Hong Kong's Securities and Futures Commission has issued a new directive requiring internet brokers and licensed virtual asset trading platform operators to replace one-time passwords with phishing-resistant authentication methods within 12 months. Larger brokers are expected to adopt the measures immediately. This marks one of the strongest regulatory actions against cybercrime targeting online trading accounts to date.
OTPs No Longer Considered Sufficient
The SFC stated that OTPs can no longer adequately defend against increasingly sophisticated phishing attacks. In 2025, phishing accounted for 57% of all cybersecurity incidents reported to the Hong Kong Computer Emergency Response Team Coordination Centre, highlighting the scale of the threat.
Regulators recommend passkeys and device binding as alternatives. Device binding links a customer's trading account to a securely registered computer or mobile device using unique characteristics, making it significantly harder for criminals to log in from unauthorized hardware.
The SFC first flagged OTP weaknesses in February 2025 after a cybersecurity review. The latest circular turns that advice into a binding requirement.
Crypto Platforms Held to Same Standards as Brokers
The new rules apply equally to licensed securities brokers and virtual asset trading platform operators, reinforcing Hong Kong's approach of treating digital asset firms similarly to traditional financial institutions.
Beyond stronger authentication, firms must implement monitoring systems to detect suspicious logins, unusual trading, and abnormal withdrawal requests. They must promptly notify clients of significant account events, respond rapidly to hacking incidents, and regularly warn customers about emerging phishing campaigns.
Senior management bears ultimate responsibility for protecting client assets. Inadequate cybersecurity controls could lead to firm liability for losses.
Dr. Eric Yip, the SFC's Executive Director of Intermediaries, said: "Protecting client accounts from increasingly sophisticated and elusive phishing attacks requires holistic measures combining prevention, detection, response and education. Licensed firms should strengthen their first line of defence with robust authentication solutions, stay alert to suspicious activities, and respond swiftly before harm is done."
Passkeys Gain Regulatory Backing
The circular adds to global momentum for passkeys. Unlike traditional credentials, passkeys rely on cryptographic authentication tied to a user's device and cannot be intercepted or reused via phishing sites. Apple, Google, and Microsoft have already embedded passkey support, and banks and fintech firms are deploying the technology.
Stronger authentication is increasingly critical as cybercriminals target trading accounts that provide immediate access to cash, securities, and digital assets.
Investor Education Remains Part of the Strategy
Alongside technical controls, the SFC urged investors to use strong, unique passwords, keep devices updated, access accounts only through official websites and apps, and review statements for unauthorized activity. If credentials are suspected compromised, investors should immediately contact their broker or platform, secure their accounts, and report to authorities.

