HKMA issues repeated scam alerts on bank phishing sites
HKMA alerted the public to fraudulent websites, phishing emails and fake internet banking login screens impersonating banks, referencing multiple press releases from affected banks.
Continued HKMA fraud alerts signal a sustained wave of phishing and impersonation targeting Hong Kong banks. Institutions should expect regulatory scrutiny over anti-fraud controls, customer education and speed of fraudulent site takedowns.
Persistent scam activity elevates operational, conduct and reputational risk and increases regulatory expectations on retail fraud controls.
Action Required
Reinforce customer fraud detection, phishing monitoring and takedown processes, and review external communications controls to reduce brand impersonation risk.
Repeated HKMA scam alerts indicate a systemic uptick in banking-related fraud requiring active mitigation.
Assess phishing monitoring, brand protection and customer alert channels; ensure timely reporting to HKMA and rapid takedown of fraudulent domains impersonating the bank.
“The HKMA alerts the public to press releases issued by banks relating to fraudulent websites, internet banking login screens, phishing emails or other scams reported to the HKMA, reminding the public that banks will not send SMS or emails with embedded hyperlinks.”
Published: 2026-07-06