HKMA issues further scam alert on bank impersonation
HKMA published a further scam alert referencing bank press releases on fraudulent websites, fake login screens and phishing emails impersonating Hong Kong banks.
Ongoing HKMA notifications reflect sustained phishing and impersonation attacks on Hong Kong banks. Firms should expect continued supervisory focus on operational resilience of anti-fraud controls and clarity of customer communications regarding legitimate bank channels.
Continued fraud alerts indicate heightened retail conduct and operational risk requiring ongoing investment in anti-fraud capability.
Action Required
Ensure incident reporting to HKMA is timely and validate that anti-phishing, brand monitoring and customer alert processes remain effective.
Sustained pattern of scam alerts shows persistent systemic fraud exposure for Hong Kong banks.
Reassess phishing takedown SLAs, customer education, and monitoring of impersonation domains; document controls to evidence responsiveness to HKMA fraud alert expectations.
“HKMA alerts the public to press releases from banks relating to fraudulent websites, internet banking login screens, phishing emails or other scams reported to HKMA, reminding the public that banks will not send SMS or emails with embedded hyperlinks.”
Published: 2026-07-02