Hong Kong SFC Orders Brokers and Crypto Platforms to Replace One-Time Passwords with Phishing-Resistant Authentication

Hong Kong SFC Orders Brokers and Crypto Platforms to Replace One-Time Passwords with Phishing-Resistant Authentication

N
News Editor 01
2026-07-23 23:20:16
Hong Kong's SFC mandates brokers and licensed virtual asset trading platforms to swap OTPs for phishing-resistant methods like passkeys and device binding within 12 months. Phishing attacks accounted for 57% of 2025 cybersecurity incidents reported in Hong Kong.
Hong Kong SFCone-time passwordphishing attackvirtual asset trading platformcybersecurity

Hong Kong's Securities and Futures Commission has issued a new directive requiring internet brokers and licensed virtual asset trading platform operators to replace one-time passwords with phishing-resistant authentication methods within 12 months. Larger brokers are expected to adopt the measures immediately. This marks one of the strongest regulatory actions against cybercrime targeting online trading accounts to date.

OTPs No Longer Considered Sufficient

The SFC stated that OTPs can no longer adequately defend against increasingly sophisticated phishing attacks. In 2025, phishing accounted for 57% of all cybersecurity incidents reported to the Hong Kong Computer Emergency Response Team Coordination Centre, highlighting the scale of the threat.

Regulators recommend passkeys and device binding as alternatives. Device binding links a customer's trading account to a securely registered computer or mobile device using unique characteristics, making it significantly harder for criminals to log in from unauthorized hardware.

The SFC first flagged OTP weaknesses in February 2025 after a cybersecurity review. The latest circular turns that advice into a binding requirement.

Crypto Platforms Held to Same Standards as Brokers

The new rules apply equally to licensed securities brokers and virtual asset trading platform operators, reinforcing Hong Kong's approach of treating digital asset firms similarly to traditional financial institutions.

Beyond stronger authentication, firms must implement monitoring systems to detect suspicious logins, unusual trading, and abnormal withdrawal requests. They must promptly notify clients of significant account events, respond rapidly to hacking incidents, and regularly warn customers about emerging phishing campaigns.

Senior management bears ultimate responsibility for protecting client assets. Inadequate cybersecurity controls could lead to firm liability for losses.

Dr. Eric Yip, the SFC's Executive Director of Intermediaries, said: "Protecting client accounts from increasingly sophisticated and elusive phishing attacks requires holistic measures combining prevention, detection, response and education. Licensed firms should strengthen their first line of defence with robust authentication solutions, stay alert to suspicious activities, and respond swiftly before harm is done."

Passkeys Gain Regulatory Backing

The circular adds to global momentum for passkeys. Unlike traditional credentials, passkeys rely on cryptographic authentication tied to a user's device and cannot be intercepted or reused via phishing sites. Apple, Google, and Microsoft have already embedded passkey support, and banks and fintech firms are deploying the technology.

Stronger authentication is increasingly critical as cybercriminals target trading accounts that provide immediate access to cash, securities, and digital assets.

Investor Education Remains Part of the Strategy

Alongside technical controls, the SFC urged investors to use strong, unique passwords, keep devices updated, access accounts only through official websites and apps, and review statements for unauthorized activity. If credentials are suspected compromised, investors should immediately contact their broker or platform, secure their accounts, and report to authorities.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
400

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.