HKMA issues further scam alert on bank impersonation
HKMA published additional alerts on fraudulent websites and phishing communications impersonating HK-authorised banks.
Repeated HKMA scam alerts confirm sustained impersonation of banks via fake sites and emails. The regulator continues to emphasise that banks will not send transactional messages containing embedded hyperlinks.
Sustained bank impersonation drives external fraud losses and heightens regulator expectations on customer protection.
Action Required
Maintain heightened phishing surveillance and validate customer communications policy against HKMA guidance.
Continuous flow of scam alerts underscores structural fraud risk in HK retail banking channels.
Validate anti-phishing controls, brand monitoring, and customer education programmes. Ensure incident response playbooks align with HKMA scam alert escalation practices.
“The HKMA wishes to alert members of the public to the press releases issued by the banks listed below relating to fraudulent websites, internet banking login screens, phishing emails or other scams. The HKMA wishes to remind the public that banks will not send SMS or emails with embedded hyperlinks.”