← Back to KHAO

Hong Kong · China · Ethereum ·

The measures raise Hong Kong's cybersecurity standards as the global crypto industry saw an increase in phishing attacks

2 min read

Compiled by KHAO Editorial — aggregated from 2 sources. See llms.txt for citation guidance.

◎ Multiple-sources

1 minute letter.

Counterfeiting and fraud attacks accounted for 57% of the security incidents reported to the Hong Kong Cyber Security Accident Coordination Center in 2025, according to announcement.

Key facts

Summary

Hong Kong’s regulator has ordered crypto platforms and online brokers to meet newly issued phishing-resistant login requirements within the next 12 months. The Hong Kong Securities and Futures Commission (SFC) on Thursday issued new requirements for phishing-resistant authentication methods for virtual asset trading platforms (VATPs) and online brokers in the special administrative region. The new standards require stronger phishing-resistant authentication methods and device binding while prohibiting the use of one-time passwords through SMS, email or app-based logins. The requirements outlined stronger alternatives such as passkeys, registered devices with cryptographic verification and hardware security keys, which the SFC described as phishing-resistant solutions. The measures raise Hong Kong's cybersecurity standards as the global crypto industry saw an increase in phishing attacks and social engineering scams in the first quarter of 2026.

#Hong Kong #China #Ethereum