Hong Kong’s Securities and Futures Commission has ordered licensed internet brokers and virtual asset trading platforms to immediately abandon SMS and email-based one-time passwords for customer authentication. The regulatory directive mandates adoption of phishing-resistant alternatives, specifically FIDO2/WebAuthn Passkeys or secure hardware-based device binding methods. Large internet brokers must comply immediately, while most other affected firms have a twelve-month implementation window.

The move targets firms licensed under Hong Kong’s Securities and Futures Ordinance, including those handling securities dealing, futures contracts, leveraged forex trading, asset management, and digital asset custody services. The SFC’s decisive action addresses rising retail account takeover threats and positions Hong Kong as a potential trendsetter in authentication security.

Regulators in Cyprus, the United Kingdom, and Singapore may follow suit given their history of monitoring peer jurisdictions when developing cybersecurity frameworks. International firms operating across multiple markets face mounting compliance costs from fragmented authentication requirements, potentially accelerating industrywide standardization around FIDO2 protocols.

FXnCO Insight

Brokers operating in or targeting Hong Kong clients should immediately audit their authentication infrastructure and budget for rapid FIDO2 implementation to avoid regulatory penalties and service disruption.

Source: Finance Magnates