HKMA consolidated scam alert on bank impersonation (10 July)
HKMA issued a consolidated alert on fraudulent websites, phishing emails, and fake internet banking login screens targeting multiple Hong Kong banks.
HKMA highlighted ongoing bank impersonation scams reported by multiple licensed banks. Institutions should reinforce anti-phishing controls, coordinate domain takedowns, and reiterate to customers that banks do not send hyperlinked SMS or emails for transactions.
Persistent bank impersonation increases operational, conduct, and reputational risk across the HK retail banking sector.
Action Required
Refresh phishing detection, brand monitoring, and customer authentication controls; verify no HKMA-listed fraudulent domains impersonate the institution.
Repeated consolidated alerts indicate sustained phishing pressure warranting continuous control enhancement.
Bank impersonation scams remain elevated. Validate brand-abuse monitoring, phishing takedown SLAs, and customer awareness messaging on hyperlink-free bank communications.
“The HKMA wishes to alert members of the public to the press releases issued by the banks listed below relating to fraudulent websites, internet banking login screens, phishing emails or other scams. Banks will not send SMS or emails with embedded hyperlinks which direct them to the banks' websites to carry out transactions.”
Published: 2026-07-10