HKMA warns of bank-related scams and phishing activity
HKMA issued a scam alert referencing multiple banks affected by fraudulent websites, phishing emails and related scams.
The HKMA alert highlights sustained phishing and impersonation threats targeting Hong Kong bank customers. Institutions should validate URL monitoring, takedown workflows and customer education, and reiterate that banks do not send embedded transactional links via SMS or email.
Increases fraud, conduct and reputational risk exposure for retail-facing banks operating in Hong Kong.
Action Required
Reinforce customer anti-phishing communications and review fraud detection controls for impersonation attacks.
Recurring HKMA scam alerts signal elevated fraud threat environment and supervisory attention to consumer protection.
Verify brand monitoring and phishing takedown SLAs; review customer authentication and scam warning messaging. Ensure fraud MI captures impersonation trends and escalation to HKMA.
“The HKMA alerts the public to press releases from banks relating to fraudulent websites, internet banking login screens, phishing emails or other scams, and reminds the public that banks will not send SMS or emails with embedded hyperlinks.”
Published: 2026-07-16