Hong Kong SFC Mandates Anti-Phishing Safeguards for Crypto Platforms and Brokers
As virtual-asset fraud and social-engineering scams proliferate worldwide, conventional authentication methods are struggling to stop new forms of attack. Hong Kong’s Securities and Futures Commission said phishing accounted for 57% of the cybersecurity incidents reported in the city in 2025, while losses from technology crimes reached HK$1.29 billion in the first quarter of 2026. Scammers frequently use man-in-the-middle attacks to intercept one-time passwords, or OTPs, sent by text message or email, prompting authorities to impose stricter safeguards on virtual-asset platforms and online brokers.
The SFC issued Circular 26EC35 on July 9, 2026, requiring licensed virtual-asset platforms and online brokers to stop using OTPs sent by text message or email for login and device binding. Firms must adopt stronger phishing-resistant authentication, such as passkeys or hardware security keys, during a 12-month grace period, with a final compliance deadline of July 8, 2027. Large online brokers must implement the measures immediately to strengthen security.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.