Hong Kong SFC Orders Brokers to Replace One-Time Passwords After Phishing Surge
Hong Kong’s Securities and Futures Commission (SFC) has directed internet brokers and virtual asset trading platforms to discontinue use of one-time passwords for client logins, citing escalating phishing attacks that have led to account takeovers. In a circular issued on Thursday, the regulator mandated adoption of phishing-resistant authentication methods, including passkeys and device binding, for login and device registration procedures.
Phishing schemes harvesting client credentials have driven a series of unauthorized trades on compromised accounts in Hong Kong markets, with the SCF freezing approximately HK$91 million across four brokers, including Interactive Brokers’ local unit, late last year.
The order specifically bars firms from using OTPs for client login and device binding, which the regulator noted carry heightened risk as stronger alternatives become viable; OTPs sent via text or app can be intercepted by attackers on fraudulent login pages in real time. Passkeys and device binding mitigate such vectors by tying access to a specific device or hardware credential rather than a transferable code. Firms are required to implement these changes as soon as practicable and no later than 12 months from the circular’s issuance, with large internet brokers expected to comply immediately.
The directive extends a broader regulatory campaign that has intensified over the past year as phishing accounted for 57% of security incidents reported to the Hong Kong Computer Emergency Response Team Coordination Centre in 2025. Earlier SFC actions included promoting enrollment in an SMS Sender Registration scheme, banning clickable links in broker text messages, and encouraging OTP abandonment in a February 2025 advisory—guidance now made mandatory.
Beyond authentication, the SFC instructed firms to monitor for suspicious login, trading, and withdrawal activity, alert clients to key account events, and respond promptly to breaches, while also maintaining ongoing customer warnings about emerging phishing risks. Dr. Eric Yip, the SFC’s Executive Director of Intermediaries, stated that account protection requires combining “prevention, detection, response and education,” and urged firms to “strengthen their first line of defence with robust authentication solutions.”
The rules cover licensed corporations dealing in securities, futures, and leveraged foreign exchange, along with asset managers using internet trading and licensed crypto platforms. The SFC affirmed that senior management retains ultimate responsibility for safeguarding client accounts and assets, and will hold executives accountable for any client losses attributable to lapses in controls.
Subscribe Now

