SFC mandates phishing-resistant authentication methods for internet brokers and VATPs to protect client accounts

Jul 9, 2026
Latest News SFC SFC mandates phishing-resistant authentication methods for internet brokers and VATPs to protect client accounts

On July 09, 2026, the SFC mandates phishing-resistant authentication for internet brokers and VATPs, requiring replacement of OTPs with methods like passkeys within 12 months to combat rising phishing threats.

This article was generated using SAMS, an AI technology by Timothy Loh LLP.

On July 09, 2026, the Securities and Futures Commission ("SFC") issued a circular requiring internet brokers and virtual asset trading platform operators ("VATPs") to adopt phishing-resistant authentication methods for client login and device binding, amid the growing threat of phishing attacks involving stolen client credentials.

Authentication Standards and Implementation Timeline

The SFC mandates the cessation of one-time passwords ("OTPs") for client login and device binding due to associated risks, requiring the adoption of robust alternatives such as passkeys and bound devices. Implementation is required as soon as practicable but no later than 12 months from the circular's issue, with large internet brokers expected to comply immediately.

Operational Controls and Management Liability

Firms must implement effective monitoring and surveillance to detect suspicious activities, notify clients of key events, and respond to hacking incidents promptly, alongside regular alerts regarding emerging cybersecurity risks. Dr Eric Yip, SFC’s Executive Director of Intermediaries, emphasized that protecting client accounts requires holistic measures combining prevention, detection, response and education.

Senior management of internet brokers and VATPs remains ultimately responsible for implementing appropriate controls to protect client accounts and assets, and the SFC will hold them accountable for any client losses arising from lapses in their controls.

Investor Security Responsibilities

Investors are reminded to stay vigilant by adopting prudent security measures, including using strong and unique passwords, keeping credentials and devices secure and up to date, and accessing accounts only through official websites or mobile applications of their licensed corporations and VATPs.

Clients should monitor their accounts regularly and promptly review account statements, transaction records and notifications for suspicious activities, contacting their LCs or VATPs immediately to secure accounts and report matters to relevant authorities if credentials are compromised or unauthorised transactions are identified.

Regulatory Definitions and Context

Internet brokers refer to licensed corporations engaged in Type 1, 2, 3, and/or 9 regulated activities via internet-based trading facilities, while device binding involves linking a client device with the trading system via securely enrolled device attributes.

Phishing attacks accounted for 57% of security incidents reported to the Hong Kong Computer Emergency Response Team Coordination Centre in 2025, and since late 2024, the SFC has been monitoring OTP risks following its February 6, 2025 Circular on cybersecurity reviews.

View the full article:Source

We use cookies to enhance your experience of our websites and to enable you to register when necessary. By continuing to use this website, you agree to the use of these cookies. For more information and to learn how you can change your cookie settings, please see our Cookie Policy and our Privacy Notice.