On 9 July 2026, the Securities and Futures Commission issued the Circular to licensed corporations and SFC-licensed virtual asset service providers on robust authentication and surveillance.1 The circular requires internet brokers2 and virtual asset trading platform operators3 to adopt phishing-resistant authentication for client login and device binding.4 Firms must cease using one-time passwords for these purposes. The deadline is 8 July 2027, twelve months from issue. Large internet brokers are expected to implement immediately. The trigger is a sustained phishing campaign against Hong Kong clients. In 2025, fraudsters ran large-scale SMS phishing operations impersonating brokers, harvesting credentials including OTPs on fake websites, and executing suspected man-in-the-middle attacks to take over accounts.5 Phishing accounted for 57% of security incidents reported to the Hong Kong Computer Emergency Response Team Coordination Centre in 2025. The circular converts two years of SFC encouragement into a dated obligation.5
SFC circular SFO/IS/021/2026 requires FIDO-certified passkey authentication or robust device binding for client login across Hong Kong internet trading and virtual asset platforms, ends OTP-based authentication within twelve months, and warns senior management that firms will bear client losses arising from control lapses.
HK SFC’s stance on OTP
“The (HK) SFC does not consider OTP to be a phishing-resistant authentication solution”, and firms should not use it for client login or device binding. The logic is technical: an OTP is a shared secret, and any secret a client can type, a fraudster can phish. The 2025 campaigns proved the point at scale, intercepting OTPs in real time through fake websites. Firms are not required to ask existing clients to rebind devices already bound, which confines the migration burden to login flows and new bindings.
OTP to be replaced by passkeys and bound devices
The Circular's Appendix sets two acceptable architectures. Passkeys are password-less credentials based on public-key cryptography: the private key never leaves the client's device, hardware security key or passkey manager, and the credential operates only with the genuine website or application for which it was created.6 A phished client redirected to a fraudulent site has nothing to surrender. Solutions, whether third-party or self-built, should hold FIDO certification. Registration must sit behind strong identity verification, with additional passkeys created only after authentication through an existing one, and firms must control revocation, recovery and the risks of passkeys synchronised across devices.
Device binding is acceptable only where the binding itself uses robust verification. Binding executed with credentials plus OTP is expressly identified as vulnerable to unauthorised device registration. After the implementation period, clients may bind new devices only through robust methods, and the Appendix gives four worked examples: cross-device passkey authentication; biometric facial verification with liveness detection checked against the firm's own database, independent of the device's native biometrics7; identity document verification with OCR cross-checking and selfie matching; or physical verification in person at the firm's office. Throughout, generally no more than three passkeys and three bound devices per account without adequate assessment; session idle timeouts should stay within 30 minutes.
The four-limb conduct standard
Authentication is only limb one. The circular requires prevention, detection, response and education together. Detection demands prompt client notification of successful logins, new-device logins, bindings and passkey creation or revocation through multiple channels, transaction monitoring against client-specific thresholds, and login and binding surveillance for irregular events: bindings from unusual locations, multiple accounts bound to one device, logins from multiple locations in short windows. Named red flags include unusual transactions shortly after a password reset, contact detail change or new binding, and sudden concentrated activity in illiquid or small-cap stocks. Response requires immediate containment, client notification and immediate reporting to the SFC, with root cause analysis. Education requires regular client alerts on impersonation tactics and credential hygiene.
Accountability: the loss-bearing warning
“Protecting client accounts from increasingly sophisticated and elusive phishing attacks requires holistic measures combining prevention, detection, response and education” — Dr Eric Yip, SFC Executive Director of Intermediaries, 9 July 2026
The enforcement teeth sit in paragraph 25. Where a firm fails to implement adequate measures to prevent, detect and stop large-scale unauthorised transactions following hacking incidents, “the SFC will hold the relevant firm accountable for the losses suffered by its clients.” Responsibility is mapped to named roles: the Manager-in-Charge of Overall Management and Oversight and the Manager-in-Charge of Information Technology are ultimately responsible for implementation, anchored in paragraph 4.3 of the Code of Conduct and paragraph 11.10 of the VATP Guidelines. The two MiCs now own a dated, testable obligation, and the loss-bearing warning converts every future account takeover into a potential restitution event.
What firms should do now
Detection, response and client-education enhancements are expected immediately; the SFC will take a pragmatic approach only on system-dependent upgrades. Sequence accordingly: uplift notification, monitoring and incident procedures now; select the FIDO-certified passkey or binding architecture; test, then roll out progressively, because continued OTP reliance during transition carries an express expectation of enhanced surveillance and immediate suspension on suspicion. Firms anticipating difficulty with the twelve-month period must notify their case officer immediately.
Notes
1. SFC, Circular to licensed corporations and SFC-licensed virtual asset service providers on robust authentication and monitoring and surveillance measures, 9 July 2026, ref. SFO/IS/021/2026, with Appendix of acceptable authentication methods. Incident reporting: Code of Conduct para 12.5(e); VATP Guidelines paras 16.7(b)-(c).
2. “Internet brokers” are licensed corporations engaged in internet trading, licensed for Type 1, 2 or 3 regulated activity and/or Type 9 to the extent funds under management are distributed through internet-based trading facilities.
3. “SFC-licensed VASPs” currently means virtual asset trading platform operators, as operating a VA exchange is presently the only VA service under Schedule 3B to the Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615).
4. Device binding links a client's mobile device or computer to the trading system via securely enrolled device attributes, so logins can be verified as originating from a previously registered device.
5. The 2025 SMS campaigns impersonated brokers, citing purported regulator information requests, to lure clients onto fake websites; see SFC circulars of 21 May and 6 June 2025. The SFC had flagged OTP weaknesses in its 23 September 2020 circular and strongly encouraged firms to stop using OTPs on 6 February 2025.
6. Passkeys implement FIDO2/WebAuthn standards, stored on hardware security keys or platform passkey managers (Apple iCloud Keychain, Google or Microsoft Password Manager). Passkeys and bound devices each satisfy the “what the client has” two-factor requirement (Cybersecurity Guidelines para 1.1; VATP Guidelines para 12.12(b)).
7. Liveness detection requires a selfie with prompted actions (blinking, turning the head) to confirm capture from a live person and defeat deepfake-based authentication.




