HKMA flags bank-related scam alert on phishing and fraudulent sites
The HKMA alerted the public to a bank's press release on fraudulent websites, internet banking login screens, phishing emails and related scams.
Continued HKMA scam alerts highlight persistent phishing and credential-harvesting attempts targeting retail bank customers. Firms should validate detection rules, takedown timelines, and customer education on unsolicited links.
Persistent retail fraud pressure with regulatory expectation for proactive bank response.
Action Required
Strengthen anti-phishing controls, login-page monitoring, and SMS/email hyperlink hygiene policies.
Recurring HKMA scam alerts indicate sustained phishing risk and supervisory attention to fraud controls.
Reassess phishing detection KPIs, takedown SLAs, and customer communications. Reinforce that banks do not send hyperlinks via SMS/email for transactional logins.
“The HKMA alerted the public to a bank press release on fraudulent websites, internet banking login screens, phishing emails or other scams, reminding the public that banks will not send SMS or emails with embedded hyperlinks directing them to bank websites.”
Published: 2026-06-02