HKMA scam alert on fraudulent bank communications
HKMA issued a further alert on fraudulent websites, phishing emails and scam communications impersonating banks.
Repeat HKMA alert reinforces persistent phishing and impersonation risk targeting Hong Kong banking customers. Firms should ensure brand-protection, URL monitoring, and customer education remain effective and aligned with HKMA expectations.
Sustained scam activity sustains fraud loss and conduct/reputational risk in HK retail banking.
Action Required
Maintain heightened phishing surveillance and refresh customer anti-scam messaging across digital channels.
Recurring regulator alert signals continued elevated fraud threat environment.
Validate phishing-takedown SLAs, ensure customer comms channels exclude embedded links, and track scam-related complaints. Update fraud KRI thresholds.
“HKMA alerts the public to bank press releases on fraudulent websites, phishing emails and other scams, reminding the public banks do not send SMS or emails with embedded hyperlinks.”
Published: 2026-05-26