Bottom line
In its 9 July 2026 circular, the Securities and Futures Commission (SFC) expects internet brokers and SFC-licensed virtual asset service providers (VASPs) to use robust, phishing-resistant authentication for client login and device binding, and to operate effective monitoring and surveillance for suspicious activity. It is an implementation-focused supervisory circular, with an express 12-month deadline for authentication solutions and immediate expectations in several other areas (paras. 4–5, 21).
This builds on the earlier 2 June 2026 AI cybersecurity controls guide: that guide addresses enterprise resilience against faster AI-enabled attacks; this circular applies that concern directly to client-account takeover through phishing. For covered firms, ordinary email or SMS one-time passwords (OTPs) are not phishing-resistant and should not be used for client login or device registration/binding (paras. 5–8).
Large internet brokers are expected to implement robust authentication immediately. All covered firms should immediately enhance notification, monitoring, surveillance, response and reporting arrangements; while OTP remains in use during the transition, suspicious or potentially fraudulent activity must prompt immediate suspension or restriction of account access (paras. 21–23).
Do today
Should — establish the implementation population and plan. The business, Technology and Compliance should identify every client internet-trading platform, login flow and device-binding journey, including any Type 9 fund-distribution portal. Produce an accountable implementation plan that achieves robust authentication no later than 8 July 2027; large internet brokers should implement it immediately (paras. 5–6, 21(c)).
Must — harden transition controls now. Operations and Financial Crime/Surveillance should enhance detection of irregular logins and unauthorised trading while legacy OTP is used. On identifying suspicious or potentially fraudulent activity, suspend or restrict account access immediately; retain the resulting decision record (para. 22).
Must — make incident response client-account ready. Incident Management should verify procedures to halt unauthorised activity, protect client assets, notify affected clients, report hacking incidents to the SFC immediately, preserve a detailed incident report, conduct root-cause analysis and track remediation (paras. 17–18).
Should — select and test an authentication architecture. Technology and Information Security should assess passkeys and robust device-binding verification for each channel, then document security, usability, outsourcing, recovery and client-support decisions. The Appendix describes FIDO-certified passkey solutions and robust device-binding methods as acceptable examples; it is illustrative, not a closed technical specification (para. 8; Appendix, pp. 1–4).
Should — brief clients before rollout. Product, Client Services and Compliance should prepare clear communications, enrolment support and lost-device/passkey-recovery guidance. Client awareness measures should be enhanced as soon as practicable (paras. 19–22; Appendix, pp. 1–3).
Check
Scope and ownership
Is the firm an “internet broker”: an LC engaged in internet trading and licensed for Type 1, 2, 3, and/or Type 9 regulated activity, where Type 9 is in scope only to the extent the firm distributes funds it manages through internet-based trading facilities? (fn. 1.)
Is the firm an SFC-licensed VASP? The circular notes that this currently means VATP operators, given the current scope of virtual-asset services (fn. 2.)
Have the Manager-in-Charge of Overall Management Oversight and MIC-IT been given clear oversight, escalation and approval evidence? They are ultimately responsible for implementing the enhancements and protecting client accounts (para. 24).
Authentication and device binding
For every website, desktop application and mobile application, what phishing-resistant factor will support client login, and how will it fit the required two-factor process? Passkeys and robustly verified bound devices are the SFC’s stated examples (paras. 8–9).
Is the passkey provider or in-house solution appropriately FIDO-certified? Does enrolment use strong identity verification, and do controls prevent unauthorised creation, revocation or recovery of additional passkeys? (Appendix, pp. 1–2.)
Are lost, compromised and replacement devices/passkeys handled through a tested recovery path with appropriate identity verification? Are synchronised software-based passkeys protected against abuse? (Appendix, pp. 1–2.)
After the transition, can new devices be bound only through robust verification methods—such as passkey authentication, biometric verification against internal records, identity-document verification, or in-person verification? (Appendix, pp. 3–4.)
Do controls enforce the existing general limit of three passkeys and/or three devices per client account, with adequate assessment before any exception? Are clients prevented from disabling session timeout, with any longer timeout justified and monitored? (paras. 10–11.)
Detection, surveillance and client communication
Are clients promptly notified, through multiple channels where applicable, of successful logins and high-risk account events, including new-device logins, device binding and passkey creation or revocation? (paras. 13–14.)
Are transaction thresholds and red flags tailored to client profile, historical behaviour, device use and login patterns? Can surveillance identify unusual trading times, transactions after credential or contact changes, illiquid/small-cap trading spikes and login/device anomalies? (para. 16.)
Are device IDs and other sufficient login/device-binding logs retained and reviewed promptly for multiple-account, multiple-location and unusual-session indicators? (para. 16(b).)
Keep an eye on
8 July 2027. Reassess delivery status monthly against the final deadline. A firm anticipating difficulty meeting the 12-month period should immediately notify its SFC case officer-in-charge (paras. 21(c), 23).
Large-broker status. The circular does not define “large internet broker”. A potentially large firm should engage its case officer promptly rather than assume it has the full 12 months; the SFC expects large internet brokers to implement robust solutions immediately (para. 21(c)).
Control evidence and losses. The SFC reminds firms of binding internal-control obligations under paragraph 4.3 of the Code of Conduct and paragraph 11.10 of the VATP Guidelines. It says it will hold a relevant firm accountable for client losses if inadequate measures mean that large-scale unauthorised transactions cannot be prevented, detected and stopped after a hacking incident (para. 25).
Technology developments. Reassess authentication, platform-specific threats and surveillance rules regularly; the SFC expects controls to remain proportionate to the nature, scale and complexity of the business and each platform (para. 12).
Why this matters
The SFC reports that phishing represented 57% of cybersecurity incidents reported to the Hong Kong Computer Emergency Response Team Coordination Centre in 2025. It also describes 2025 SMS-phishing campaigns against internet-broker and VASP clients, where fraudsters allegedly intercepted credentials and OTPs to enter accounts and place unauthorised transactions (paras. 2–3 and fn. 5–6).
For a covered asset manager that distributes proprietary funds through an internet-based trading facility, the gating issue is no longer simply whether the firm has two-factor authentication. The SFC is explicit that OTP does not meet its phishing-resistant standard for login and device binding. The programme should therefore combine a deployment roadmap with immediate detection, containment, client-notification and evidence-retention controls.
Scope and timing
Jurisdiction/regulator: Hong Kong / SFC. Document: supervisory circular SFO/IS/021/2026, dated 9 July 2026. In scope: internet brokers and SFC-licensed VASPs; in current practice, VASPs refers to VATP operators. Immediate: enhance client notifications, monitoring/surveillance, response/reporting, and phishing awareness; large internet brokers are expected to implement robust authentication immediately. By 8 July 2027: all other covered firms must implement robust authentication for client login and device binding, roll it out to all clients and support the change (paras. 21–22).
This guidance note does not constitute legal advice. Enforcement matters described involve allegations only; no findings of wrongdoing have been made by a court unless expressly stated. AI, under human supervision, has been used for research and drafting assistance. All content has been reviewed by a human prior to publication.




