2026-07-09

Added · Updated

SFC mandates phishing-resistant authentication methods for internet brokers and VATPs to protect client accounts

The Securities and Futures Commission (SFC) issued a circular requiring internet brokers and virtual asset trading platform operators (VATPs) to adopt phishing-resistant authentication methods for client login and device binding, ceasing the use of one-time passwords (OTPs). These measures, such as passkeys and bound devices, must be implemented as soon as practicable, but no later than 12 months from July 9, 2026, with large internet brokers expected to adopt them immediately. Firms must also implement effective monitoring, promptly notify clients of key account events, respond to hacking incidents, and senior management will be held accountable for client losses due to control lapses.

Securities and Futures Commission Hong Kong logo

Hong Kong

Securities and Futures Commission Hong Kong

Click to view full text