2024-10-10
Added · Updated
The Hong Kong Monetary Authority mandates authorized institutions to default to bound device authentication for online payment card transactions to mitigate risks from SMS OTP interception by malware. Institutions must treat changes to this default method as high-risk transactions and implement appropriate support for customers lacking mobile banking applications or facing authentication difficulties. These enhanced anti-fraud controls must be fully implemented by 31 December 2024 following industry feedback and collaboration with banking associations and law enforcement.
55th Floor, Two International Finance Centre, 香 港 中 環 金 融 街 8 號 國 際 金 融 中 心 2 期 55 樓 8 Finance Street, Central, Hong Kong 網 址:www.hkma.gov.hk Website: www.hkma.gov.hk Our Ref.: B1/15C B9/29C 10 October 2024 The Chief Executive All Authorized Institutions issuing payment cards Dear Sir/Madam, Enhancement measures for online payment card transactions I am writing to provide further guidance for authorized institutions (AIs) to implement enhanced anti-fraud/scam measures to strengthen the security of online payment card transactions, following the announcement of this initiative in August alongside the launch of Suspicious Account Alerts for internet banking and physical branch transactions1 Feedback and suggestions from the subsequent industry engagements have also been incorporated Retail banks introduced an anti-malware measure in February 2024 in view of intelligence shared by law enforcement agencies, the Hong Kong Monetary Authority (HKMA) and overseas regulators This measure entails restricting customers’ access to their mobile banking applications (Apps) if suspicious apps are detected on their devices Since the implementation of this measure, no new cases have been reported by AIs regarding malware manipulating mobile banking Apps, as compared to more than 30 reported cases in 2023 /…page 2 1 HKMA press release: Expansion of Suspicious Account Alert for internet banking and physical branches transactions (https://www hkma gov hk/eng/news-and-media/press-releases/2024/08/20240801-5/)
If customers with mobile banking Apps encounter difficulties in authenticating payment card transactions using a bound device, AIs should consider the circumstances of each case and take appropriate follow-up actions This may include providing suitable arrangements for vulnerable customers who may lack sufficient knowledge about mobile banking Apps, or for dormant users of mobile banking Apps While customers without mobile banking Apps may continue to use SMS OTPs for authentication of online payment card transactions, considerations should be given to incentivise customers to install and use mobile banking Apps as appropriate and with proper education and awareness initiatives In addition, AIs should tighten their fraud monitoring for online payment card transactions authenticated via SMS OTPs / … page 3 2 In such cases, AIs should use other means than SMS OTP for authentication, for example, biometric authentication measures, or identity verification at a physical branch