Hong Kong’s Securities and Futures Commission has ordered internet brokers and virtual asset platforms to immediately stop using one-time passwords for client authentication, mandating phishing-resistant alternatives like passkeys and device binding instead. The directive, issued Thursday, responds to a surge in account takeovers driven by phishing attacks that intercept OTP codes in real time through fake login pages.
The regulator froze approximately HK$91 million across four brokers late last year, including Interactive Brokers’ Hong Kong unit, after unauthorized trades compromised customer accounts. Phishing now accounts for 57 percent of security incidents reported to Hong Kong’s Computer Emergency Response Team in 2025. Firms must comply as soon as practicable, with a hard deadline of twelve months from Thursday’s circular, though major brokers face expectations for immediate adoption.
The mandate escalates earlier voluntary guidance from February 2025 and follows previous measures banning clickable links in broker text messages.
**
FXnCO Insight
** Brokers operating in or serving Hong Kong clients should budget now for authentication infrastructure upgrades, as enforcement timelines are tight and non-compliance could trigger account freezes or licensing action.
Source: Finance Magnates