HKMA warns public of bank-related phishing and scam websites
HKMA issued a scam alert flagging fraudulent websites, phishing emails and fake internet banking login screens impersonating banks.
HKMA continues to escalate warnings about impersonation scams targeting bank customers via fake websites and phishing emails. Banks should reinforce customer education, monitor domain abuse, and ensure rapid takedown and incident reporting channels are effective.
Ongoing phishing activity elevates fraud losses, ATO risk, and reputational exposure for retail banks operating in Hong Kong.
Action Required
Review customer fraud controls, phishing takedown processes, and public communications on digital banking authentication.
Persistent scam alerts signal sustained fraud pressure and regulator focus on consumer protection controls.
Fraud and cyber risk rating maintained elevated. Confirm phishing detection, URL monitoring, and customer alerting controls remain effective; validate SMS/email communication policy compliance.
“The Hong Kong Monetary Authority (HKMA) wishes to alert members of the public to the press releases issued by the banks listed below relating to fraudulent websites, internet banking login screens, phishing emails or other scams, which have been reported to the HKMA.”
Published: 2026-07-20