger phishing-resistant authentication, such as passkeys or hardware security keys, during a 12-month grace period, with a final compliance deadline of July 8, 2027. Large online brokers must implement the measures immediately to strengthen security.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →