News
Public · Published
LATEST: ðŸ‡ðŸ‡° Hong Kong's SFC has told brokers and crypto platforms to phase out one-time password logins within 12 months, after phishing made up 57% of reported security incidents in 2025.
Hong Kong's Securities and Futures Commission ordered brokers and crypto platforms to stop using one‑time password logins within the next 12 months after phishing accounted for 57% of security incidents in 2025.
Published:
Updated:
What happened
Hong Kong’s Securities and Futures Commission ordered brokers and crypto platforms to stop using one‑time password logins within the next 12 months after phishing accounted for 57% of security incidents in 2025.
Confirmed
Global impact / market context
Phishing attacks that exploit one‑time passwords put customers at risk of fraud, so the SFC’s rule forces firms to adopt stronger authentication, lowering loss potential and helping maintain investor confidence in Hong Kong’s financial market.
Analyst inference
The directive adds compliance pressure on crypto exchanges and brokerages operating in Hong Kong, likely increasing their technology spending and possibly slowing new service launches while signalling tighter regulatory oversight to the market.
Analyst inference
What to watch
- Speed at which brokers and crypto platforms deploy alternative authentication methods such as biometrics or hardware tokens, indicating their ability to meet the SFC deadline and protect users. Proposed
- Reported rise in operational costs from firms replacing one‑time password systems, showing the financial impact of adopting more secure authentication solutions. Analyst inference
- Any SFC enforcement actions, such as fines for non‑compliance, which could affect profitability and market perception of firms that fail to meet the new rule. Proposed