Mark RadarMARK RADAR
EN
Event File CRYPTO Cryptocurrency Security

Hong Kong SFC Mandates Anti-Phishing Safeguards for Crypto Platforms and Brokers

1 reports · First detected 2026-07-09 · Last active 2026-07-09

As virtual-asset fraud and social-engineering scams proliferate worldwide, conventional authentication methods are struggling to stop new forms of attack. Hong Kong’s Securities and Futures Commission said phishing accounted for 57% of the cybersecurity incidents reported in the city in 2025, while losses from technology crimes reached HK$1.29 billion in the first quarter of 2026. Scammers frequently use man-in-the-middle attacks to intercept one-time passwords, or OTPs, sent by text message or email, prompting authorities to impose stricter safeguards on virtual-asset platforms and online brokers.

The SFC issued Circular 26EC35 on July 9, 2026, requiring licensed virtual-asset platforms and online brokers to stop using OTPs sent by text message or email for login and device binding. Firms must adopt stronger phishing-resistant authentication, such as passkeys or hardware security keys, during a 12-month grace period, with a final compliance deadline of July 8, 2027. Large online brokers must implement the measures immediately to strengthen security.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR
All times are in Taipei time (GMT+8)