Tel +852 5382 0328 info@safeharbour.hk WhatsApp 繁體中文
Safe Harbour Consultants · Hong Kong & Macau Get a Quote
Hong Kong regulatory

SFC sets a July 2027 deadline for phishing-resistant authentication

A circular dated 9 July 2026 requires internet brokers and SFC-licensed virtual asset trading platforms to replace one-time passwords and device binding with phishing-resistant methods, no later than 8 July 2027.

One-time passwords sent by SMS or email are the weakest link in most client login journeys. They can be intercepted, relayed in real time, or defeated by a convincing phishing page. The circular sets a fixed date to retire them.

The deadline, and what it covers

  • Replace one-time passwords and device binding with phishing-resistant methods.
  • Deadline: as soon as practicable, and no later than 8 July 2027.
  • Strengthen account monitoring and surveillance for suspicious activity.
  • A separate SFC circular of 2 June 2026 covers AI-enabled cyberattack resilience.

What this means for you

The date is fixed, so the work is a project with a hard end, not a policy statement. Start with the client journey you cannot change quickly — legacy platforms, shared logins, and any flow where a third party controls the login screen.

What to do first

Map every route a client uses to log in and trade, including mobile apps and any white-label front end. Then confirm which of them can adopt passkeys or hardware-backed authentication before the deadline.

Sources
SFC circular 26EC35, 9 July 2026 — apps.sfc.hk
SFC circular 26EC32, 2 June 2026 (AI-enabled cyberattacks) — apps.sfc.hk